spf-discuss
[Top] [All Lists]

Re: Hole in spfmilter 0.95

2005-08-20 12:25:47
Daniel Taylor wrote:
 
EHLO j.random.example.org
MAIL FROM: "user(_at_)example(_dot_)com"
RCPT TO: user(_at_)example(_dot_)com
[...]
Lesson: make sure you validate your input.

Yes, AFAIK that should be an SMTP syntax error for
the MAIL FROM, and you'd never reach the second
syntax error in RCPT TO, let alone any SPF tests.

But MAIL FROM:<"user"@example.org> would be okay,
that should also work for SPF tests (result NONE).

                      Bye, Frank