[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Asrg] whitelisting server and not users
On Wed, Apr 02, 2003 at 09:05:35PM +0200, Markus Stumpf wrote:
> On Wed, Apr 02, 2003 at 07:34:34AM -0800, william@elan.net wrote:
> > It does not because of multiple problems like breaking mailing lists and
> > forwarders and roaming users, only looking for enevelope from (while most
> > users see header from and it can still be forged, etc). Here are
> > links about this (and similar) proposal that I gathered so far:
>
> Maybe I didn't make it clear in my first post in this thread, but sorry,
> I can't
> a) see the problems described above
> b) see how the proposals in the list you provided do relate to my proposal
>
> What I am proposing is:
> mail.space.net IN A 195.30.0.8
> we will like other mailservers to accept mail from mail.space.net and
> indicate that by adding
> 8.0.30.195.in-addr.arpa IN TXT "abuse@space.net"
Personally, I'd go a step further. Associate an MTA connection with a
domain name. In other words, require rDNS and use the host name returned
to look up a TXT record. Using your above example, you'd have this:
mail.space.net. IN A 195.30.0.8
IN TXT "abuse@space.net"
8.0.30.195.in-addr.arpa. IN PTR mail.space.net.
For an MTA to be considered "valid" it must have both valid rDNS and a TXT RR.
My only concern is how to get this in widespread use, which would be required
before any severe penalty could be imposed on those that don't employ it.
--
Steven F. Siirila Office: Lind Hall, Room 130B
Internet Services E-mail: sfs@umn.edu
Office of Information Technology Voice: (612) 626-0244
University of Minnesota
_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg