Re: Problems with SPF, solutions, and a timeline.
Hadmut Danisch <[email protected]> Wed, 3 Mar 2004 07:15:57 +0100
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <[email protected]> |
On Sat, Feb 28, 2004 at 09:39:31PM -0000, John Levine wrote: > > Since spammers have proven to be quick to adapt to changing conditions > here's the question: How hard would it be for them to adapt to LMAP > and either send spam that's LMAP compliant, or that's non-compliant in > ways that LMAP won't detect? I don't see any other answer than that > it would be trivial for them to do so. If you're sending through a > hijacked PC, you use an address in the hijacked PC's domain. That's why I proposed dynamic authorization. It allows to limit the number of mails sent (e.g. per day or after business hours) by a PC or to detect if an PC is sending an unusual amount of mails. There is a solution to this. And even if you use static authorization, you know whom to contact and inform. If the domain is not spammer friendly, they will immediately turn down this PC. This at least can block sending millions of mails. And if they get complaints too often, they will start to modify their mail infrastructure. Today they don't have a reason to do so. Once they became accountable, network administrators will take much more care about their network. > Or if > you're sending from anywhere else, you can either use throwaway > domains, or pick from a large random list of dusty old domains with no > LMAP. Since LMAP only checks the envelope, you can continue to forge > From: just like now so users won't see any less forgery than they do now. No, for two reasons: - Use an MUA which can display the envelope. Better MUAs do that. Others will have to learn it. - Spammer friendly domain resellers will certainly be blacklisted. And once you reliably know which domain the spam came from, you can fetch the whois record. You can reject mails if it does not give a responsible human. And you can blacklist this human. LMAP will not stop spam within a second as you can switch off the light. But it will allow to trace and blacklist spammer friendly organizations. I guess it take no longer than 6-12 months to trace the spammer friendly providers in a way that allows blacklisting. regards Hadmut