SMTP VERP Service Extension
draft-nurpmeso-smtp-verp-03
This document is an Internet-Draft (I-D).
Anyone may submit an I-D to the IETF.
This I-D is not endorsed by the IETF and has no formal standing in the
IETF standards process.
| Document | Type | Active Internet-Draft (individual) | |
|---|---|---|---|
| Author | Steffen Nurpmeso | ||
| Last updated | 2026-08-04 | ||
| RFC stream | (None) | ||
| Intended RFC status | (None) | ||
| Formats | |||
| Stream | Stream state | (No stream defined) | |
| Consensus boilerplate | Unknown | ||
| RFC Editor Note | (None) | ||
| IESG | IESG state | I-D Exists | |
| Telechat date | (None) | ||
| Responsible AD | (None) | ||
| Send notices to | (None) |
draft-nurpmeso-smtp-verp-03
Network Working Group S. Nurpmeso, Ed.
Internet-Draft 3 August 2026
Intended status: Informational
Expires: 4 February 2027
SMTP VERP Service Extension
draft-nurpmeso-smtp-verp-03
Abstract
This specification makes official D. J. Bernstein's Variable
Envelope Return Paths: VERP.
Status of This Memo
This Internet-Draft is submitted in full conformance with the
provisions of BCP 78 and BCP 79.
Internet-Drafts are working documents of the Internet Engineering
Task Force (IETF). Note that other groups may also distribute
working documents as Internet-Drafts. The list of current Internet-
Drafts is at https://datatracker.ietf.org/drafts/current/.
Internet-Drafts are draft documents valid for a maximum of six months
and may be updated, replaced, or obsoleted by other documents at any
time. It is inappropriate to use Internet-Drafts as reference
material or to cite them other than as "work in progress."
This Internet-Draft will expire on 4 February 2027.
Copyright Notice
Copyright (c) 2026 IETF Trust and the persons identified as the
document authors. All rights reserved.
This document is subject to BCP 78 and the IETF Trust's Legal
Provisions Relating to IETF Documents (https://trustee.ietf.org/
license-info) in effect on the date of publication of this document.
Please review these documents carefully, as they describe your rights
and restrictions with respect to this document.
Table of Contents
1. Introduction . . . . . . . . . . . . . . . . . . . . . . . . 2
1.1. Conventions and Terminology . . . . . . . . . . . . . . . 2
2. Variable Envelope Return Path service extension . . . . . . . 2
3. Additional parameter for MAIL command . . . . . . . . . . . . 2
Nurpmeso Expires 4 February 2027 [Page 1]
Internet-Draft SMTP VERP Service Extension August 2026
4. Operational behavior . . . . . . . . . . . . . . . . . . . . 2
5. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 3
6. Security Considerations . . . . . . . . . . . . . . . . . . . 3
7. Normative References . . . . . . . . . . . . . . . . . . . . 4
8. Informative References . . . . . . . . . . . . . . . . . . . 4
Appendix A. Rationale . . . . . . . . . . . . . . . . . . . . . 4
Appendix B. Acknowledgements . . . . . . . . . . . . . . . . . . 4
Author's Address . . . . . . . . . . . . . . . . . . . . . . . . 4
1. Introduction
Since at least 1997 many mailing-list managers (and possibly other
email configurations) make use of D. J. Bernstein's Variable
Envelope Return Paths, or, short, VERP. As he rightfully wrote, on
1997-02-01: _Every application of RFC 1891's ORCPT and ENVID can be
handled with VERPs --- easily, reliably, and right now_. (This is
DSNs[RFC3461] at the time of this writing.) This specification
defines an according SMTP VERP Service Service Extension. With it,
undeliverable mail will reveal the recipient address simply through
the return path address.
1.1. Conventions and Terminology
This document uses the terminology of The Open Group Standard Base
Specifications, Issue 8, Volume 1, Chapter 1.6, Terminology.
2. Variable Envelope Return Path service extension
If a SMTP[RFC5321] server announces VERP in the list of EHLO keywords
(4.1.1.1, Extended HELLO (EHLO)), then VERP is supported.
3. Additional parameter for MAIL command
If VERP is supported, the extended MAIL command (SMTP[RFC5321],
4.1.1.2, MAIL) takes an additional VERP parameter.
4. Operational behavior
When a server supports VERP, and the client requested its usage for a
particular mail transaction, then it guarantees that each accepted
message recipient (SMTP[RFC5321], 4.1.1.2, RECIPIENT (RCPT)) will be
furtherly addressed with a copy of the message and a variable
envelope return path.
Nurpmeso Expires 4 February 2027 [Page 2]
Internet-Draft SMTP VERP Service Extension August 2026
The VERP is constructed by encapsulating the address of the
recipient, separated by a plus sign (U+002B, +), and the commercial
at (U+0040, @) being replaced with an equals sign (U+003D, =), in the
MAIL sender address, after the senders "local-part", before the
senders domain.
| For example, a hypothetic recipient _abc@def_ will be encapsulated
| in the hypothetic sender address _zyx@wvu_ as _zyx+abc=def@wvu_.
| _Informative remark:_ A sender may include additional variable
| constructs in its address, which must be taken into account when
| constructing the VERP. For example, if the VERP delimiter plus
| sign is already present, a separating hyphen-minus (U+002D, -) is
| appended to the VERP-delimited address part, followed by the
| otherwise unchanged VERP. In this example, a hypothetic recipient
| _abc@def_ will be encapsulated in the hypothetic sender address
| _zyx+bounces-1234@wvu_ as _zyx+bounces-1234-abc=def@wvu_.
The construction of the VERP happens when either a MTA is encountered
along the hops that does not support the VERP service extension, or
right before final delivery of an email message to a recipient,
whichever comes first.
| _Informative remark:_ This means that a SMTP server which supports
| VERP must take into account the need, and therefore be capable, to
| splice a single message with potentially many recipients into many
| messages with a single recipient and a dedicated VERP.
If the resulting VERP for a message recipient would exceed a SMTP
size limit ("local-part" must fit in 64 octets, the "reverse-path"
limit of RFC 821 and RFC 2821 is 256 octets), the recipient shall be
rejected with reply code 550, in conjunction with enhanced status
codes[RFC3463] 5.1.4 shall be used.
5. IANA Considerations
This document includes no request to IANA.
6. Security Considerations
Today, as by IETF means, SMTP trace headers etc need to be traversed,
or non-standardized, MTA-specific bounce message content has to be
parsed in order to find out (the) envelope recipient(s). Furthermore
more and more SMTP trace headers are seen which completely hide the
according information to the uppermost standard-compliant extend.
With VERP as a standardized extension, bounce processing can be made
a reliable task for one, and reveal only envelope content that the
sender intended to reveal.
Nurpmeso Expires 4 February 2027 [Page 3]
Internet-Draft SMTP VERP Service Extension August 2026
7. Normative References
[RFC5321] Klensin, J., "Simple Mail Transfer Protocol", RFC 5321,
DOI 10.17487/RFC5321, October 2008,
<https://www.rfc-editor.org/info/rfc5321>.
8. Informative References
[RFC3461] Moore, K., "Simple Mail Transfer Protocol (SMTP) Service
Extension for Delivery Status Notifications (DSNs)",
RFC 3461, DOI 10.17487/RFC3461, January 2003,
<https://www.rfc-editor.org/info/rfc3461>.
[RFC3463] Vaudreuil, G., "Enhanced Mail System Status Codes",
RFC 3463, DOI 10.17487/RFC3463, January 2003,
<https://www.rfc-editor.org/info/rfc3463>.
Appendix A. Rationale
This document only specifies VERP for senders. It could also be
specified for recipients, to cover more aspects of the referenced
DSNs[RFC3461].
This method of creating variable envelope return paths is in active
use on the internet for over the quarter of a century. The use of
the plus sign and the equals sign as delimiters seem to have not been
the cause of problems in real life.
Appendix B. Acknowledgements
Thanks to Roy Schulz of Utah University for attention. Thanks to
Wietse Venema of the postfix MTA, for adding VERP support in version
1.1 (released 20020117). The Exim MTA seems to have implemented it
pre-Y2K. D. J. Bernstein for documenting VERP, and implementing it
in his qmail MTA, back in 1997. (This, however, used different
delimiters: it used hyphen-minus and the equals sign, which is a bad
choice for other software as list names etc, they often regulary
contain hyphen-minus.)
Author's Address
Steffen Nurpmeso (editor)
Email: steffen@sdaoden.eu
Nurpmeso Expires 4 February 2027 [Page 4]