Re: [taugh.com-johnl] Re: Problems with SPF, solutions, and a

"John R Levine" <[email protected]> 3 Mar 2004 10:42:40 -0500
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
> > ways that LMAP won't detect?  I don't see any other answer than that
> > it would be trivial for them to do so. If you're sending through a
> > hijacked PC, you use an address in the hijacked PC's domain.
>
> That's why I proposed dynamic authorization.
>
> It allows to limit the number of mails sent (e.g. per day or after
> business hours) by a PC or to detect if an PC is sending an unusual
> amount of mails. There is a solution to this.

Of course.  ISPs need to do that now.  But I don't see how LMAP makes any
difference, because they already know what their network ranges are.

> No, for two reasons:
>
> - Use an MUA which can display the envelope. Better MUAs do that.
>   Others will have to learn it.

I think a purported solution that expects that everyone will get a new MUA
isn't a very practical solution.

> - Spammer friendly domain resellers will certainly be blacklisted.

They aren't now, and we know who they are.  Why will LMAP make any
difference?

> I guess it take no longer than 6-12 months to trace the spammer friendly
> providers in a way that allows  blacklisting.

We know who the spammer-friendly providers are now.  See
http://www.spamhaus.org/rokso.  Why will LMAP make any difference?

Regards,
John Levine, [email protected], Taughannock Networks, Trumansburg NY
"I dropped the toothpaste", said Tom, crestfallenly.