[Mimedefang] Message header madness - was Re: SPF Usefulness (was Re: SNARE spam detection)
kd6lvw at yahoo.com
Thu Jul 30 15:57:46 EDT 2009
When comparing the envelope sender to the from and reply-to headers, the sender header should also be considered.
As noted, envelope sender and from will always differ for mailing list distributions, but even this list sets the sender header properly.
There's also the optional resent-from and resent-sender headers to check. Why not also check the depreciated errors-to header as well!
Remember that reply-to is supposed to be used specifically when it differs from the from header. I would suggest scoring positive points (towards spam) if they were IDENTICAL (as such implies that the message generator doesn't understand what it's doing or the purpose of reply-to). Doing stupid things often implies spamminess.
More information about the MIMEDefang