spf-discuss
[Top] [All Lists]

RE: [spf-discuss] Misuse of Return Address

2006-12-08 14:06:19
Jason LEWIS wrote on Friday, December 08, 2006 5:34 AM -0600:

Speaking of the SMTP client, all MTAs act like any SMTP client to send
email to another SMTP server using port 25.  When you say that inject
mail is different for forwarders and humans, I say otherwise as you
cannot tell the difference.  I suspect that even a network packet
sniffer could not tell the difference either.

Even when you submit messages via SMTP, the client normally
authenticates to the server first.  That may be via possessing a
particular IP address, POP before SMTP, SMTP AUTH, TLS or something
else.  You don't _have_ to use authentication, only you operate an open
relay if you don't.  Injecting messages into the internet mail stream
with SMTP, on the other hand, does not involve authentication.

--
Seth Goodman

-------
Sender Policy Framework: http://www.openspf.org/
Archives at http://archives.listbox.com/spf-discuss/current/
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to http://v2.listbox.com/member/?list_id=735