Re: limitations of reputation, was Spam sent from compromised

Steve Atkins <[email protected]> Mon, 25 Mar 2013 11:06:10 -0700
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On Mar 25, 2013, at 10:58 AM, Barry Shein <[email protected]> wrote:

> 
> On March 24, 2013 at 10:07 [email protected] (Neil Schwartzman) wrote:
>> 
>> SPF and DKIM can DMARC solve the problem of people purloining from domains and sending phish/malware etc.
>> 
>> They are completely ineffective, of course, for look-alike domains, which are 80-90% of the problem.
> 
> Look-alike domains are 80-90% of the problem?

If they're not now, they will be once malware / phish authors notice DMARC deployment.

> I'm not sure what they even are, do you mean like bankoamerica.com
> (note missing 'f')?

Yes, that.

> Definition please.

A domain that is not byte-identical to the protected domain, but which could
conceivably be accepted as a legitimate domain owned by the same owner.

Typo-style, as you suggest, is one type.

Related word is another - e.g. paypalbilling.com

Spot the TLD is another - e.g. paypal.com.http0.ru

Homographs are another - e.g. paypa1.com (or the much trickier unicode variants).

Punycode-encoded ascii could be another approach, but I've never seen a registry that'll let you get away with that.

Cheers,
  Steve

-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org