Why SPF? Why not Digital Signatures?

September 19th, 2004

Here’s what I’m confused about. Why SPF? Let’s recap what SPF does.

SPF says which machines on the internet are allowed to send email from a certain domain name.

Doesn’t digital signatures say who can send e-mail from a certain address? I mean it doesn’t know because nobody uses them. But what if it became the status quo, and we could just reject any e-mails without digital signatures. Then we can say so and so sent this message. I don’t care where he sent it from, I just know that unless his key was compromised this had to be him.

It seems like SPF is not only a rushed half-baked answer, but we have a better solution in place that we’re not using.

Comments are closed.