[Mimedefang] SPF Usefulness (was Re: SNARE spam detection)

Steffen Kaiser skmimedefang at smail.inf.fh-bonn-rhein-sieg.de
Thu Jul 30 03:12:47 EDT 2009


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Wed, 29 Jul 2009, David F. Skoll wrote:

> Not really.  SPF applies to envelope senders; people's mail clients
> show the header senders.  So you can have MAIL FROM:<spammer at throwaway.net>
> and From: <servce at intl.paypal.com> with an SPF pass. :-(

However, it is possible to notify end-users about this case. Once I placed 
the MAIL FROM into the subject, if the addresses differ, but this caused 
lots of grief with mailing lists.

I wonder why so few MUAs show a notice, when Return-Path and From differs. 
- - Actually I remember this only on Webmail.

Bye,

- -- 
Steffen Kaiser
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iQEVAwUBSnFH8tlJzF6z/k3SAQJS5AgAjdm7LP49wzudLR3daxG6hFg87pR2MisS
K0lUWqJqWj6UKAVtA3DGQ6bupZc517snMAONVV2tOzkIHwmjcEYFnDhlO4rendzZ
l0px1xT3w/jkRUgiXww2I5gngZWSB+2HLW5o5UIs1nMXBLRc24MGhOHoS8eGYRhL
s7/acYhprNbydavhapleMNGJ/OIv6PuFg6vAZCOd2QIRyfazYh/RWRHfwNdfDfJQ
CoOTj0HXcYMFJYR61LUR+bjzhbf2NWIhFrnQFb3/P/Xd75/30iZ3t3FlVaYwyIDU
L7Rzku1LW9guHtkyxZriOv//VlSZzcdA3b+aQtCYBZNHq84RfHvwrA==
=REor
-----END PGP SIGNATURE-----



More information about the MIMEDefang mailing list