public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* VGER does gradual SPF activation  (FAQ matter)
@ 2006-06-10 22:27 Matti Aarnio
  2006-06-10 23:06 ` David Woodhouse
                   ` (5 more replies)
  0 siblings, 6 replies; 101+ messages in thread
From: Matti Aarnio @ 2006-06-10 22:27 UTC (permalink / raw)
  To: linux-kernel

Now that there is even an RFC published about SPF...


What is SPF ?

It is one way to to ensure that at SMTP transport level the claimed
message source domain is valid, and message is coming from place
where origination domain's administrator has declared that are valid
source servers for emails claiming to be of that domain.


It does NOT verify that SMTP origination local part is true. 

It does NOT verify message visible headers.

Several people have written MTA configurations that test arriving email
visible "From:" (and sometimes "Sent:") header against SPF data and
actually violate SPF specification doing that!
(We have routinely kicked subscribers with that bug from lists..)


What it gives ?

It gives us a way to tell the world, that emails claiming to be
coming from VGER should be accepted only when they really are
coming from vger. (Complications like recipients incoming MX
relays are not _our_ problem..)

We might get slight reduction of back falling junk at vger with
that - reduction increases when people begin to deploy the SPF
verification more and more widely into their receiving email servers.
(And do it correctly...)



Will VGER begin to verify SPF in incoming email ?

Yes, sometime this summer.



What will break ?

You really should go and read SPF documents and guides and FAQs at:
    http://spf.pobox.com/

Very little will break, but one should really consider converting
their email sending methodology to one, which uses fewest possible
number of servers, publish that data in DNS, and always send all
emails thru those servers.

In longer run the amount of irresponsible (incurable) network security
holes (known as Windows) shows no sign of becoming extinct at adsl -lines,
so there will be increased pressure to demand sender identification
(and verification) during email sending - viruses can't do that yet...
And when they learn, user with infection can be trivially identified
and contacted/blocked.  At the same time I do find it most likely that
ADSL-lines (and modems) will no longer be allowed to send _anywhere_
over plain SMTP.

In order to be able to send email, a "SUBMISSION" protocol does exist,
and is relatively easy to get working with for example the Thunderbird.
Better would be having a button "use submission service" in its account
setup..   (And similar in Outlook/O.Express...)


/Matti Aarnio -- one of  postmaster at vger.kernel.org

^ permalink raw reply	[flat|nested] 101+ messages in thread

end of thread, other threads:[~2006-06-16  3:54 UTC | newest]

