OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: Question about "standards" WRT BATV and SAV

From: Arne Hoffmann (arnefish.in-berlin.de)
Date: Mon May 12 2008 - 09:10:31 CDT


Mike Selner wrote:
> To diagnose, I used telnet and smtpclient to manually probe their server
> to simulate SAV:
>
> An attempt to send from <> to MS.XXXXEXAMPLE.COM or
> prvs=MS.XXXX=0112a152aEXAMPLE.COM
> to either of their answering MX hosts 198.89.160.70 or 12.20.127.40
> results in:
> 550 #5.1.0 Rejected by bounce verification.
>
> This was tested a few minutes after receiving the above message to
> minimize the effects due to BATV timeout.

Is the host that you used for testing listed on ips.backscatterer.org? If
example.com is utilizing this list to reject bounces it would explain the
situation. Try testing from a host that is not listed.

> It appears to me that the above sender's implementation is broken since
> they do not accept mail from <>, and skipping SAV may be the most
> practical option for this RECIPIENT.COM domain.

... unless you want to maintain an extensive whitelist.