On 01/12/2006 09:10, Dick St.Peters wrote:
This has become operationally less important since the zone cuts were
removed, but I still regard it as ludicrous to think that a single
policy applies to both MAIL-FROM identities and HELO identities. My
servers send mail for hundreds of domains, but the servers themselves
are in a domain never used legitimately in a MAIL-FROM.
I understand the theory, but what's the practical operational risk with the
combination?
If you publish "v=spf1 a -all" for yourserver1.example.com to cover HELO, you
don't open any ability to spoof that name except for from that machine. I
don't think that's a significant issue. What am I missing?
Scott K
-------
Sender Policy Framework: http://www.openspf.org/
Archives at http://archives.listbox.com/spf-discuss/current/
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to
http://v2.listbox.com/member/?listname=spf-discuss(_at_)v2(_dot_)listbox(_dot_)com