Internet Engineering Task Force (IETF) R. Clayton
Request for Comments: 6692 University of Cambridge
Updates: 6591 M. Kucherawy
Category: Standards Track Cloudmark, Inc.
ISSN: 2070-1721 July 2012
Source Ports in Abuse Reporting Format (ARF) Reports
Clayton & Kucherawy Standards Track [Page 1]
RFC 6692 ARF Source Ports July 2012
Table of Contents
1. Introduction
[ARF] defined the Abuse Reporting Format, an extensible message format for Email Feedback Reports. These reports are used to report incidents of email abuse. ARF was extended by [AUTHFAILURE-REPORT] to enable the reporting of email authentication failures. These specifications provided for the source IP address to be included in a report. As explained in [LOG], the deployment of IP address sharing techniques requires the source port values to be included in reports if unambiguous identification of the origin of abuse is to be achieved.
2. Keywords
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in [KEYWORDS].
3. Source-Port Field Definition
A new ARF header field called "Source-Port" is defined. When present in a report, it MUST contain the client port of the TCP connection from which the reported message originated, corresponding to the "Source-IP" field that contains the client address of that same connection, thereby describing completely the origin of the abuse incident.
Clayton & Kucherawy Standards Track [Page 2]
RFC 6692 ARF Source Ports July 2012
"CFWS", which represents email-style comments or folding white space, is imported from [MAIL].
4. Time Accuracy
[LOG] underscores the importance of accurate clocks when generating reports that include source port information because of the fact that source ports can be recycled very quickly in Internet Service Provider environments. The same considerations described there apply here.
5. IANA Considerations
IANA has added the following entry to the "Feedback Report Header Fields" registry:
6. Security Considerations
This extension introduces no new security considerations not already covered in [ARF].
Clayton & Kucherawy Standards Track [Page 3]
RFC 6692 ARF Source Ports July 2012 7. References 7.1. Normative References[ABNF] Crocker, D. and P. Overell, "Augmented BNF for Syntax
7.2. Informative References
[LOG] Durand, A., Gashinsky, I., Lee, D., and S. Sheppard,
Clayton & Kucherawy Standards Track [Page 4]
RFC 6692 ARF Source Ports July 2012 Appendix A. AcknowledgementsThe authors wish to acknowledge the following for their review and constructive criticism of this proposal: Steve Atkins, Scott Kitterman, John Levine, and Doug Otis.