Quote:
Originally Posted by cgmckeever
The only issue is, that if I really want to post as the ADMIN, I could just set up a whole profile in thunderbird or outlook and truly send as that person. Then the script will still pass the tests and post as a fake author.
So, putting that test in limits people who use services like gmail but have multiple profiles.
|
You would have to have the password to login to the domain.
With yahoo I can go to the options, type whatever email name I want, and that would show up as me. I wouldn't need any passwords.
With outlook and thunderbird you have to have the password.
This is also why the error email that gets sent to you for the incorrect email address shows you the address that the modification sees you as having and has a link to update your email address
Your solution, doesn't require that people have a password or any access to the mailbox.
I'm not saying the method I'm using is perfect security... but it at least requires that you are on sending from the same domain as the email your trying to fabricate.
I'm sorry but I will not remove this feature for anything less then a more secure method.
Removing the prime security feature to me, is just not wise even if it's not the perfect method.