Re: IPv6 mail, was Let's try to be productive...

Barry Shein <[email protected]> Thu, 9 Jan 2014 17:10:41 -0500
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On January 9, 2014 at 21:44 [email protected] (Martijn Grooten) wrote:
 > 
 > Apart from being able to drop the connection slightly earlier during the SMTP transaction, does this give you a significant advantage over just blacklisting (or whitelisting) individual email addresses? Something which I would think doesn't really scale.

Dropping the SMTP transaction "slightly earlier" can be the Holy Grail
of surviving these onslaughts.

You have to sit here on a bad day when we're getting hundreds or even
thousands of spam attempts per second, all the mail servers pegged,
little or no legitimate mail getting through, phones ringing off the
hook from customers who noticed they're not getting email, etc.

Put an IP block at various levels -- depends on the details of the
attack, but the earlier in the chain the better -- and watch
everything come back to normal when you get it right.

I assume that's roughly what AOL went through over the past few weeks
when a lot of service providers (see the NANOG thread) noticed AOL
seemed to be randomly blocking mail servers and even when unblocked
would just return "Service Unavailable" for every SMTP delivery
attempt generally after the DATA phase which is indicative to me that
something was out of control.

P.S. AOL seems ok now and has been ok for a few days.

-- 
        -Barry Shein

The World              | [email protected]           | http://www.TheWorld.com
Purveyors to the Trade | Voice: 800-THE-WRLD        | Dial-Up: US, PR, Canada
Software Tool & Die    | Public Access Internet     | SINCE 1989     *oo*
-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org