Who are the users of abuse reports?
Steve Atkins <[email protected]> Mon, 27 Sep 2004 19:58:50 -0700
| Newsgroups | gmane.ietf.asrg.abuserep |
|---|---|
| Message-ID | <[email protected]> |
This is a first cut of some thoughts on who the consumers of abuse
reports are, and some of what their needs are:
Reports of unwanted email are used by several different groups:
o End user ISP abuse desks
Primarily reporting compromised machines being misused to send
spam or host services. Mixed in with this will be a small number
of reports of directly abusive behaviour, lots of petty user
annoyances and the usual mixture of misdirected complaints.
Generally an IP address and a timestamp is enough to identify
the user responsible. In many cases (typical infected system)
that may be all the specific information needed, but in many
cases more may still be needed.
o Connectivity / colo abuse desks
The most complex case. A tier one provider will receive reports
about websites and sources of email from customers, customers
of customers and so on. There may be no direct contractual
relationship between the source of the problem and the provider,
but again the IP address and timestamp are enough to identify
the responsible user.
Many of the requirements of other recipients also apply to
large providers - as they'll have customers of the other
types and will need to pass complaints on to them for handling.
o Email Service Providers
ESPs send a lot of email and receive a lot of reports of unwanted
email. To identify the user responsible for the mail there needs
to be a way to identify the mailing responible - either the From:
address or a vendor-specific X-Header. To take appropriate action,
though, the ESP almost always needs the recipient email address.
There are several reasons for this. One is that many complaints
are about email the user actually asked for - in which case the
main sensible action to take is to ensure that the newsletter
owner unsubscribes the user who complained. In pretty much every
case a newsletter owner will state that the recipient asked to
receive the newsletter (or has a prior relationship with the
newsletter owner or somesuch). Often that's true. Often it isn't.
Unless there's overwhelming evidence (hundreds of complaints) the
only way to tell whether it's true or not is to challenge the
newsletter owner to provide subscription information.
(A rare exception to this need is when the mail was sent to a
spamtrap address, the list owner claims to be running a confirmed
opt-in list and the spamtrap owner is trusted, or at least
respected by the ESP. This is a pretty rare case, though.)
ESPs tend to track number and type of complaints to work out
which of their customers are problematic. But many of the complaints
they receive are inaccurate, so they also need some specific, accurate
complaints to challenge their customers with, to resolve whether
or not there is a real problem that needs to be addressed or not.
Easy automated categorisation and usable evidence are both needed.
An explicit differentiation between cases like "I subscribed to
this mail and don't want it any more", "I subscribed and can't
unsubscribe", "I bought something from the sender, but didn't
ask for this email", "I've never heard of the sender" and "This
is a role address, often harvested but never, ever subscribes
to anything" is extremely important data for an ESP.
o Email Marketers
Legitimate marketers sending their own email need reports for
several reasons. The most obvious is so they can stop sending
email to the recipient who doesn't want it. Another is so they
can monitor and handle internal processes to understand why
they're sending email to people who don't want it.
Handling complaints and unsubscription requests is also legally
required, so marketers are beginning to appreciate that handling
complaints is something they need to do.
o Spammers
Many spammers don't much care for reports - though most would
prefer you send them to the spammer rather than their provider.
A business-like subset of spammers doesn't want to send email to
recipients who expressly say they don't want it and do actually
add remove requests to their suppression list. CAN-SPAM may have
increased that fraction.
There's an argument that spammers shouldn't be allowed to maintain
suppression lists, and that a recipient of their spam should do
everything in their power to ensure the spammer keeps spamming
them. It's extremely difficult for a spammer to actually keep
below the radar simply by removing the email addresses of those
who complain, though, so that's not really a big issue in most
cases (spamtrap addresses used to maintain spam filters may
be an exception - but they're seldom, if ever, also used to send
reports by competent filter maintainers).
o Law Enforcement
Several government groups gather spam reports, [email protected]
for one. They use these for two main functions - firstly to
prioritise enforcement action and secondly to provide evidence
in that action. This data may not be used until years after the
original report in some cases, so it's even more important that
the report be self-contained - "Here's a brief report, email
me back for full information" or even "This report is brief
for your convenience, click here for more information" may not
be usable once action starts.
o Attorneys
Legal action against a spammer with the basis of a single
email is doomed to failure. Attorneys working on a civil
action against an accused spammer need evidence, and that's
often based on complaints sent to the spammers ISP. Again
the use of these reports is often many months or years after
the report was made originally.
o Third party reputations services
Such as Habeas or Bonded Sender (or even TrustE).
o Complainants
The report is obviously of use to the person making the report
or they wouldn't waste their time.
Some of the reasons people report email as spam.
o Not wanting to receive the email any more (whether it
was spam or not - many users use spamcop or "report as
spam" in both cases).
o Because their ISP told them to. AOL users in particular.
o Accidentally. A lot of AOL users report as spam mail they
never intended to due to UI limitations.
o Because they want to have the sender punished.
o Anger. The recipient wants to cuss out the spammer.(I get
forged as the sender in a lot of spam and the response range
from orders for the spammed product through friendly heads-up
that I'm being forged through unsubscription requests through
incoherent cursing and legal threats to fairly chilling death
threats).
o Because they want to alert the sender they have a problem.
This is the "hey, I like you as a company, but you're spamming
me" report - not as rare as you might think.
o As evidence for future legal action. Under most legislation
the fact that a recipient has asked for no further email and
email continues to be sent is extremely important.
EOF