spf-discuss
[Top] [All Lists]

Re: Re: Can the SPF technique be used to stop IPaddress spoofi

2004-11-23 04:54:18
On Tue, Nov 23, 2004 at 11:24:37AM +0000, David Woodhouse wrote:

Only partly; it's a serious point I'm trying to make.

and you fail miserably.

Obviously the 'suggestion' is entirely bogus. But it's a _very_ close
analogy to SPF, and that's why I find it interesting that people here do
have sufficient wit to _instantly_ see that it has the same problems
which SPF has. I'll make it more explicit for the computationally
challenged, by putting the SPF references in parentheses.

Sure, more insults.  It is clear that you don't agree, that you think
you know it all and that you don't want to discuss matters in a normal
and polite way.  Grow up, or shut up.

Despite this fact, I will try one more time to discuss it.

Your analogy is flawed beyond repair.  For this analogy to work,
you would need to have many open smtp relays that are used to
forward your message.  This does not fly anymore.  The world has
already changed, you are too late.

And also of course I just paper over and ignore the 'forwarding problem'
by declaring that all the routers should suddenly use NAT (SRS) despite
that fact that the vast majority of them when asked to do so will simply
declare that it's impractical and I'm nuts.

If you want to route _my_ email _to_ _you_ on _your_ internal network,
there is no need to alter anything.  SPF should be checked on the border
and on the border alone.

If you want to send _your_ email _to_ _another_ mailbox you are _not_
allowed to use _my_ name.

_If_ your analogy would be correct, you would be trying (and failing)
to setup a connection _with_someone_else_ using _my_ ip addresses.

The fact that you don't see this right away makes me think that you are
not as smart as you think you are.