spf-discuss
[Top] [All Lists]

RE: Ignoring rejected mail?

2004-12-08 09:19:27
On Wed, 2004-12-08 at 15:02 +0000, Mark wrote:
And as I have been replying ever-since: without the digest, there is
nothing SES offers which I cannot also accomplish with a 'self-signed' SRS
address. Including call-back verification.

Right. Just a self-signed SRS address without the digest is also a
perfectly viable alternative to SPF too. That's precisely what I'm doing
too, in fact.

There are a lot of people with rabid objections to SMTP callbacks
though, which is why the addition verification options are there. And
the optional digest is to help solve the theoretical replay attack. I
haven't bothered with either, yet.

Unless I adopt your highly exaggerated scenario of people, en masse,
forwarding over multiple .forward files. Anyone with half-a-brain will
use, say, an alumni forwarding service to have mail forwarded to the final
recipient.

If they do that, they need to change the various forwarding addreses
_every_ time they change the place where they actually keep their
mailboxes. That's certainly not what I do; I point everything to one
place, and then have a _single_ pointer there which I change. I know
others who do likewise.

-- 
dwmw2


<Prev in Thread] Current Thread [Next in Thread>