spf-discuss
[Top] [All Lists]

Re: [spf-discuss] Re: Anyone Got an Explanation?

2005-09-21 03:59:37
On Mon, 2005-09-19 at 13:45 -0400, Stuart D. Gathman wrote:
But those messages are still a mail loop waiting to happen. Surely it's
better to deal with them by hand, by reporting them as network abuse to
the upstream network provider?

Actually, by converting them to a real DSN, I am helping to prevent
a mail-loop.

You're helping to prevent _one_ mail loop, but it would be better to
have their ISP remove them from the network -- or at least 'educate'
them under the threat of removal. There's plenty of other mail loops the
offending party could get involved in, that don't involve you.

Imagine that I was running brain-dead spam software like theirs.
I get a (non-DSN) message from mailer-daemon(_at_)clueless(_dot_)com telling 
me I sent
them some spam.  I recognize it as spam, and send *them* a (non-DSN)
message telling them they sent me some spam, which their program
recognizes as spam, and send me a (non-DSN) message telling me
I sent them some spam (which is actually true this time 'round),
which my program recognizes as spam...

Actually you don't need to be that stupid. Even if you send a DSN, they
might respond to it using the address in the From: header and cause a
mail loop. Of course, you shouldn't really be sending DSNs in the common
case either, but that's a different matter.

Another motivation for converting postmaster(_at_)HELO to <> is that 
I have encountered some MTAs out there that actually *convert*
<> to postmaster(_at_)HELO or mailer-daemon(_at_)HELO when they relay the 
mail.
This tries to undo that braindamage.

The fix for mail-mangling brain damage is not to apply further mangling.
People do send genuine mail from postmaster@, and rewriting it _to_ <>
is not really any more of a good idea than rewriting in the other
direction.

-- 
dwmw2


-------
Sender Policy Framework: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname=spf-discuss(_at_)v2(_dot_)listbox(_dot_)com