Re: IPv6 mail, was Let's try to be productive...
Barry Shein <[email protected]> Thu, 9 Jan 2014 17:10:41 -0500
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On January 9, 2014 at 21:44 [email protected] (Martijn Grooten) wrote: > > Apart from being able to drop the connection slightly earlier during the SMTP transaction, does this give you a significant advantage over just blacklisting (or whitelisting) individual email addresses? Something which I would think doesn't really scale. Dropping the SMTP transaction "slightly earlier" can be the Holy Grail of surviving these onslaughts. You have to sit here on a bad day when we're getting hundreds or even thousands of spam attempts per second, all the mail servers pegged, little or no legitimate mail getting through, phones ringing off the hook from customers who noticed they're not getting email, etc. Put an IP block at various levels -- depends on the details of the attack, but the earlier in the chain the better -- and watch everything come back to normal when you get it right. I assume that's roughly what AOL went through over the past few weeks when a lot of service providers (see the NANOG thread) noticed AOL seemed to be randomly blocking mail servers and even when unblocked would just return "Service Unavailable" for every SMTP delivery attempt generally after the DATA phase which is indicative to me that something was out of control. P.S. AOL seems ok now and has been ok for a few days. -- -Barry Shein The World | [email protected] | http://www.TheWorld.com Purveyors to the Trade | Voice: 800-THE-WRLD | Dial-Up: US, PR, Canada Software Tool & Die | Public Access Internet | SINCE 1989 *oo* - This is the asrg mailing list. To change your subscription settings, see http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org