spf-discuss
[Top] [All Lists]

Re: [spf-discuss] Re: draft-otis-spf-dos-exploit

2006-11-03 13:23:36
On Fri, 3 Nov 2006 10:46:50 -0500 (EST) "Stuart D. Gathman" 
<stuart(_at_)bmsi(_dot_)com> wrote:
On Thu, 2 Nov 2006, wayne wrote:

                       checking SPF for a given domain more than once 
is a
braindead checking implementation.

How would each forwarder know that the SPF record had already been
checked by the previous forwarder?  Most forwarders, be it

If they *don't* know, then they should do SRS - so that the next MTA
checks their own domain, not a possible Dos victims.

So yes, checking SPF _for_a_given_domain_ more than once is braindead.

Braindead globally, but sensible individually.  The trick then is to 
convince forwarders to suboptimize locally to get a better global solution.

This is not a technical issue.

Scott K

-------
Sender Policy Framework: http://www.openspf.org/
Archives at http://archives.listbox.com/spf-discuss/current/
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to http://v2.listbox.com/member/?list_id=735