Re: Welcome to the new(ish) ASRG list
Matthias Leisi <[email protected]> Mon, 18 Mar 2013 13:59:45 +0100
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <CALgnk9oX65jAbeptOcKnr1yWzCK5C2vc81VT37csSiGC3Hg3fQ@mail.gmail.com> |
[Disclosure: I'm involved with dnswl.org] On Mon, Mar 18, 2013 at 11:23 AM, Paul Smith <[email protected]> wrote: > Surely the answer is to whitelist good servers rather than blacklist bad >>> servers >>> >> >> How do I end up on the whitelist? >> > > You ask to be on it. > > The way I'd do it would be to charge people, say, $10 per year per MTA IP > address to be on the whitelist (to fund the WL DNS servers) > Paying to be on a whitelist creates detrimental incentives for the list operator by creating conflicts of interest (list quality vs commercial incentives). Paying to use for the whitelist data ("rsync download" etc) is largely free of such conflicts of interest and is thus preferrable (although it vastly limits the commercial appeal of any such system). > This won't affect legitimate users much as it would only affect those with > the "final" MTA, so mostly ISPs, and businesses with their own MTAs. > To avoid central control, the system needs to be open with multiple organisations providing whitelisting services. Would a sender need to pay for each (widely used) such service? If an IP address spams a lot, then you remove it, and the owner has to > reapply to be on the whitelist (possibly paying more if this happens > frequently) How do you identify the "same owner"? This again creates an introduction problem. Not unexepectedly, I believe that whitelisting can play a greater role in the box of antispam tools in an IPv6 world than it plays in IPv4. I'm also realistic about its limits. -- Matthias