spf-discuss
[Top] [All Lists]

Re: [spf-discuss] GMAIL mis-usage of SPF?

2005-11-17 13:57:25

----- Original Message -----
From: "Craig Whitmore" <lennon(_at_)orcon(_dot_)net(_dot_)nz>

From 'Mail::SPF::Query' module (1.997):

Set C<guess=E<gt>1> to turned on automatic best_guess processing.
This will use the best_guess SPF record when one cannot be found
in the DNS. Note that this can only return C<pass> or C<neutral>.

By default, the mechanism 'a/24 mx/24 ptr' is used then, which
explains the

Mail::SPF::Query has quite a number of bugs which doesn't pick up
alot of stuff.. I fixed most of them,  but have not had much
time to update this Perl Module. (I'm too busy most of the time)

I can give it to someone else to update the official stuff if
needed

I vote to remove this NON-SPF feature out of the SPF protocol.  It promotes
usage when in fact it is not part of the SPF standard.

It creates social engineering problems.  It tells SPAMMERS you don't need to
use SPF to get a "Received-SPF: PASS"  false illusion.

It is BAD.  It is terrible. It should not be part of the SPF concept.  I
suggest save yourself time, don't fix it. Just remove it. :-)

--
Hector Santos, Santronics Software, Inc.
http://www.santronics.com








-------
Sender Policy Framework: http://www.openspf.org/
Archives at http://archives.listbox.com/spf-discuss/current/
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname=spf-discuss(_at_)v2(_dot_)listbox(_dot_)com