Re: [taugh.com-johnl] Re: Problems with SPF, solutions, and a
Hadmut Danisch <[email protected]> Sun, 29 Feb 2004 01:12:46 +0100
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <[email protected]> |
On Sat, Feb 28, 2004 at 06:58:17PM -0500, John R Levine wrote: > > Once again, I hear "if we can't do something useful, we'll do something > useless instead." No. we're not going to do that. It's a bad style to call it "useless" because it doesn't match your personal taste. You did not give any reason for why it should be useless. You expect to have a method which protects against spam directly. There is currently no such method, because as far as it is known, there is no technical way to do this, because there is no technical way to detect spam reliably. However, spam can be outlawed, which is a non-technical method. Outlawing is/can be effective against spam, but only if you know whom to blame for. This requires to protect against forgery. Furthermore, sender verification enables black and whitelisting, which is completely impossible at the moment. And, as I proposed in RMX, sender verification allows to find the correct whois entry for the sender's domain. If this entry doesn't contain a reliable human or contains a blacklisted human, then mail can be rejected. Spammers can have plenty of throwaway domains, but they can not have plenty of throwaway identities. At least not under reasonable legislations. The next step would be to blacklist those legislations which allow throwaway identities for spammers. I don't see why this should be "useless". You're continuosly assuming that sender verification is "useless", but you still did not explain why. Could you please elaborate your opinion and what you'd except? Hadmut