[82764] in Cypherpunks
ISP signatures on outgoing mail
daemon@ATHENA.MIT.EDU (Anonymous)
Thu Jul 3 14:31:17 1997
Date: Thu, 3 Jul 1997 18:14:07 +0200 (MET DST)
To: cypherpunks@cyberpass.net
From: nobody@replay.com (Anonymous)
Reply-To: nobody@replay.com (Anonymous)
Anyone heard of a proposal for ISPs to automatically sign outgoing
mail headers? Problem has been that spammers send email by one
path but forge a reply-to or from address at another location. Most
recent case is hotmail, which got blocked by netcom over a spam attack.
Actually mail didn't come from hotmail, was forged to look like it came
from there. Same thing has happened to remailers.
They need a standard for which headers to sign, then a dig sig can be
included in the headers to check that a message came from where it
claims.