spf-discuss
[Top] [All Lists]

Re[14]: [spf-discuss] Trying to understand the best recommendation for my client, help appreciated.

2009-05-14 00:34:18
At 04:51 14/05/2009  Thursday, Sanford Whiteman wrote:
you  will seem to any of us compliance extremists just to be another
spambot  as  no other SPF checks are considered trusted if HELO/EHLO
doesn't pass.

i never meant to imply it was [in RFC 4408]

i wasn't talking about RFC compliance but simply Best practice

In  a newsgroup focused on a pub'd standard, if you don't want readers
to think you're talking about compliance with the standard, you should
use  words  other  than "compliance" to describe your motivation for a
certain configuration.

Maybe  "stricter-than-standards  anti-abuse  architectures"  is a fair
wrapper  term  for  your policies, which I don't use judgmentally. "My
server,  my  rules"  thinking  and "standards compliance" thinking are
starkly  different.  Both  have their place, but mixing terms from one
with  policies from the other is bound to confuse. From looking at the
textual description of your ruleset, it seems well-thought-out and not
egregiously draconian. Still, the rules are local rules that don't fit
the  open  standards and/or public regulatory meaning of "compliance,"
but rather within the realm of personal/internal policies.

I'm  sure  there  was  no  way  to  say  this without it adding to the
negative  tone,  but  I  can't  see  a  way  out of it. I'll add a few
smileys. :)))

thank you, honestly for the tone change

I think though any receiver is only ever running in  "anti-abuse architecture" 
mode
i prefer to refer to it as rewarding compliance to Best practices
{as its more geared to raising the trust score for good MTA's than lowering the 
score for bad}
ie their are many data points you can only score well or nothing on

thus upshot is less>no false positives for those running mail via a very well 
setup MTA {more customers for them}
and hopefully encouragement for those other senders to adopt Better practices 
{less customers or more unhappy ones}

ending up in less receiver load {eventually} due to bots being clearly 
differentiable from badly-admined-MTA's

{think back to before AOL started to refuse mail from those missing FcRDNS, 
before then it was argued it was only extremists that demanded it, now its 
considered slightly mad to not do so}




--Sandy



-------------------------------------------
Sender Policy Framework: http://www.openspf.org
Modify Your Subscription: http://www.listbox.com/member/
Archives: https://www.listbox.com/member/archive/735/=now
RSS Feed: https://www.listbox.com/member/archive/rss/735/
Powered by Listbox: http://www.listbox.com



-------------------------------------------
Sender Policy Framework: http://www.openspf.org
Modify Your Subscription: http://www.listbox.com/member/
Archives: https://www.listbox.com/member/archive/735/=now
RSS Feed: https://www.listbox.com/member/archive/rss/735/
Powered by Listbox: http://www.listbox.com

<Prev in Thread] Current Thread [Next in Thread>