Posted Jun 15, 2006 21:32 UTC (Thu) by dwmw2 (subscriber, #2063)
[Link]
You didn't actually read the why not SPF page linked above, did you?
In particuar, I was thinking of BATV. Not only does it instantly stop the bounces to mail you didn't actually send, but it also allows others to detect fake mail.
Try faking MAIL FROM:<dwmw2@infradead.org> to any site which bothers with sender verification callouts to avoid mail from invalid addresses (like sourceforge, amongst many others).
550-Verification failed for <dwmw2@infradead.org>
550-Called: 2001:4bd0:203e::1
550-Sent: RCPT TO:<dwmw2@infradead.org>
550-Response: 550-This address never sends messages directly, and should not accept bounces.
550-550-Please see http://www.infradead.org/rpr.html or contact
550-550 postmaster@infradead.org for further information.
550 Sender verify failed
SPF, joe jobs, and phishing
Posted Jun 22, 2006 23:51 UTC (Thu) by kitterma (subscriber, #4448)
[Link]
How many of those solutions are accessible to someone who doesn't run their own dedicated mail server?