spf-discuss
[Top] [All Lists]

Re: SPF HELO checking

2004-12-13 13:10:07
Chris Haynes wrote:
 
      Received: from [212.159.107.246] (helo=[192.168.0.4])
 
I would have expected the message to have been failed for
this address discrepency alone, before even consulting the
SPF record.  Am I too strict?

IMHO your decision is correct, but it's difficult to justify it
based on RfC 2821.  You can always reject HELO foo.bar.example
if foo.bar.example is _your_ name.  You can reject HELO foobar
because it's a syntax error (2821 wants at least one dot).

OTOH you wouldn't reject your own users if they say HELO xyzzy,
William joked about this some days ago.

In theory HELO a.b.x.example must have _an_ IP, but this IP is
not necessarily the IP of the peer,  It's a "receiver policy"
how you handle HELO [1.2.3.4].   I'd interpret 2821 like you,
EHLO or HELO [1.2.3.4] must correspond to a sending IP 1.2.3.4

                       Bye, Frank



<Prev in Thread] Current Thread [Next in Thread>