Re: [CORE] SPF Record ...

From: Dave Page <dpage(at)postgresql(dot)org>
To: "Marc G(dot) Fournier" <scrappy(at)hub(dot)org>
Cc: Peter Eisentraut <peter_e(at)gmx(dot)net>, pgsql-www(at)postgresql(dot)org, Andrew Sullivan <ajs(at)crankycanuck(dot)ca>
Subject: Re: [CORE] SPF Record ...
Date: 2006-11-20 08:28:07
Message-ID: 45616717.7080704@postgresql.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-www

Marc G. Fournier wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> the only way it wouldn't is if I
> could relay *through* gmx.net (I'm assuming that I can't?) so that not only am
> I impersonating you, but I'm doing it in such a way that the SPF record
> verifies that it is legit ...

Which is another reason why it doesn't work well - a large percentage
(perhaps the majority) of spam is sent through trojans running on poorly
secured Windows boxes. If Peter were running such a machine, yes, you as
an evil spammer could easily send spam as peter_e(at)gmx(dot)net through
mail.gmx.net.

SPF just legitimsed that spam :-(

Regards, Dave.

In response to

Responses

Browse pgsql-www by date

  From Date Subject
Next Message Andrew Sullivan 2006-11-20 13:57:12 Re: [CORE] SPF Record ...
Previous Message Joshua D. Drake 2006-11-20 03:42:21 Re: [CORE] SPF Record ...