Spammers are sending spam, forging my (non-gmail) address as the FROM
address in SMTP, to gmail-hosted mailboxes (I don't know the
victims). Luckily I have an SPF record set for my address's domain,
and gmail does the Right Thing and stops those spam emails being
delivered. However, gmail is being evil by sending bounce messages
back to my address (which it shouldn't, given it knows that address is
forged).
In summary: Message Delivery Notifications due to SPF hard failures
SHOULD NOT be delivered.
This is only an annoyance at the moment, but since the amount of spam
in the world is only going to increase, and presumably the amount of
spam sent forged in my name will increase proportionally, it means
I'll be receiving more bounce messages unless this bug is fixed. It
reduces the utility of having an SPF record if I take collateral
damage the more spam gets blocked by SPF.
Full bounce message here: http://scarff.id.au/blog/2008/google-spf-bounces/
Will google fix this?