This is to be expected
This is to be expected
Posted Jul 19, 2005 9:00 UTC (Tue) by job (guest, #670)In reply to: This is to be expected by Ross
Parent article: Spammers Most Likely Users Of E-Mail Authentication (TechWeb)
No, it does not. The normal user will only care about what's in the From-field and you can still type anything there.
I know you are probably thinking of automatic blacklist filters on the SPF information now, but what would be more effective is to filter out specific IP networks instead. Domains can be easily changed and if this gets widespread we will only see more top domains like .nu which allows you to change your domain name as much as you want for a yearly fee.
IP based filtering is much more effective, and it may surprise you to find out that this has been used for nearly(?) ten years to a great success, technically speaking. We got rid of most open relays that way. The big problem turned out to be political: Who will administer the list and how to you remove false listings? This will be a problem with any blacklist.
So SPF accomplishes nothing except getting rid of some joe jobs, at the price of breaking the email model. The collateral damange includes email forwarding via SMTP and the DNS TXT record, as the RFC stands right now. But this may change in the future. There are much cleaner ways to get rid of false bounces by tagging the legitimate ones if this is very important to you.
No one with an understanding of the email RFCs would want to use SPF. But don't take my word for it. Listen instead to Brad Knowles or Eric Allman of sendmail fame, they really know their stuff.
