Re: Other SMTP verification methods
"Alan DeKok" <[email protected]> Tue, 02 Mar 2004 14:34:40 -0500
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <[email protected]> |
Yakov Shafranovich <[email protected]> wrote: > > e.g. an originating MTA "logs in" to a recipient MTA, using > > "[email protected]". The recipient MTA then somehow authenticates > > that user ID, using information published by "example.com". > > Wouldn't that be the same as the various callback systems? I'm not sure. I've skimmed over the callback documents, but haven't read them in detail. > It sounds pretty interesting. I am wondering if we are missing anything > like a spammer hijacking a computer that is part of the trust network or > perhaps a rogue member of the trust network. Trust can change over time. One element of trust is how much that trust has changed over time. It's better to have a consistent history of trust than a spotty one. > Something like senderbase perhaps? We had a discussion going on the main > list sometime back about a standard for blacklists and reputation > systems, and this sounds like a reputation system except the only factor > it lists is how long the IP has been an MTA. Such standard combined with > a database of existing MTAs might be interesting. The benefit is that the system is simple, easy to manage, and doesn't involve the maintainers making political decisions. Once the system is primed, participants could simply register a domain name, and the system could do DNS lookups every day/week/whatever, and keep the stats from there. Alan DeKok.