[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: SPF (was: Re: PERSONAL xxxx - KTA)

Chris Wagner wrote:
At 07:54 AM 7/1/2007 +1000, Craig Sanders wrote:
you misunderstand what SPF is for.  SPF is *NOT* an anti-spam system. it
is an anti-forgery system. SPF's *SOLE* purpose is for a domain owner to
decide which hosts are allowed to send mail claiming to be from their
domain. nothing more, nothing less.
Tell that to all the people who incorporate SPF into their spam scoring
systems. :\
Well, you have to provide incentive for people to actually *implement* SPF.

Here's an analogy that might clear things up:

Suppose we had a problem with terrorists getting on airplanes and doing terroristy stuff. So, we start compiling a list of known terrorists (call it a realtime blacklist, or RBL). So, we start asking people their name before we let them on the plane and checking it against the list. But then, we find that the terrorists are giving us fake names. So.... we issue some ID cards (we'll call them "SPF" cards) so that it's harder for them to get away with giving a fake name.

Now, notice how the ID cards' primary purpose is to increase the effectiveness of the blacklists. Okay, fine. But... what do we do with the people who say they don't have their ID or, for some reason or another, don't provide it when asked? Well, if that doesn't count against them, then the terrorists would just show up and say "my dog ate it", and we'd let them on.

So, there has to be some penalty to not providing SPF. How *much* of a penalty is a dicey issue. If the penalty is *less* than the penalty for *providing* SPF *and* being on a blacklist, then the blacklisted domains would be rewarded if they turned off their SPF. If the penalty is *higher* than the penalty for providing-yet-being-blacklisted, then you'd get legitimate users (who haven't implemented SPF) getting spam scores higher than people on RBLs....

So, it's a bit of a puzzle.
and forcing everyone to shift to it.... you are joking, right?
Well they did force us to get new TV sets. :D  And France has managed to ram
the metric system down the whole world's throats. :(

That's different. In those cases, the existing system really sucked and was almost more trouble than it was worth. Oh, wait... :P

- Joe

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply to: