spf-discuss
[Top] [All Lists]

RE: Authentication vs. Authorization

2005-05-21 23:03:24

On Sun, 22 May 2005, Mark wrote:

Wayne, what do you think?

I think that "accepts responsibility" is a loaded term that will scare
away people from publishing SPF records. Does that mean that the
domain owner must accept all responsiblity for any illegal, immoral or
unethical behavior that the MTA owner and/or user of that MTA may do?

I fully agree; "accepts responsibility" is a term fraught with legal
pitfalls. Not to mention that 'accepts responsibility for the message' and
(the perhaps more appropriate) 'accepting responsibility for the use of
the domain name' are two entirely different things, -- legally, I mean.

+1

Don't put "accepts responsibility" in the draft, its legal jargon and SPF authorization is not full trust and not strong enough for "responsibility" except as it relates to responsibility for accepting bounces if address is verified (even that may not be 100% true).

--
William Leibzon
Elan Networks
william(_at_)elan(_dot_)net


<Prev in Thread] Current Thread [Next in Thread>