SPF isn't a challenge/response mechanism.  It's a suggested extension to
current DNS practice that would allow organisations to specify which
mail systems are allowed to send mail for their domain (current practice
only allows you to specify which machines will receive mail for your
domain).  If such practice were widespread, it would enable mail admins
to reject any mail with an address if it didn't come from a
designated sender machine woth out even looking any further.

The basic idea is good but it faces the problem that it doesn't become
effective until the practice is widespread, which provides no incentive
for early adoption.

Note for the obstinate: like many other mail policies, SPF would only be
effective for an organisation if the policy were applied on *all* mail
exchangers, "backup" or no.


