Re: [ietf-smtp] EHLO domain validation requirement in RFC 5321

John Levine <johnl@taugh.com> Sun, 27 September 2020 05:22 UTC

Return-Path: <johnl@iecc.com>
X-Original-To: ietf-smtp@ietfa.amsl.com
Delivered-To: ietf-smtp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B9BC63A0F2F for <ietf-smtp@ietfa.amsl.com>; Sat, 26 Sep 2020 22:22:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.851
X-Spam-Level:
X-Spam-Status: No, score=-1.851 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.249, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=iecc.com header.b=1MdBI8l5; dkim=pass (2048-bit key) header.d=taugh.com header.b=wYbt+RS7
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id exp3nTepjeYf for <ietf-smtp@ietfa.amsl.com>; Sat, 26 Sep 2020 22:22:28 -0700 (PDT)
Received: from gal.iecc.com (gal.iecc.com [IPv6:2001:470:1f07:1126:0:43:6f73:7461]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BBAAA3A0F2E for <ietf-smtp@ietf.org>; Sat, 26 Sep 2020 22:22:27 -0700 (PDT)
Received: (qmail 67366 invoked from network); 27 Sep 2020 05:22:23 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=iecc.com; h=date:message-id:from:to:cc:subject:in-reply-to:mime-version:content-type:content-transfer-encoding; s=10724.5f70218f.k2009; bh=9A1SYaNcMDtUMTEx1d/5TTgPBqGGSU1PFkOGbmERshE=; b=1MdBI8l564980OtNCAGNNa302QtCNfVO8utZLhFN84qufcbV6M70LguQgdT5KeTpA8DYJh9+o6/lRT/oYcCaUgipP88nZRdZfnfidRyO/iKdKPf8oqoiMgWdVf3P1J99NCsvzU3UPum3HKxe86eUM2oBPM/frdhOB2qll4TFPmOsq51/6XtyKmrfEPjJHdmBivtOVUzdvx9GIyIcyDeyWn2ZMMJ+3OeChq07dtikhOGZOpmWzvg0T7vJic3YClsFICnWSQ7UONrHXnpvOGc02LDj7hG2mrmtKWqMeypdBUDsGbHlkC/8PwL5fkpd5VtA2YWwW4imVW8CFevh3vwjKw==
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=taugh.com; h=date:message-id:from:to:cc:subject:in-reply-to:mime-version:content-type:content-transfer-encoding; s=10724.5f70218f.k2009; bh=9A1SYaNcMDtUMTEx1d/5TTgPBqGGSU1PFkOGbmERshE=; b=wYbt+RS70eeALUTeH1cq/WH+xZ+XZ7UGqMn0HrLIa5eKgGu17Oj7B0E2criDWOgYvQHbk24dMoo2slmAr0cPUedqmjeiMxHomsS7IlL0xoNJLKDBR2J5VuWSzOpYox2/PTfDiEXZH5BfAvy4nL6Wg+Xom4oDZVzszmGZ5QSqMtt5qaoRR93ryBwOWNwWBqsrKS9lcAYcv0q1HlaXBzrEvShLpyyOgh7shjQEVDFiSwEC0x51kP/T8qDFbDqZuty/0rJI70TS1wWnWRZYj9TBsXq3JKkjEes1cPsl5lI/Q1467rOfnHGDj8XgGk9C15K09vpJvsRpvld0QCq4t7E4cQ==
Received: from ary.qy ([IPv6:2001:470:1f07:1126::78:696d:6170]) by imap.iecc.com ([IPv6:2001:470:1f07:1126::78:696d:6170]) with ESMTPS (TLS1.2 ECDHE-RSA AES-256-GCM AEAD) via TCP6; 27 Sep 2020 05:22:22 -0000
Received: by ary.qy (Postfix, from userid 501) id E0A1A21D3A2D; Sun, 27 Sep 2020 01:22:21 -0400 (EDT)
Date: Sun, 27 Sep 2020 01:22:21 -0400
Message-Id: <20200927052221.E0A1A21D3A2D@ary.qy>
From: John Levine <johnl@taugh.com>
To: ietf-smtp@ietf.org
Cc: moore@network-heretics.com
In-Reply-To: <da460777-824b-1f13-be7c-32bfa9664d02@network-heretics.com>
Organization: Taughannock Networks
X-Headerized: yes
Mime-Version: 1.0
Content-type: text/plain; charset="utf-8"
Content-transfer-encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf-smtp/ifaMmCb7WSwGBdFoEwaArIjHjf8>
Subject: Re: [ietf-smtp] EHLO domain validation requirement in RFC 5321
X-BeenThere: ietf-smtp@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Discussion of issues related to Simple Mail Transfer Protocol \(SMTP\) \[RFC 821, RFC 2821, RFC 5321\]" <ietf-smtp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf-smtp>, <mailto:ietf-smtp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf-smtp/>
List-Post: <mailto:ietf-smtp@ietf.org>
List-Help: <mailto:ietf-smtp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf-smtp>, <mailto:ietf-smtp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 27 Sep 2020 05:22:30 -0000

In article <da460777-824b-1f13-be7c-32bfa9664d02@network-heretics.com> you write:
>On 9/18/20 6:36 PM, Sam Varshavchik wrote:
>>
>> Courier has an optional setting that can be enabled, that verifies 
>> that "the domain name argument in the EHLO command actually correspond 
>> to the IP address". I have it enabled. It's one of my most successful 
>> spam filters. ...

>At some point in the past, this was _not_ a reliable spam filter. ...

I think you may be conflating SMTP and submission. For submission,
you're right, the EHLO argument is frequently some random name that a
computer thinks it has behind a couple of layers of NAT. For SMTP,
server to server, I agree with Sam that it is extremely rare for a
legit message to come from a host that doesn't know its name.

R's,
John