Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Authenticate Us From Evil » Why no revision to SMTP to include authentication?
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
« limit the number of outgoing emails  

TamaraB
Question The Current Paradigm
Premium
join:2000-11-08
Brooklyn NYC
·Verizon Online DSL

Re: Why no revision to SMTP to include authenticat

said by fantomposter See Profile:

Spammer controls his domain. He can set up DNS and SPF any way he wants to point to any machine he wants.
Any machine with an A record within his domain.

said by fantomposter See Profile:
So he lists the comcast trojaned machine as his domains mail server. And SPF fails.

He can't! He is not listed as authoritave for comcast IP's, he can use a redirect mechinism, but that does the oposite of what he wants.

My smtp server gets a connect from that trojened comcast machine, my server checks with COMCAST DNS for spf, not his DNS...

Think of SPF as an extension of MX. Only a list of a domains allowed "sending" servers instead of receiving servers (MX).

Spammer is toast!
--
Motor Vessel - Tamara B. - 43' Long-Range Trawler Cape Elizebeth ME.»www.tamara-b.org
fantomposter
Phantom Poster
Premium
join:2002-09-21
Independence, OH

Re: Why no revision to SMTP to include authenticat

said by TamaraB See Profile:

He can't! He is not listed as authoritave for comcast IP's, he can use a redirect mechinism, but that does the oposite of what he wants.

I have not seen a spec on SPF that says you check IP addresses. It only checks the SPF records for the domain name in the from field.

quote:

My smtp server gets a connect from that trojened comcast machine, my server checks with COMCAST DNS for spf, not his DNS...

You got that backwards. That is not what SPF does. If I have that wrong point me to a website that explains it is otherwise.

All SPF does is check the authoritative DNS for the DOMAIN name in the from field. It checks the DNS records for that domain name and makes sure there is an SPF record that shows the sending computers IP address. If spammer controls his own domain name then he can put any IP address he wants in the SPF record.

Check here: »spf.pobox.com/faq.html

And scroll down to the part where the headline is:

"It doesn't really prevent spam. Spammers can always get throwaway domains, etc."

Don't get me wrong, SPF is needed, to fix the virus bounces and the forged from address's in spam, it does a great job of that, but not much more.
Forums » Authenticate Us From Evil« limit the number of outgoing emails  


Sunday, 06-Dec 01:00:17 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [147] Avast Antivirus Has Gone Mad
· [128] Comcast Makes NBC Universal Acquisition Official
· [122] The Bandwidth Hog Does Not Exist
· [105] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [85] FCC Ponders Moving From PSTN To IP Voice
· [82] Latest Consumer Reports Survey Not Kind To AT&T
· [80] New Bill Aims To Limit ETFs
· [75] Sprint Defuses GPS Privacy Media Bomb
Most people now reading
· False positive in Avast! or is it real? [Security]
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· First commercial tool to crack BitLocker arrives (Updated) [Security]
· RG Firmware update to VDSL2 this morning [AT&T U-verse]
· Unable to get incoming SIP with Callcentric [VOIP Tech Chat]
· Wife might have to work in.... Iowa for a few months!!! [General Questions]
· What is the spell hit cap for a lvl 80 full arcane spec mage [World of Warcraft]
· Using AirMax to provide triple play services? [Wireless Service Providers]