spf-discuss
[Top] [All Lists]

Re: followup: Re: [spf-discuss] libspf2 sample programs

2007-01-04 14:02:23
What about RFC 1123 where it states:

      5.2.5  HELO Command: RFC-821 Section 3.5

         The sender-SMTP MUST ensure that the <domain> parameter in a
         HELO command is a valid principal host domain name for the
         client host.  As a result, the receiver-SMTP will not have to
         perform MX resolution on this name in order to validate the
         HELO parameter.

         The HELO receiver MAY verify that the HELO parameter really
         corresponds to the IP address of the sender.  However, the
         receiver MUST NOT refuse to accept a message, even if the
         sender's HELO command fails verification.




Please respond to spf-discuss(_at_)v2(_dot_)listbox(_dot_)com

To:     spf-discuss(_at_)v2(_dot_)listbox(_dot_)com
cc:      (bcc: Dan Mitton/YD/RWDOE)
Subject:        Re: followup: Re: [spf-discuss] libspf2 sample programs
User Filed as: Not Categorized in ERMS



This e-mail requires categorization and determination of LSN Relevancy. 
You may categorize now, or later when you exit, delete, reply to or 
forward the e-mail.

On Thu, 4 Jan 2007, Don Lee wrote:

It is not clear on the web site, or in "common parlance" that
SPF is designed for, or to be used for, HELO.  I am looking into
using it on HELO, and am getting pushback from admins that this
is an abuse of SPF, and not "supported".

Is there a definitive statement I can point to that declares that this
usage is OK?

RFC 4408 2.1/2 

  It is RECOMMENDED that SPF clients not only check the "MAIL FROM" 
identity,
  but also separately check the "HELO" identity by applying the 
check_host()
  function (Section 4) to the "HELO" identity as the <sender>.

The admins giving you pushback are clueless.

-- 
                       Stuart D. Gathman <stuart(_at_)bmsi(_dot_)com>
    Business Management Systems Inc.  Phone: 703 591-0911 Fax: 703 
591-6154
"Confutatis maledictis, flammis acribus addictis" - background song for
a Microsoft sponsored "Where do you want to go from here?" commercial.

-------
Sender Policy Framework: http://www.openspf.org/
Archives at http://archives.listbox.com/spf-discuss/current/
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to http://v2.listbox.com/member/?list_id=735


-------
Sender Policy Framework: http://www.openspf.org/
Archives at http://archives.listbox.com/spf-discuss/current/
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to http://v2.listbox.com/member/?list_id=735