[Mailman-Developers] FYI -- mailback validations no longer safe?

Chuq Von Rospach chuqui@plaidworks.com
Sat, 9 Dec 2000 21:07:32 -0800


At 8:36 PM -0500 12/9/00, John A. Martin wrote:

>     CVR> received lines can be forged, but the one your server adds to
>     CVR> tell you who it got the mail from -- the direct connection --
>     CVR> can't be (or you have bigger problems).
>
>Would you unconditionally accept postings received at your list host
>from a backup MX?

I'd say it's up to the list admin. that's the advantage of allowing 
the admin to approve given IP addresses as approved addresses for 
that email. it can be dealt with on a case by case basis. And if you 
run into a case where an approved IP is abused, you remvoe it from 
the approval list and manually moderate those messages.



>

-- 
Chuq Von Rospach - Plaidworks Consulting (mailto:chuqui@plaidworks.com)
Apple Mail List Gnome (mailto:chuq@apple.com)

We're visiting the relatives. Cover us.