Matching domain to sender.

David Lee t.d.lee at DURHAM.AC.UK
Wed Feb 2 15:12:21 GMT 2005

On Wed, 2 Feb 2005, David Curtis wrote:

> I have not seen this setting and thing that it might prevent a ton of
> spam. I may be wrong. Just your normal System super human
> traits.
> Can you run some rule to check the senders ip and or domain name and
> match that to the mail from address?
> Thanks for any comments.

It may not be as straightforward as it seems on the surface.

Who is the "sender", what is the domain name?

Example: let's imagine a legitimate mail list to which you and I might
both belong.  I, "me at", send a message to it, "list at",
hosted on machines at an ISP/university/etc. "".  You receive this
mail.  But who has been the "sender" from your perspective?

o  The visible "From:" contains my "": but that is several
    steps away from the transaction at your site;
o  The SMTP machine (probably the list expander) pushing it to you is
    "", which bears no direct relation to me (email
    originator) as "sender";
o  The envelope "From" contains "owner-list at", which doesn't
    directly trace back to the "" DNS names and addresses;
o  The visible "To:" contains "" (which, as a text string,
    bears no direct relation to your site).

So your "check the senders ip and or domain name and match that to the
mail from address" becomes non-trivial.

Note that an emerging technology, SPF, is designed to help to address the
email forgery aspects of the problem if, and as, it gains wider acceptance
and use.  Indeed, SpamAssassin 3.x is beginning to take account of it.
By its very nature, it needs time to ramp up.  (It has a few "no pain, no
gain" implications, but that's part of life in these spam-riddled days,
and no-one has yet come up with a better, and even more widely acceptable,

