probably Pete Resnick:If we can't validate the domain of the From header, then we must inform the user that we validated something else.
--Harry Katz <hkatz@xxxxxxxxxxxxxxxxxxxxxx> wrote:I would agree with this, but as the above example points out, if there is going to be an easy way for spammers/phishers to avoid the From check, MUAs are going to have to start displaying stuff to the user other than just the From line. And if MUAs are going to have to start doing that anyway (and I agree they must), I don't see any *urgency* to focus our efforts at the >From line of the message, as Harry started this thread.
HKATZ: For the reasons I've stated above, you face the same requirement if you base the validation on MAIL FROM.
-- Greg Connor <gconnor@xxxxxxxxxxxx>