RFC 6692 Proposed Standard Reporting and feedback

Source Ports in Abuse Reporting Format (ARF) Reports

This document defines an additional header field for use in Abuse Reporting Format (ARF) reports to permit the identification of the source port of the connection involved in an abuse incident. This document updates RFC 6591. [STANDARDS-TRACK]

Status
Proposed Standard. On the standards track and stable enough to implement against. Most of the email stack stays at this level permanently.
Published
July 2012
Authors
R. Clayton, M. Kucherawy
Read it
rfc-editor.org · DOI

Normative requirements

Every sentence in this RFC carrying an RFC 2119 keyword, with the section it came from. 1 must, 2 should, 1 may.

3 Source-Port Field Definition

  • MUSTWhen present in a report, it MUST contain the client port of the TCP connection from which the reported message originated, corresponding to the "Source-IP" field that contains the client address of that same connection, thereby describing completely the origin of the abuse incident.
  • SHOULDWhen any report is generated that includes the "Source-IP" field (see Section 3.2 of [ARF]), this field SHOULD also be present, unless the port number is unavailable.
  • RECOMMENDEDUse of this field is RECOMMENDED for reports generated per [AUTHFAILURE-REPORT] (see Section 3.1 of that document).

4 Time Accuracy

  • MAYReport generators that include an Arrival-Date report field MAY choose to express the value of that date in Universal Coordinated Time (UTC) to enable simpler correlation with local records at sites that are following the provisions of [LOG].

Every current email RFC