spf-discuss
[Top] [All Lists]

Re: Is anyone else getting DoS'd by relay attacks?

2005-01-14 17:36:05
On Fri, 2005-01-14 at 19:08 +0100, Hannah Schroeter wrote:
Frankly, what information do you expose if you reject immediately
instead of in a delayed fashion which you don't expose anyway in other
ways?

You can tell the difference between sender verification callouts and an
actual attempt to send a bounce.

Remember, a bounce with multiple recipients is a rare case. You can
reject at DATA in the common case, and only actually reject at RCPT time
in the rare case that a bounce have multiple recipients, some of whom
would accept the bounce and some of whom would not.

-- 
dwmw2



<Prev in Thread] Current Thread [Next in Thread>