Thread overview: 101+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-06-10 22:27 VGER does gradual SPF activation (FAQ matter) Matti Aarnio
2006-06-10 23:06 ` David Woodhouse
2006-06-11  0:16   ` Rik van Riel
2006-06-11  0:44     ` David Woodhouse
2006-06-11 13:02     ` Theodore Tso
2006-06-11 13:55       ` Rik van Riel
2006-06-11 14:03         ` Avi Kivity
2006-06-12  8:47           ` Matthias Andree
2006-06-12 10:17             ` Neil Brown
2006-06-12 10:35               ` David Woodhouse
2006-06-12 11:07               ` Matthias Andree
2006-06-11  2:24   ` marty fouts
2006-06-11  2:41     ` jdow
2006-06-11  2:58       ` David Schwartz
2006-06-11  5:17         ` jdow
2006-06-12  8:18           ` Bernd Petrovitsch
2006-06-12  8:23             ` jdow
2006-06-12  8:31               ` Bernd Petrovitsch
2006-06-12  9:47               ` Neil Brown
2006-06-12 10:30                 ` Alan Cox
2006-06-12 10:33                   ` Neil Brown
2006-06-12 17:37               ` Gerhard Mack
2006-06-12 18:14                 ` Krzysztof Halasa
2006-06-12 18:46                   ` jdow
2006-06-12 19:16                     ` Krzysztof Halasa
2006-06-12 21:51                   ` Bernd Petrovitsch
2006-06-13 21:12                 ` David Woodhouse
2006-06-12  9:53             ` Alan Cox
2006-06-12 10:01               ` Bernd Petrovitsch
2006-06-12 11:14                 ` Matthias Andree
2006-06-12 10:58               ` Neil Brown
2006-06-12 11:22                 ` Matthias Andree
2006-06-12 11:42             ` Kyle Moffett
2006-06-13 23:32               ` Scott Lockwood
2006-06-13 23:42                 ` Kyle Moffett
2006-06-14  0:02               ` Neil Brown
2006-06-14 10:20                 ` Matthias Andree
2006-06-16  3:53                   ` Kyle Moffett
2006-06-12  8:27     ` Bernd Petrovitsch
2006-06-12 20:25       ` Horst von Brand
2006-06-12 21:10         ` Nick Warne
2006-06-12 22:06           ` Jesper Juhl
2006-06-12 22:12             ` Randy.Dunlap
2006-06-12 23:03             ` jdow
2006-06-13  3:00               ` Horst von Brand
2006-06-13  5:54                 ` jdow
2006-06-13  8:36                   ` Bernd Petrovitsch
2006-06-13  9:58                   ` Marc Perkel
2006-06-13 13:28                   ` Horst von Brand
2006-06-13 14:34                     ` David Woodhouse
2006-06-13  9:05                 ` David Woodhouse
2006-06-13 10:45                   ` Matthias Andree
2006-06-13 12:24                     ` David Woodhouse
2006-06-13 12:49                       ` Matthias Andree
2006-06-13 13:10                         ` David Woodhouse
2006-06-13 15:19                         ` Marc Perkel
2006-06-13 15:57                           ` Auke Kok
2006-06-13 19:54                             ` David Woodhouse
2006-06-13 20:31                               ` Lennart Sorensen
2006-06-13 20:48                                 ` David Woodhouse
2006-06-15 17:05               ` Keith Owens
2006-06-15 23:14                 ` Wakko Warner
2006-06-13  0:11             ` Phil Oester
2006-06-13  0:26               ` David Miller
2006-06-13  4:18                 ` Willy Tarreau
2006-06-13 15:17               ` Joel Jaeggli
2006-06-12 21:43         ` Bernd Petrovitsch
2006-06-13  3:05           ` Horst von Brand
2006-06-13  8:31             ` Bernd Petrovitsch
2006-06-13 10:50               ` Matthias Andree
2006-06-13 13:15                 ` Justin Piszcz
2006-06-11  5:09   ` Neil Brown
2006-06-11  5:26     ` jdow
2006-06-11  6:12       ` Willy Tarreau
2006-06-11 16:02 ` Folkert van Heusden
2006-06-11 17:54   ` Lee Revell
2006-06-11 18:54     ` David Miller
2006-06-12  9:09       ` Matthias Andree
2006-06-12 11:32       ` Nikita Danilov
2006-06-12 14:52       ` Jeff Garzik
2006-06-12 20:00         ` David Miller
2006-06-12 22:29           ` Jesper Juhl
2006-06-12 22:48             ` David Miller
2006-06-12 22:57               ` Jesper Juhl
2006-06-13  3:54         ` VGER does gradual SPF activation (FAQ matter) - Alternative Marc Perkel
2006-06-13  4:51           ` David Miller
2006-06-13 13:41       ` VGER does gradual SPF activation (FAQ matter) Athanasius
2006-06-11 17:31 ` Marc Perkel
2006-06-11 18:50 ` Florian Weimer
     [not found] ` <20060611072223.GA16150@flint.arm.linux.org.uk>
2006-06-12  8:32   ` Matti Aarnio
2006-06-12  8:40     ` Russell King
2006-06-12  9:57       ` Neil Brown
2006-06-12 15:55         ` Russell King
2006-06-12 20:06       ` Zwane Mwaikambo
2006-06-12 11:22     ` David Woodhouse
2006-06-12 15:41     ` Simon Oosthoek
2006-06-12 22:55       ` Matthias Andree
2006-06-13 17:41       ` Matti Aarnio
2006-06-12  9:05 ` Matthias Andree
2006-06-12 17:28   ` Matthew Frost
2006-06-13  0:12   ` David Woodhouse

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox