>Cool try explaining any of these terms to the average sysadmin.
if someone is managing a mail system and doesn't know what spf is, they should be immediately fired.
i am also not convinced this will remove or limit exposure to anything. the attack vector lives in the protocol, not the service used.
this might end up as a tiny, tiny blip in some small percentage of spammer/phisher operations.