spf-discuss
[Top] [All Lists]

Re: [spf-discuss] Fixing Forwarding with RPF

2006-11-11 13:02:48
On Sat, 11 Nov 2006, K.J. Petrie wrote:

So, to my proposed addition, which is, alongside the spf record for a domain, 
I suggest a second record, which I shall call Recipient Protocol Framework 
(RPF). The RPF record would be similar in format to an SPF record as 
described in RFC 4408 except that it would begin "v=rpf1" instead 
of "v=spf1". It would only support a subset of the fields contained in an SPF 

If I understand you, your idea is for senders to tell receivers via a RPF
record when mail is forwarded, and disable SPF for those cases..  This will not
work because forwarders are selected and configured by the receiver.
Otherwise, the "forwarder" would already be accounted for in the SPF record.  

In the case of large mail providers, receivers need to provide a web page for
users to configure non-SRS forwarders before rejecting on SPF.  (Or else just
expect all the poor forwarders to use SRS or else, as seems to be the case
currently.)  Small receivers need to have enough sense to realize that
checking SPF for their forwarders is not going to work unless the
forwarders do SPF.  In either case, they need to list the forwarders in their
SPF implementation, or not reject.

In pymilter, non-SRS forwarders are listed by domain, if the forwarder has
an SPF record, or by SPF record (showing where the forward sends mail
from).

If you are thinking of "greeting card" or "political email" type websites,
then they will pass SPF if they use their own MAIL FROM as they should.
They will pass Sender ID if they use their own Sender: as they should.
Don't patronize sites that forge MAIL FROM or PRA.

-- 
              Stuart D. Gathman <stuart(_at_)bmsi(_dot_)com>
    Business Management Systems Inc.  Phone: 703 591-0911 Fax: 703 591-6154
"Confutatis maledictis, flammis acribus addictis" - background song for
a Microsoft sponsored "Where do you want to go from here?" commercial.

-------
Sender Policy Framework: http://www.openspf.org/
Archives at http://archives.listbox.com/spf-discuss/current/
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to http://v2.listbox.com/member/?list_id=735