spf-discuss
[Top] [All Lists]

Re: IPv6 / a+ip6 (Was: Re: New SPFv1 spec: draft-schlitt-spf-classic-01pre7)

2005-05-18 06:17:49

On Wed, 18 May 2005, wayne wrote:

  When any mechanism fetches host addresses to compare with <ip>, when
  <ip> is an IPv4 address, A records are fetched, when <ip> is an IPv6
  address, AAAA records are fetched.  Even if the SMTP connection is
  via IPv6, an IPv4-mapped IPv6 IP address (see [RFC3513] section
  2.5.5) MUST still be considered an IPv4 address.

Is this clear enough, or does it need to be changed?

The 'a', thus defines a host address which is both IPv4 and IPv6, and
I am really wondering what happens if I setup my spf rules and send out
a mail over IPv6 outbound, and some SPF checker doesn't check the IPv6
address, sees that it's not the IPv4 address as mentioned in the SPF
rule, thus most likely dropping the mail...

I think this is answered by the above quote of the SPF spec.  If not,
let me know.

How am I supposed to read "a:example.com/24" with example.com having
both IPv4 and IPv6 address? What if I want to specify different masks
depending on if the connection from my server is coming from ip4 or ip6?

P.S. I hope you realize that saying we will always assume mask to be ip4 will get you into hot waters with IETF because IETF says that all new protocols should be ip-address neutral or support both ip4 and ip6 equally well.

--
William Leibzon
Elan Networks
william(_at_)elan(_dot_)net