spf-discuss
[Top] [All Lists]

[spf-discuss] Authentication-Results

2007-11-22 01:45:59
Hi, the Internet Draft specifying a new header field 
Authentication-Results is almost ready.  Some of us
likely regret that three years too late is really too
late, but we could still decide to support it as good
idea.

AFAIK the author intends to fix his "results" table:
Sender ID will get the same "smtp.helo" row as SPF,
and there won't be a separate "smtp.ehlo" row for SPF.

Actually there is no difference between Sender ID and
SPF wrt "smtp.mfrom" and "smtp.helo" results, the
draft could unify these rows.  Sender ID RFC 4406 got
a normative reference to SPF RFC 4408 about this.

IMO the "security considerations" have to state that
noting "hardfail" results instead of simply rejecting
"hardfail" will cause the loss of legit mails in some
arguably broken scenarios.

Assuming the author fixes this, can we "officially"
support his draft, on behalf of th SPF project ?  The
"iprev" check in this draft is quite interesting, and
the draft might also help the SSP-folks ("SSP" is the
keystone of DKIM).

 Frank

-------------------------------------------
-----------------------------------------------------------------------
Sender Policy Framework: http://www.openspf.org/
Archives at http://archives.listbox.com/spf-discuss/current/
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to http://v2.listbox.com/member/?list_id=735
Powered by Listbox: http://www.listbox.com

<Prev in Thread] Current Thread [Next in Thread>