spf-discuss
[Top] [All Lists]

Re: SPF lookup with intermediate ISP mail relay

2004-11-24 06:22:27
On Wed, 24 Nov 2004 08:57:17 GMT, Mark <admin(_at_)asarian-host(_dot_)net> 
wrote:
I understand what you're trying to do, and why; but perusing the headers
for Received: headers is, in the case of SPF, somewhat questionable. The
beauty of doing SPF at the SMTP dialogue level, is that the connecting IP
address, for all purposes and intent, is a trustworthy entity (see earlier
posts about the difficulty of hijacking a TCP/IP connection). You lose
that certainty with (unsigned) headers.



Mark, I'm going to have to quibble with you about the connecting IP
being a "trustworthy entity". A more appropriate phrasing would be "a
knowable entity". Just because someone connects to me on port 25
doesn't make them trustworthy.

Mike