spf-discuss
[Top] [All Lists]

Re: [spf-discuss] Re: Revising SOFTFAIL

2008-01-07 07:22:07
On 1/6/08, Edmig <emgemgemg(_at_)gmail(_dot_)com> wrote:




Which of these addresses is connecting to your mailhost?


There is only one source address in a TCP connection, and it can't be
forged.

What matters is that a domain owner is willing to assume responsibility
for that address.



I love it when someone makes a delcarative statement that is incorrect. As I
read what you wrote I immediately thought of a case even before reading your
next sentence.

When an IP address is on the same subnet (collision domain) as another, it
is certainly possible to forge the source IP address. Now most people would
think of that in an RFC1918 context. But what about small
companies/organizations that are assigned external IPs by their upstream.
Food for thought.

-------------------------------------------
Sender Policy Framework: http://www.openspf.org
Archives: http://v2.listbox.com/member/archive/735/=now
RSS Feed: http://v2.listbox.com/member/archive/rss/735/
Modify Your Subscription: 
http://v2.listbox.com/member/?member_id=2183229&id_secret=82576255-e9979d
Powered by Listbox: http://www.listbox.com
<Prev in Thread] Current Thread [Next in Thread>