Re: Problems with SPF, solutions, and a timeline.
John Levine <[email protected]> 29 Feb 2004 03:24:54 -0000
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Organization | I.E.C.C., Trumansburg NY USA |
| Message-ID | <[email protected]> |
>> If ISPs want to deal with the hijacking problem, they can do it now >> by looking at the mail traffic through their own servers. They >> don't need LMAP for that. nor will LMAP make it any more likely that >> that do so. > > Great! Where's your proposal on how to deal with that problem using >resources available in the network? > > Oh... there isn't one. ISPs that care have been dealing with this all along. You count the messages from each host, and if you see a big spike, you either suspend the account or confine the host to a web jail that tells them to disinfect their computer and call in to get out of jail after they do. The jail's like the one you're in when you connect to a hotel network and haven't agreed to pay the ten bucks yet. The mail spikes are not subtle. Hosts that normally send five messages a day start sending blasts of thousands. This is not a research topic, since ISPs do this in production now and the techniques are well known. It's barely possible that a user might be sending mail to a list, but a quick look at the logged envelopes makes it easy to tell if that's the case. I have to say that I'm kind of surprised that you're so unfamiliar with this aspect of ISP operational life. Regards, John Levine, [email protected], Taughannock Networks, Trumansburg NY http://www.taugh.com