[Mimedefang] $RelayHostname not matchingsendmail's Receivedheader?

David F. Skoll dfs at roaringpenguin.com
Sun Dec 10 19:36:24 EST 2006


John Rudd wrote:

> You're right, I couldn't just look at if it's an SPF pass, it would have
> to be an SPF record that specifically mentions the host.

SPF is under the control of the attacker.  Maybe an "all" entry is
too obvious.  What about these four entries:

0.0.0.0/2 64.0.0.0/2 128.0.0.0/2 192.0.0.0/2

which together are equivalent to "all"?

> So, the SPF record has to explicitly mention the host for me to exempt
> it.  A SOHO type mail server can/will probably accommodate that
> requirement.

That's true.  It's a usable heuristic.

Regards,

David.



More information about the MIMEDefang mailing list