[93127] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: BCP38 thread 93,871,738,435 + SPF

daemon@ATHENA.MIT.EDU (Michael.Dillon@btradianz.com)
Fri Oct 27 05:57:44 2006

In-Reply-To: <1161895406.25707.100.camel@bash.adsl-64-142-13-68>
To: nanog@merit.edu
From: Michael.Dillon@btradianz.com
Date: Fri, 27 Oct 2006 10:59:12 +0100
Errors-To: owner-nanog@merit.edu


> How is this attack avoided?

Sounds like the attack is inherent in SPF. In that case,
avoiding it is simple. Discourage the use of SPF, perhaps
by putting any SPF using domain into a blacklist.
Eventually, people will stop using SPF and the attack
vector goes away.

--Michael Dillon


home help back first fref pref prev next nref lref last post