spf-discuss
[Top] [All Lists]

RE: Sendmail white paper

2004-11-21 07:30:48
-----Original Message-----
From: owner-spf-discuss(_at_)v2(_dot_)listbox(_dot_)com
[mailto:owner-spf-discuss(_at_)v2(_dot_)listbox(_dot_)com] On Behalf Of 
Publishing -all is not wise.  SPF is _BROKEN_ please remember this.
There is much forwarding going on and SPF checks failing, and the number
of domains publishing is still less than 5% of all domains...

SPF can only be accurately used to give an IDEA as to the legitimacy of
an e-mail.  Any positive or negative action taken based on an SPF result
is risky business, and I'm disappointed to see people publishing -all,
and further to see people complaining about email being dropped by
servers treating -all in a nazi like fashion and rejecting email which
is clearly legitimate although also clearly a "forgery" in the sense
that it came through a forwarder.

Well I am only publishing in this manner on UFN, there is no way I could
do that for the business domains. I will note for the record that if I
absolutely KNOW all my mail servers, then why NOT publish -all. I am not
rejecting based on that, I simply use it to *weight* and *score* the
email for further evaluation.

Michael Weiner


<Prev in Thread] Current Thread [Next in Thread>