[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Asrg] whitelisting server and not users



On Wed, Apr 02, 2003 at 09:05:35PM +0200, Markus Stumpf wrote:
> On Wed, Apr 02, 2003 at 07:34:34AM -0800, william@elan.net wrote:
> > It does not because of multiple problems like breaking mailing lists and 
> > forwarders and roaming users, only looking for enevelope from (while most 
> > users see header from and it can still be forged, etc). Here are
> > links about this (and similar) proposal that I gathered so far:
> 
> Maybe I didn't make it clear in my first post in this thread, but sorry,
> I can't
> a) see the problems described above
> b) see how the proposals in the list you provided do relate to my proposal
> 
> What I am proposing is:
>     mail.space.net	IN	A	195.30.0.8
> we will like other mailservers to accept mail from mail.space.net and
> indicate that by adding
>     8.0.30.195.in-addr.arpa	IN	TXT	"abuse@space.net"

Personally, I'd go a step further.  Associate an MTA connection with a
domain name.  In other words, require rDNS and use the host name returned
to look up a TXT record.  Using your above example, you'd have this:

mail.space.net.			IN	A	195.30.0.8
				IN	TXT	"abuse@space.net"
8.0.30.195.in-addr.arpa.	IN	PTR	mail.space.net.

For an MTA to be considered "valid" it must have both valid rDNS and a TXT RR.

My only concern is how to get this in widespread use, which would be required
before any severe penalty could be imposed on those that don't employ it.
-- 

Steven F. Siirila			Office: Lind Hall, Room 130B
Internet Services			E-mail: sfs@umn.edu
Office of Information Technology	Voice: (612) 626-0244
University of Minnesota
_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg