Re: To email or not to email...

Huey Callison <[email protected]> Sat, 23 Oct 2004 10:46:03 -0400
Newsgroups gmane.ietf.asrg.abuserep
Message-ID <[email protected]>
Bruce Brown wrote: 
> My concern is that those reporting abuse are also themselves,
> being abusers - at least it will happen in some cases. This leads to the
> problem that if you're blocking mail from abusers, you're not going to
> receive abuse reports from them via email.

Yes, but just as there are some customers you don't want, there are
some abuse complaints you just don't need.

On 23 Oct 2004 13:06:48 -0000, John Levine <[email protected]> wrote:
> My experience running abuse.net tells me that the sites that are so
> badly mismanaged that they get blocked don't send enough useful abuse
> reports to worry about.  As Suresh points out, if people really want
> to get in touch with you, they can and do use a Yahoo or Hotmail or
> AOL/Netscape account.
> Another way to look at it is that this gives them an added incentive
> to clean up their own acts.

I'm not sure how much of the previous discussion on this list has
dealt with the overwhelming majority of hand-generated complaints from
individuals, which are varying degrees of worthless. For example, some
of these go to netblock owner or the trailing RHS of the rDNS of every
machine in a traceroute from the spam recipient to... ...well,
somewhere, not always having anything to do with the spam, some go to
IANA, some say simply "YUOR HAKCING MY PORT 53" or "STOP SENDING
SPAM", some get sent to every publicly-available localpart in your
company's corp mail domain... ...I understand that abuse@ and
postmaster@ are supposed to be unfiltered, but I see no reason to pass
on to my abuse desk complaints that are effectively worthless, and
would suggest that abuse@ and postmaster@ be _differently_ filtered.
Wm James doesn't need to send mail to my abuse desk, EVER, because
emails from him are demonstrably just a waste of time.

Having said all of that, if there were an agreed standard format for
abuse complaints, and you could build tools to generate those
complaints automagically, would there be fewer of them that are
totally worthless? If you could stick a "This is Spam" button on the
Outlook toolbar of every Aunt Edna, would her complaints be less of a
time-waster for my abuse desk?

Also, given the number of users who see "Report as Spam" as
"Unsubscribe me", Al Iverson suggested some kind of trusted
unsubscribe mechanism. Should that be tied into the protocol, or are a
certain number of the end-users pushing that button incapable of
making the distinction? Of course there are - but regardless of that,
should the ability to make that distinction be possible for those that
can? Suppose your 'Report as Spam' button has three possible values:
- I am certain I did not give permission for this, and it is definitely spam.
- I may have subscribed to this, or it may be spam. Unsubscribe me. 
- I subscribed to this, but no longer want it. Unsubscribe me.
and the value would default to the middle one unless the user is the
sort of pesky longhair geek that actually looks at configuration
options and reads helpfiles and stuff?

Just thinking out loud. Sorry for the rambling.

-- 
Huey