At 11:54 AM +0000 1/28/08, Charles Lindsey wrote:
I think all you need, as Frank has pointed out, is a security
consideration to the effect that

"Verifiers should be aware that Bad Guys may attempt to subvert the
intentions of SSP by submitting messages that are non-compliant with RFC
2822 (for example by using empty From headers, mutiple From headers, Etc
{i.e. list a few examples, but not too may }).

That seems like a good resolution to this long thread.

--Paul Hoffman, Director
--Domain Assurance Council
NOTE WELL: This list operates according to

Reply via email to