spf-discuss
[Top] [All Lists]

[spf-discuss] Re: Can this really be true?

2005-09-26 08:14:18
Hector Santos wrote:

if EXIM is doing this, I sincerely HOPE it is not in the MAIN
OFF-THE-SHELF- PRODUCT that everyone gets and that its just
one some personal custom or lone wolf local policy setup.

This might conflict with SPF desires, but tough. So be it.
It means SPF is not yet ready handle all situations.

SPF does not say "MAY add Sender", it's an option in 2476(bis).

You might want this for op=pra (that would be "opt-in"), or of
course for spf2.0/pra.

Besides technically it's no real privacy issue, what it does:

1 MAIL FROM x  2 MAIL FROM x  3 MAIL FROM x    4 MAIL FROM x  
  From x         From y         From y           From y 
                 Sender x                        Sender z

1 => noop      2 => noop      3 => add Sender  4 => reject (?)

Plus some situations where this fails (= William's appeal) in
conjuction with Resent-* header fields.

The critical case 3) adds "Sender x", but the MAIL FROM x is
already there, no real privacy problem for x.  Okay, there's
another case 3.a) with MAIL FROM <> where an added "Sender x"
would give it away.  

But that's a problem of 2476(bis) 8.1 or Senderid PRA, it's
no SPF issue.  SPF doesn't suggest to manipulate mail header
fields on the side of the sender.

                      Bye, Frank


-------
Sender Policy Framework: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname=spf-discuss(_at_)v2(_dot_)listbox(_dot_)com