spf-discuss
[Top] [All Lists]

Re: Re: draft of email security glossary for review

2005-01-07 08:20:15
On Fri, 7 Jan 2005 05:39:30 -0800 (PST), william(at)elan.net
<william(_at_)elan(_dot_)net> wrote:

FYI - I've released glossary officially for first of several the projects
it will appear in, if you need to reference this glossary right now use
http://www.metasignatures.org/glossary.htm

I'd like to thank those of you on this list who have provided valuable
feedback and in particular I'd like to commend Rene Barbier for his help.

--
William Leibzon
Elan Networks
william(_at_)elan(_dot_)net


William, you thought you were going to get off that easy? Hmmmm.....

I think you should include a definition for "Sender" per RFC2822
(3.6.2 Originator fields). Definition: specifies the mailbox of the
agent responsible for the actual transmission of the message.

I would recommend including ASP (Application Service Provider) as
there are many (Hotmail and Gmail being two examples) companies which
provide email access as ASPs (without actually providing connectivity
to the user as an ISP would). An example of another type of ASP would
be Frontbridge which provides SPAM and VIRUS filtering.

There is an entry for SYMMETRIC KEY but not one for ASYMMETRIC KEY.

I guess I'm a little picky but I have a quibble with the definition
for "Confirmed
   OPT-IN". Technically speaking, the access/control of the mailbox is
confirmed. The actual identity of the user is not.

A definition for abuse@ (standard mailbox to send abuse complaints
to...) might be appropriate.

Other candidates for inclusion:

Hard bounce - permanent failure
Soft bounce - temporary failure

I'll try and do a more through review this weekend.

Mike


<Prev in Thread] Current Thread [Next in Thread>