Who are the users of abuse reports?

Steve Atkins <[email protected]> Mon, 27 Sep 2004 19:58:50 -0700
Newsgroups gmane.ietf.asrg.abuserep
Message-ID <[email protected]>
This is a first cut of some thoughts on who the consumers of abuse
reports are, and some of what their needs are:


Reports of unwanted email are used by several different groups:

 o End user ISP abuse desks

      Primarily reporting compromised machines being misused to send
      spam or host services. Mixed in with this will be a small number
      of reports of directly abusive behaviour, lots of petty user
      annoyances and the usual mixture of misdirected complaints.

      Generally an IP address and a timestamp is enough to identify
      the user responsible. In many cases (typical infected system)
      that may be all the specific information  needed, but in many
      cases more may still be needed.

 o Connectivity / colo abuse desks

      The most complex case. A tier one provider will receive reports
      about websites and sources of email from customers, customers
      of customers and so on. There may be no direct contractual
      relationship between the source of the problem and the provider,
      but again the IP address and timestamp are enough to identify
      the responsible user.

      Many of the requirements of other recipients also apply to
      large providers - as they'll have customers of the other
      types and will need to pass complaints on to them for handling.

 o Email Service Providers

      ESPs send a lot of email and receive a lot of reports of unwanted
      email. To identify the user responsible for the mail there needs
      to be a way to identify the mailing responible - either the From:
      address or a vendor-specific X-Header. To take appropriate action,
      though, the ESP almost always needs the recipient email address.

      There are several reasons for this. One is that many complaints
      are about email the user actually asked for - in which case the
      main sensible action to take is to ensure that the newsletter
      owner unsubscribes the user who complained. In pretty much every
      case a newsletter owner will state that the recipient asked to
      receive the newsletter (or has a prior relationship with the
      newsletter owner or somesuch). Often that's true. Often it isn't.
      Unless there's overwhelming evidence (hundreds of complaints) the
      only way to tell whether it's true or not is to challenge the
      newsletter owner to provide subscription information.

      (A rare exception to this need is when the mail was sent to a
       spamtrap address, the list owner claims to be running a confirmed
       opt-in list and the spamtrap owner is trusted, or at least
       respected by the ESP. This is a pretty rare case, though.)

      ESPs tend to track number and type of complaints to work out
      which of their customers are problematic. But many of the complaints
      they receive are inaccurate, so they also need some specific, accurate
      complaints to challenge their customers with, to resolve whether
      or not there is a real problem that needs to be addressed or not.
      Easy automated categorisation and usable evidence are both needed.

      An explicit differentiation between cases like "I subscribed to
      this mail and don't want it any more", "I subscribed and can't
      unsubscribe", "I bought something from the sender, but didn't
      ask for this email", "I've never heard of the sender" and "This
      is a role address, often harvested but never, ever subscribes
      to anything" is extremely important data for an ESP.

 o Email Marketers

      Legitimate marketers sending their own email need reports for
      several reasons. The most obvious is so they can stop sending
      email to the recipient who doesn't want it. Another is so they
      can monitor and handle internal processes to understand why
      they're sending email to people who don't want it.

      Handling complaints and unsubscription requests is also legally
      required, so marketers are beginning to appreciate that handling
      complaints is something they need to do.

 o Spammers

      Many spammers don't much care for reports - though most would
      prefer you send them to the spammer rather than their provider.
      A business-like subset of spammers doesn't want to send email to
      recipients who expressly say they don't want it and do actually
      add remove requests to their suppression list. CAN-SPAM may have
      increased that fraction.

      There's an argument that spammers shouldn't be allowed to maintain
      suppression lists, and that a recipient of their spam should do
      everything in their power to ensure the spammer keeps spamming
      them. It's extremely difficult for a spammer to actually keep
      below the radar simply by removing the email addresses of those
      who complain, though, so that's not really a big issue in most
      cases (spamtrap addresses used to maintain spam filters may
      be an exception - but they're seldom, if ever, also used to send
      reports by competent filter maintainers).

 o Law Enforcement

      Several government groups gather spam reports, [email protected]
      for one. They use these for two main functions - firstly to
      prioritise enforcement action and secondly to provide evidence
      in that action. This data may not be used until years after the
      original report in some cases, so it's even more important that
      the report be self-contained - "Here's a brief report, email
      me back for full information" or even "This report is brief
      for your convenience, click here for more information" may not
      be usable once action starts.

 o Attorneys

      Legal action against a spammer with the basis of a single
      email is doomed to failure. Attorneys working on a civil
      action against an accused spammer need evidence, and that's
      often based on complaints sent to the spammers ISP. Again
      the use of these reports is often many months or years after
      the report was made originally.

 o Third party reputations services

      Such as Habeas or Bonded Sender (or even TrustE).

 o Complainants

      The report is obviously of use to the person making the report
      or they wouldn't waste their time.

      Some of the reasons people report email as spam.

        o Not wanting to receive the email any more (whether it
          was spam or not - many users use spamcop or "report as
          spam" in both cases).

        o Because their ISP told them to. AOL users in particular.

        o Accidentally. A lot of AOL users report as spam mail they
          never intended to due to UI limitations.

        o Because they want to have the sender punished.

        o Anger. The recipient wants to cuss out the spammer.(I get
          forged as the sender in a lot of spam and the response range
          from orders for the spammed product through friendly heads-up
          that I'm being forged through unsubscription requests through
          incoherent cursing and legal threats to fairly chilling death
          threats).

        o Because they want to alert the sender they have a problem.
          This is the "hey, I like you as a company, but you're spamming
          me" report - not as rare as you might think.

        o As evidence for future legal action. Under most legislation
          the fact that a recipient has asked for no further email and
          email continues to be sent is extremely important. 

EOF