Why don’t SMTP servers just require all senders to be authenticated before accepting mail?
Try an answer before revealing the guidance below.
Key Concepts
- SMTP relay
- Inter-domain delivery
- Authentication
- Open federation
Answer Approach
- Distinguish a user submitting mail from a remote server delivering it.
- Ask whether a receiving server shares credentials with every other mail domain.
- Consider what would happen to ordinary inter-domain delivery.
Full Answer
Answer status: Draft answer (unofficial). Revision notes, not an official marking scheme.
An SMTP server accepts mail from many other domains’ mail servers. Those remote servers generally do not share accounts or credentials with the receiving domain. Requiring every sender to authenticate locally would block ordinary inter-domain delivery. Submission servers can require authentication from their own users, while receiving servers use other anti-abuse controls.
Shortcuts: K concepts · A approach · F answer · R reviewed · B bookmark · ← / → previous / next