Re: [Asrg] misconception in SPF

Chris Lewis <clewis+ietf@mustelids.ca> Mon, 10 December 2012 16:36 UTC

Return-Path: <clewis+ietf@mustelids.ca>
X-Original-To: asrg@ietfa.amsl.com
Delivered-To: asrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B1C9721F84FB for <asrg@ietfa.amsl.com>; Mon, 10 Dec 2012 08:36:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.048
X-Spam-Level:
X-Spam-Status: No, score=-1.048 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FH_RELAY_NODNS=1.451, RDNS_NONE=0.1]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZStLrRB1zf30 for <asrg@ietfa.amsl.com>; Mon, 10 Dec 2012 08:36:48 -0800 (PST)
Received: from mail.mustelids.ca (unknown [174.35.130.2]) by ietfa.amsl.com (Postfix) with ESMTP id 5590B21F84CA for <asrg@irtf.org>; Mon, 10 Dec 2012 08:36:48 -0800 (PST)
Received: from [192.168.0.8] (otter.mustelids.ca [192.168.0.8]) (authenticated bits=0) by mail.mustelids.ca (8.14.4/8.14.4/Debian-2ubuntu2) with ESMTP id qBAGalon012826 (version=TLSv1/SSLv3 cipher=DHE-RSA-CAMELLIA256-SHA bits=256 verify=NOT) for <asrg@irtf.org>; Mon, 10 Dec 2012 11:36:47 -0500
Message-ID: <50C60F9E.1060202@mustelids.ca>
Date: Mon, 10 Dec 2012 11:36:46 -0500
From: Chris Lewis <clewis+ietf@mustelids.ca>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-GB; rv:1.8.1.23) Gecko/20090812 Thunderbird/2.0.0.23 Mnenhy/0.7.6.666
MIME-Version: 1.0
To: asrg@irtf.org
References: <20121206212116.10328.qmail@joyce.lan> <50C1A95A.5000001@pscs.co.uk> <50C4A7F8.3010201@dcrocker.net> <CAFdugamTbTirVV2zXKOmc9oTaCS+QiTemhT=jvYJnHYscHQK7g@mail.gmail.com> <0D79787962F6AE4B84B2CC41FC957D0B20ACE6D0@ABN-EXCH1A.green.sophos> <20121209213307.D90C12429B@panix5.panix.com> <CAFduganBR_E-ui-3Xbic6F7qSmg1-Q+ideXLvb+1isLz8OF0Nw@mail.gmail.com> <0D79787962F6AE4B84B2CC41FC957D0B20ACFFE1@ABN-EXCH1A.green.sophos> <50C5A9A0.105@pscs.co.uk> <0D79787962F6AE4B84B2CC41FC957D0B20AD01B2@ABN-EXCH1A.green.sophos> <20121210145627.GA21217@gsp.org> <CAFdugakdqoN7S2YuWEVHo_YaOZJTPKt1w7tdcn8oasB=gb+qcg@mail.gmail.com>
In-Reply-To: <CAFdugakdqoN7S2YuWEVHo_YaOZJTPKt1w7tdcn8oasB=gb+qcg@mail.gmail.com>
X-Enigmail-Version: 1.4.6
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Subject: Re: [Asrg] misconception in SPF
X-BeenThere: asrg@irtf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: Anti-Spam Research Group - IRTF <asrg@irtf.org>
List-Id: Anti-Spam Research Group - IRTF <asrg.irtf.org>
List-Unsubscribe: <http://www.irtf.org/mailman/options/asrg>, <mailto:asrg-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/asrg>
List-Post: <mailto:asrg@irtf.org>
List-Help: <mailto:asrg-request@irtf.org?subject=help>
List-Subscribe: <http://www.irtf.org/mailman/listinfo/asrg>, <mailto:asrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Mon, 10 Dec 2012 16:36:48 -0000

On 12-12-10 10:59 AM, Christian Grunfeld, christian.grunfeld@gmail.com
wrote:

> I'm really surprised to see how discussions diverges on this list !
> 
> The problem statement is very simple:
> 
> 1) How many people on this list saying that SPF is bad have TXT
> records published on their domains ? Why do you use it in real life
> and deplore it here ?

Maybe they're experimenting with DMARC.  Maybe they're listening to PHBs
who insist on it.  Maybe they wanted to get email into hotmail.

Or simply that that it's useless, and it don't matter whether they have
one or not.

> 2) How many people on this list that use SPF have only one TXT record
> at the top domain and remain relaxed having [?~-]all, ignoring this
> thread ?

See below

> I accept that some of you don't mind that a third party can use your
> subdomains to send forged emails claiming that are from you. I
> personally don't like that and applied the fix !

You mean like this?

_spf.google.com.	300	IN	TXT	"v=spf1 include:_netblocks.google.com ?all"