Drafted for the wrong fight
My friend [acp author=”Al Iverson” title=”SPF Still Matters in 2016″ id=”Iverson-01″ url=”http://www.spamresource.com/2016/03/spf-still-matters-in-2016.html” year=”2016″ month=”March” day=”7″ year_accessed=”2016″ month_accessed=”March” day_accessed=”7″ media=”blog”]{author} just wrote a new blog post: “{title}”[/acp].
One of the things that he said struck a chord with me: “‘But SPF is worthless,’ occasionally a spam fighter will cry.” It struck a chord with me because SPF wasn’t ever really intended to fight spam, per se. While there is perhaps some utility of it to receivers in helping to stem the tide of spam, that’s not SPF’s intention at all. In fact, if you have a look at the original versions of the [acp author=”Julian Mehnle” year=”2006″ month=”May” day=”9″ year_accessed=”2016″ month_accessed=”March” day_accessed=”8″ media=”website” title=”Introduction” id=”OpenSPF-01″ url=”http://www.openspf.org/?action=browse&id=Introduction&revision=4″ publisher=”OpenSPF”]{title} page of the {publisher}[/acp] website, you’ll see this quote: “The Sender Policy Framework (SPF) is a technical method to prevent sender address forgery.”
Now, if you do much reading at all, you’ll usually see SPF mentioned as an anti-spam method. But, it’s not that so much because it’s an anti-spam method, but instead it’s an anti-forgery method that can be useful in detecting the types of unauthorized mail that are often “spammy.” And, it’s worth noting that at its beginning, (predating even the OpenSPF website), [acp author=”John Leyden” title=”Spammers embrace email authentication” id=”Register-02″ year=”2004″ month=”September” day=”3″ year_accessed=”2016″ month_accessed=”March” day_accessed=”8″ media=”periodical” url=”http://www.theregister.co.uk/2004/09/03/email_authentication_spam/” publisher=”The Register”]{publisher} reporter {author}[/acp] noted that spammers had fully embraced the SPF standard and more spam was being sent that was authenticated by SPF than it was being used to authenticate actual good mail.
Fortunately, despite several blog posts and much ranting that SPF is harmful and doesn’t solve the spam problem by various hot heads, the standard stuck around. It’s true that SPF doesn’t solve the spam problem, but that’s because that’s not what it’s intended to do. The same thing is true of DKIM, and the more recent DMARC. None of these things are intended to solve the spam problem. They’re intended to allow one domain to assist another domain in determining the legitimacy of an email that has been received, in other words, they’re intended to provide a method to prove the authenticity of an email. To the extent that this is useful in fighting spam, that’s a good thing, but these authentication methods are not intended for that purpose.
Occasionally, we will see something drafted into service to help in a cause that it wasn’t intended to handle. When it works out to our advantage, that’s a good thing. But, we still shouldn’t be surprised that it’s not perfect.
Leave a Reply