Re: [taugh.com-johnl] How accountability helps
"John R Levine" <[email protected]> 28 Feb 2004 17:07:36 -0500
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <[email protected]> |
> If we can get that spam path to use the ISP's domain name in the > outbound mail, I really think those ISPs will start clamping down. People who run large e-mail systems tell me that there are medium sized broadband ISPs right now where 90% or more of the mail passing through their outgoing mail relays is spam from hijacked PCs. They know it, the recipient systems know it, their only response has been to buy more mail hosts. Why would they be more likely to solve their problem if the spam had their address in the envelope? Their reputations are mud now. > - getting that spam path to not use my ISP's domain name. That's the joe job problem. It's down in the noise. > - getting that spam path to not use any other reputable domain name. Now we're back to what's reputable, and why we think that a reputation system could keep up with the names that spammers use. We're a long, long, long way from the day when anyone would dare to use the absence of reputation one way or the other to reject mail. > I believe there is a positive adoption dynamic there; reputable domains > don't want to be named in spam. In just a few months SPF has seen > tremendous grassroots response with many thousands of domains > publishing. Wow, that's almost 1/100 of 1% of the domains that are used in e-mail. If we get .01% adoption per month, we'll have the problem licked in the year 3600. Even if we assume that takeup increases by 50% every two months, that's still five years to get to half of the domains which I'd say would be a minimum to argue that you can reject the ones that aren't listed. We have to do something sooner than that. SPF may well be useful for something, but as a standalone measure, I really don't get it. Regards, John Levine, [email protected], Taughannock Networks, Trumansburg NY "I dropped the toothpaste", said Tom, crestfallenly.