"David L. Nicol" spake unto me and said:
> 
> what keeps spammers from faking envelope-from and using
> include-in-bounce features to relay spam content?  

Nothing; see <http://cr.yp.to/docs/mailabuse.html> for this and other
more heinous possibilities.

> Is it possible that a subject of "failure notice" will
> some day not be sufficient to prevent this possibility?

It's not clear what you mean. If you destroy bounces, you prevent that
attack; however you also prevent people from seeing legitimate bounces.
In general, it is impossible to make bounces unforgeable.

Len.

Reply via email to