> What is the functional or security reason for verifying that > the domain exists, in terms of ASP.
The short answer is in 3.2, where there's a different answer for "I dunno" and "doesn't exist". As I recall, it's always been that way, but that's a good question. There's certainly plenty of reasons to be wary of mail with a return address that doesn't exist, but baking that into ASP does feel like mission creep, doesn't it? _______________________________________________ NOTE WELL: This list operates according to http://mipassoc.org/dkim/ietf-list-rules.html
