Search code examples
emailspam-preventionspfdmarc

Why don't we use FROM header in SPF


I was reading about SPF lately and got to know that SPF fails to identify spoofing when the spammer sends email with the envelope-from pointing to a domain that he/she controls and there is a completely different domain that the receiving client sees. I was just wondering why not do a check against the domain that the sender sees?

Thanks


Solution

  • I asked one of my colleagues as well. According to him, although spoofers can take advantage of SPF's design. But, it still makes it a bit harder to do that. Given that at the time SPF was created, nothing was there , so even not-so-good SPF was something to cherish about. Regarding, why not use the message-from, it was done to avoid breaking of mail forwarding mechanisms currently in place.