On 2021-11-30 12:24, Greg Troxel wrote:
Lots of people think SPF is silly. And spammers spamming from a domain they control can even dkim/dmarc.
Domain based reputation is an extremely powerful tool, but it is only useful when you know the actual sender of a message. The benefit isn't in blocklisting, it is enabling legitimate mail to get through while you can filter more aggressively.
This applies a lot less to smaller operations as you really need a large amount of data (and the skills to use it), but even at small scales being able to bypass spam filters for mail you know you want is incredibly useful, especially when you want mail from a particular company even though they use a garbage ESP or service provider that you would really rather block.