SMTP RFC: "MUST NOT" change or delete Received header

"Kevin M. Gallagher" <kevin@ageispolis.net> Sat, 29 March 2014 06:59 UTC

Return-Path: <kevin@ageispolis.net>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3C7721A0781 for <ietf@ietfa.amsl.com>; Fri, 28 Mar 2014 23:59:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.113
X-Spam-Level:
X-Spam-Status: No, score=-0.113 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bFEG6SXjlP5d for <ietf@ietfa.amsl.com>; Fri, 28 Mar 2014 23:59:04 -0700 (PDT)
Received: from ageispolis.net (ageispolis.net [207.12.89.97]) by ietfa.amsl.com (Postfix) with ESMTP id E964D1A077D for <ietf@ietf.org>; Fri, 28 Mar 2014 23:59:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ageispolis.net; s=default; t=1396076341; bh=4ryQx6QIZjnm+dWEdM3Bfe8D0tz9xNjHWzpZsoG2O1A=; h=Date:From:To:Subject:References:In-Reply-To:From; b=Ux2CLFngFCdWf9EZJY8oLl/KDC2YbCKxDjbqekS9tWN/+chwFqh1r0qrfq7MMvy3C LlKU4IZYvVcm2talz/Nbz/hgYykerCIzGiZHXqr18BbZgC1vr97kdeTyAqsaUjA631 vrXFpxVFlQlKDfzfu6Njd4GAygvnI4MJ6e1pydbT6pdFpSCsf6ntGr6SDFODSmMgre 0PFqmp8bMC2BXmBdutU80itRhoOAQPy/HGpeSiQz16mE14cdtq+MAAaWlayMs0uc2F 7oFdr80PpPVhgVRGyUgvVezI3BGV59JGy51eEBAmvaZEwx1l7pw3/TZo1A73URuYvV Gt4H0XTLYkDZQ==
Message-ID: <53366F34.8050501@ageispolis.net>
Date: Sat, 29 Mar 2014 02:59:00 -0400
From: "Kevin M. Gallagher" <kevin@ageispolis.net>
MIME-Version: 1.0
To: ietf@ietf.org
Subject: SMTP RFC: "MUST NOT" change or delete Received header
References: <mailman.1570.1395964793.2468.ietf@ietf.org>
In-Reply-To: <mailman.1570.1395964793.2468.ietf@ietf.org>
OpenPGP: id=5921D69C; url=https://ageispolis.net/kmggpg.asc
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/ietf/tU_ZbnQ0S3Qmqlsr2fXZ-XksFyQ
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 29 Mar 2014 06:59:05 -0000

What do people today think of the SMTP RFC's current requirement that
mail programs and servers must not under any circumstances change or
delete Received: headers? Is exposing sender IP addresses to any
attacker who can view e-mail headers, for the purposes of preserving
trace information, really worth it when weighed against considerations
like security and privacy?

http://tools.ietf.org/html/rfc5321#section-4.4

Kevin
@ageis
0x5921D69C