On Thu, 18 Feb 2021 11:16:41 -0600, Lionel B Dyck wrote:

>XMITIP does not provide a digital signature and does not utilize a CA.  The 
>antispoof is a block of text with the senders userid/date/time jobname, jobid, 
>system name, node name, and user name that is added by XMITIP when sending any 
>email.
>
What anti-spoof protection does this provide?

Might a (fe)malefactor send a message directly via CSSMTP with
a counterfeit anti-spoof block?

Does CSSMTP add X-headers containing similar information?  Is
there a tool to verify the anti-spoof block?  Is that widely used?

Does anyone use XMITIP to post to IBM-MAIN?

Thanks,
gil

----------------------------------------------------------------------
For IBM-MAIN subscribe / signoff / archive access instructions,
send email to [email protected] with the message: INFO IBM-MAIN

Reply via email to