On Fri, July 25, 2008 14:05, Scott Kitterman wrote:

> Based on the example, he's whitelisting based on Rcpt To. In my counter
> example the local domain is being used in both Mail From and Rcpt To, so

dont test spf on this 2 headers

> the only domain's SPF that might enter into this is his own.

wroung, see headers from this maillist

> SPF can be used to reject such messages, but there are other ways to
> do it for your own domains.

i have seen one sending back bounces to maillist with my email as return-path

very cleever done when i see the bounce

> The policy service does not have access to the message body, so no DKIM
> either.

yes a shame dkim does not integrade well, but atleast if it works in
postfix we can downgrade to sendmail and keep our milter setup stilll
going, with is not bad at all

> A domain level whitelist function based on SPF Pass or good DKIM
> signatures would potentially be useful (no way to do the latter
> in a policy server in any case), but that doesn't seem to be
> what's on offer here.

policyd-weight have missed spf and greylist for so long now, if this was
weighted 2 then it was good, do greylist when spf fail, or skip greylist
when spf pass

-- 
Benny Pedersen
Need more webspace ? http://www.servage.net/?coupon=cust37098

Reply via email to