Gentoo Archives: gentoo-project

From: "William L. Thomson Jr." <wlt-ml@××××××.com>
To: gentoo-project@l.g.o
Subject: Re: [gentoo-project] Spoofing on list -> Infra response re SPF
Date: Mon, 05 Dec 2016 20:33:43
Message-Id: assp.0147ea5a05.1957347.8TJG1rhEKU@wlt
In Reply to: Re: [gentoo-project] Spoofing on list -> Infra response re SPF by Alex Xu
1 On Monday, December 5, 2016 3:11:44 PM EST Alex Xu wrote:
2 >
3 > SPF does not validate the From header in the first place, it only
4 > verifies the envelope sender. SPF is irrelevant to the concern of email
5 > sender spoofing from a user perspective.
6
7 I think that is a matter of how the software is validating the SPF record. I
8 have an inquiry into ASSP on this topic.
9 https://sourceforge.net/p/assp/mailman/message/35533609/
10
11 > > Also why is GPG signing no longer required?
12 > >
13 > > That alone can help ensure emails are coming from who they say they
14 > > are. Not sure how I was able to sign an email with an email not part
15 > > of my GPG key. Not sure if that is kmail bug or by design.
16 >
17 > I am fairly confident that it never was. I am fairly confident that no
18 > mainstream mailing list software checks GPG signatures.
19
20 Not sure, but I bet that is something that could be added to ASSP and may need
21 to be. I am asking else where first.
22
23 You can put things like ASSP a proxy in front of mailing lists. I did that for
24 some time. It takes some work, occasionally legit is rejected and I think some
25 spam made it through. But it does allot and is one of the few things that can
26 sit in front of mail servers.
27
28 --
29 William L. Thomson Jr.

Attachments

File name MIME type
signature.asc application/pgp-signature