[RFCI-Discuss] Yahoo break RFC
jeff_pang at arcor.de
jeff_pang at arcor.de
Fri Nov 2 01:50:10 EDT 2007
----- Original Nachricht ----
Von: Frank Ellermann <omniplex at freenet.de>
An: rfci-discuss at lists.megacity.org
Datum: 02.11.2007 04:23
Betreff: [RFCI-Discuss] Yahoo break RFC
> ACK. However Jeff talked about a mail claiming to be from gmail.com
> forged by Yahoo. AFAIK the gmail.com SPF policy is PASS or NEUTRAL,
> therefore Yahoo's forgery only results in NEUTRAL, not in FAIL. In
> other words Gmail still permits to forge Gmail addresses. It would
> very stupid to reject all NEUTRAL mails.
>
Thanks frank. I in fact use yahoo to send mail with arcor.de address.
Arcor.de 's SPF was set to "~all", and yahoo MTA set "mail from:" address with the account of arcor's when in smtp talking session to other MTAs, so other MTAs which do the filters based on SPF will reject this message.
Viel oder wenig? Schnell oder langsam? Unbegrenzt surfen + telefonieren
ohne Zeit- und Volumenbegrenzung? DAS TOP ANGEBOT FÜR ALLE NEUEINSTEIGER
Jetzt bei Arcor: günstig und schnell mit DSL - das All-Inclusive-Paket
für clevere Doppel-Sparer, nur 29,95 inkl. DSL- und ISDN-Grundgebühr!
http://www.arcor.de/rd/emf-dsl-2
More information about the RFCI-Discuss
mailing list