spf-discuss
[Top] [All Lists]

Re: Re: SPF implementations

2005-08-16 14:11:26
Scott Kitterman writes:
Graham Murray wrote:
"Stuart D. Gathman" <stuart(_at_)bmsi(_dot_)com> writes:


On Tue, 16 Aug 2005, Graham Murray wrote:

I would disagree. I suspect that it is common for 'role' addresses to
be aliased to a personal address, often with the same person receiving
more than one 'role' address. If user(_at_)example(_dot_)com receives mail 
for
postmaster(_at_)example(_dot_)com and abuse(_at_)example(_dot_)com, they 
may well want
replies to mails sent to those addresses to show the appropriate
'role' account rather than user(_at_)example(_dot_)com(_dot_)

Yes, but we are not talking about internal forwarding.  The above
scenario causes no problems with SPF.


Neither am I talking about internal forwarding. I am talking about the
replies to the internally forwarded or aliased email. If my mailbox is
user(_at_)example(_dot_)com it also receives mail addressed to
postmaster(_at_)example(_dot_)com, then when I reply to mail addressed to
postmaster I may well want to change the RFC(2)821 envelope return
path and header "From" to "postmaster(_at_)example(_dot_)com" rather than 
the
default "user(_at_)example(_dot_)com". This, I think is one situation where
RFC2831 section 7.1 is legitimate.

Yes, but that's all within the same domain.  With the limited exception 
of records that use the localpart of the e-mail address in macros, this 
is nothing to do with SPF.

I would say it's a an internal routing/forwarding issue however because 
once I deliver to your MX, how you route it afterwards (the local part) 
is of no concern to me as long as you don't bounce it back to me after 
you've accepted responsibility for it....

(Apologies for the long quote)

Role addresses are not necessarily all within the same domain.  For
example, I have clients whose sales(_at_)example(_dot_)com address gets 
forwarded
to multiple salesmen using multiple email services ... one salesman
may like Yahoo mail, another may like AOL.  (A *major* part of the
email service I sell is that people can use the mail system of their
choosing.)  If you send mail to example.com's sales@ address, it gets
forwarded to both salesmen.

To avoid SPF problems I have to use SRS to rewrite the MAIL FROM.  You
may not realize it, but a major goal of SRS is to make sure you do get
any bounces.  If I can't forward mail you send, you get a bounce from
me, *and* if mail is bounced back to the SRS rewritten MAIL FROM after
I forward it, that bounce is forwarded back to you.

The important bottom line here is that you do get bounce notification
that your mail didn't make it, *and* you only get bounces of mail you
really did send (provided your SPF record ends in -all).

--
Dick St.Peters, stpeters(_at_)NetHeaven(_dot_)com 


<Prev in Thread] Current Thread [Next in Thread>