Re: Paul's Mailfrom (Was: IETF SMTP Working Group Proposal at smtpng.org)
Brad Knowles <brad.knowles@skynet.be> writes: [...]
Moreover, even if all servers on the Internet were secured in this manner and there were no open relays, it would also require perfect reverse DNS because the MXes are listed by name and not IP address -- that's assuming you do a reverse lookup on the IP address and require that the returned name is on the list.
The proposal suggests that you get all of the A records for all of the accepted names, then make sure that one of the A records matches the address that the connection came from. See sec. 2.3. Even if it did require good reverse DNS, that would only be needed for domains that chose to implement this, and only for addresses that are allowed to send mail from that domain. ----ScottG.
At 7:02 PM -0400 2002/08/26, Scott Gifford wrote:
The proposal suggests that you get all of the A records for all of the accepted names, then make sure that one of the A records matches the address that the connection came from. See sec. 2.3.
Right. And when they add a new mail gateway and don't tell you about it? What if they have forty-five of the damn things, each with its own unique name?
Even if it did require good reverse DNS, that would only be needed for domains that chose to implement this, and only for addresses that are allowed to send mail from that domain.
So, if you can't send mail out directly, you pass it on up to your ISP. And if they can't send the stuff directly, they pass it up another level. And so on. And you have to know all the possible IP addresses that could be used as exit points for your mail. Yeesh. Ya know, even X.400 wasn't this silly. -- Brad Knowles, <brad.knowles@skynet.be> "They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety." -Benjamin Franklin, Historical Review of Pennsylvania. GCS/IT d+(-) s:+(++)>: a C++(+++)$ UMBSHI++++$ P+>++ L+ !E W+++(--) N+ !w--- O- M++ V PS++(+++) PE- Y+(++) PGP>+++ t+(+++) 5++(+++) X++(+++) R+(+++) tv+(+++) b+(++++) DI+(++++) D+(++) G+(++++) e++>++++ h--- r---(+++)* z(+++)
participants (2)
-
Brad Knowles
-
Scott Gifford