SPF, joe jobs, and phishing
Posted Jun 15, 2006 21:32 UTC (Thu) by
dwmw2 (subscriber, #2063)
In reply to:
SPF, joe jobs, and phishing by dlang
Parent article:
SPF on vger
You didn't actually read the why not SPF page linked above, did you?
In particuar, I was thinking of
BATV. Not only does it instantly stop the bounces to mail you didn't actually send, but it also allows others to detect fake mail.
Try faking
MAIL FROM:<dwmw2@infradead.org> to any site which bothers with sender verification callouts to avoid mail from invalid addresses (like sourceforge, amongst many others).
550-Verification failed for <dwmw2@infradead.org>
550-Called: 2001:4bd0:203e::1
550-Sent: RCPT TO:<dwmw2@infradead.org>
550-Response: 550-This address never sends messages directly, and should not accept bounces.
550-550-Please see http://www.infradead.org/rpr.html or contact
550-550 postmaster@infradead.org for further information.
550 Sender verify failed
(
Log in to post comments)