SPF, joe jobs, and phishing
SPF, joe jobs, and phishing
Posted Jun 15, 2006 18:13 UTC (Thu) by dwmw2 (subscriber, #2063)In reply to: SPF, joe jobs, and phishing by rfunk
Parent article: SPF on vger
There are much better solutions to the problem of bounces to joe-jobs. Solutions which don't require wholesale changes to the way that email works.
Posted Jun 15, 2006 19:32 UTC (Thu)
by dlang (guest, #313)
[Link] (2 responses)
Posted Jun 15, 2006 21:32 UTC (Thu)
by dwmw2 (subscriber, #2063)
[Link] (1 responses)
You didn't actually read the why not SPF page linked above, did you?
Posted Jun 22, 2006 23:51 UTC (Thu)
by kitterma (guest, #4448)
[Link]
Posted Jun 15, 2006 19:35 UTC (Thu)
by rfunk (subscriber, #4054)
[Link]
Posted Jun 22, 2006 23:48 UTC (Thu)
by kitterma (guest, #4448)
[Link]
SPF checking may be relatively rare, but in my experience it is enough that within a month of publishing a -all SPF record, bounce messages due to forged sending using my domains ended. There is enough SPF checking going on to provide deterrence.
SPF is a horrible idea in theory. In practice, unless your user base sends to peope who do a lot of forwarding, it works pretty well for many domains. Eventually, it will be obsolete because something better will come along. In the meantime, it does the job for me and lots of others.
like what?SPF, joe jobs, and phishing
SPF, joe jobs, and phishing
550-Verification failed for <dwmw2@infradead.org>
550-Called: 2001:4bd0:203e::1
550-Sent: RCPT TO:<dwmw2@infradead.org>
550-Response: 550-This address never sends messages directly, and should not accept bounces.
550-550-Please see http://www.infradead.org/rpr.html or contact
550-550 postmaster@infradead.org for further information.
550 Sender verify failed
How many of those solutions are accessible to someone who doesn't run their own dedicated mail server?SPF, joe jobs, and phishing
Note that I mentioned bounces being only part of the problem with SPF, joe jobs, and phishing
joe-jobs.
None of which are implementable by someone who isn't running their own mail server and using custom software. With SPF, with all it's flaws, any domain owner that can publish a TXT record in their DNS can gain some protection.SPF, joe jobs, and phishing