spf-discuss
[Top] [All Lists]

SPF receivers are weak link

2005-08-25 08:46:08
All 6 of the spf-help problems I've handled so far have been
senders stymied by recipients with broken SPF.  The most common problem
is for the recipient to test SPF at some inner MTA and not at
the gateway (rejecting most senders with SPF records).

And then there was the Hector incident.  No wonder senders are
reluctant to publish -all!  One trick I've discovered is to create a special
subdomain that has a very lax SPF record (or none).  When a braindead receiver
rejects all your regular mail, you can usually get through with that domain
(unless it has been spam-forged already).

I was going to talk about the importance of a test suite, and perhaps
having a certification program for SPF implementations.  But since
the most common problem is not testing SPF at the right place - 
perhaps a common mistakes page on the web site would be better.

-- 
              Stuart D. Gathman <stuart(_at_)bmsi(_dot_)com>
    Business Management Systems Inc.  Phone: 703 591-0911 Fax: 703 591-6154
"Confutatis maledictis, flamis acribus addictis" - background song for
a Microsoft sponsored "Where do you want to go from here?" commercial.


<Prev in Thread] Current Thread [Next in Thread>