Julian Mehnle wrote:
(Can I have "HardPass", please?)
3.4 The optional "auth" property
The "auth" property indicates that no other user of mailers resulting
in a "Pass" can forge any addresses covered by the sender policy.
This is often the case for MSAs as defined in [I-D.gellens-submit-
bis], but many MSAs and smart hosts still allow to use any MAIL FROM
after a succesful authentication.
For details about enforced submission rights see [I-D.gellens-submit-
bis]. Example:
IN SPF "v=spf1 op=auth +a ?include:example.com -all"
Please note that the "auth" property has no technical effect. It is
arguably better to use a "Neutral" mechanism for any shared smart
host, and to use "Pass" only if the MSA enforces submission rights.