Re: Problems with SPF, solutions, and a timeline.

John Levine <[email protected]> 29 Feb 2004 03:24:54 -0000
Newsgroups gmane.ietf.asrg.smtpverify
Organization I.E.C.C., Trumansburg NY USA
Message-ID <[email protected]>
>> If ISPs want to deal with the hijacking problem, they can do it now
>> by looking at the mail traffic through their own servers.  They
>> don't need LMAP for that. nor will LMAP make it any more likely that
>> that do so.
>
>  Great!  Where's your proposal on how to deal with that problem using
>resources available in the network?
>
>  Oh... there isn't one.

ISPs that care have been dealing with this all along.  You count the
messages from each host, and if you see a big spike, you either
suspend the account or confine the host to a web jail that tells them
to disinfect their computer and call in to get out of jail after they
do.  The jail's like the one you're in when you connect to a hotel
network and haven't agreed to pay the ten bucks yet.  The mail spikes
are not subtle.  Hosts that normally send five messages a day start
sending blasts of thousands.  This is not a research topic, since ISPs
do this in production now and the techniques are well known.  It's
barely possible that a user might be sending mail to a list, but a
quick look at the logged envelopes makes it easy to tell if that's the
case.

I have to say that I'm kind of surprised that you're so unfamiliar
with this aspect of ISP operational life.

Regards,
John Levine, [email protected], Taughannock Networks, Trumansburg NY
http://www.taugh.com