spf-discuss
[Top] [All Lists]

RE: [spf-discuss] SPF adoption - HELO vs FROM

2008-01-05 14:52:33
-----Original Message-----
From: Don Lee [mailto:spfdiscuss(_at_)caution(_dot_)icompute(_dot_)com] 
Sent: zaterdag 5 januari 2008 19:41
To: spf-discuss(_at_)v2(_dot_)listbox(_dot_)com
Subject: [spf-discuss] SPF adoption - HELO vs FROM

That scrutiny is forcing server operators to provide RFC-compliant
HELO data that can in turn be checked with SPF. 

The 'problem' with RFC-compliant HELO data is, of course, that,
officially, there's no other requirement than that HELO be a FQDN or an
address literal.

Section 3.6 of RFC 2821 states:

    The domain name given in the EHLO command MUST be either a primary
    host name (a domain name that resolves to an A RR) or, if the host
    has no name, an address literal as described in section 4.1.1.1.

Nowhere is it written, in RFC-marble, that said HELO name actually
corresponds
with the connecting IP address. It makes a great deal of sense in doing so,
of
course; but the point being, that server operators can supply fully
RFC-compliant HELO data, and still be relatively free in their choice of
HELO
name.

- Mark

-------------------------------------------
Sender Policy Framework: http://www.openspf.org
Archives: http://v2.listbox.com/member/archive/735/=now
RSS Feed: http://v2.listbox.com/member/archive/rss/735/
Modify Your Subscription: 
http://v2.listbox.com/member/?member_id=2183229&id_secret=82225526-cb714d
Powered by Listbox: http://www.listbox.com