On 3/2/2005 12:33 AM, List Mail User wrote:

> you can do whatever you like, I'd recommend at least doing more than just a
> simple check for the names being identical

I don't care if the names don't match (although somebody else might). My
goal with this particular lookup is to weight identifiers that don't have
any reverse DNS, that is all. Postfix supports this internally already but
there are way too many FPs for these checks, there are too many possible
errors (including delegation burps), and so forth. Given that SA is
supposed to be about managing probabilities ... seems like a good place to
do the checking is inside SA.

Same thing goes for SMTP versus ESMTP. If they are using HELO they are
probably malware, and I'd like to be able to test on this.

I'd like to be able to poke at TLS data so that I can assigne a negative
weight, since functional TLS is a good indicator of a well-managed network
(not proof, but again, we are talking about probabilities)


-- 
Eric A. Hall                                        http://www.ehsco.com/
Internet Core Protocols          http://www.oreilly.com/catalog/coreprot/

Reply via email to