Spamming...

"James Couzens" <[email protected]> Mon, 25 Apr 2005 11:01:38 -0700
Newsgroups gmane.mail.im2000
Message-ID <[email protected]>
This is a quick note in response to the lengthy e-mail I haven't finished 
reading yet by JCB: 

Subject: Re: Comments on IM2000
Date:     20 Apr 2005 18:01:19 -0000  (11:01 PDT) 

I wanted to interject with a question, which is if any of you have looked at 
SES which I have been developing with a few other "SPF alumni".  I would 
love to give up on the existing e-mail architecture but it appears that we 
are married to it for quite some time to come although I have long thought 
my time would be better spent aiding IM2000. 

If you have the time, give SES a look at: http://ses.codeshare.ca 

It is designed as a solution to the SPF forwarding problem, only we soon 
quickly discovered that SES could easily replace SPF and eliminate all of 
the DNS nastiness associated with SPF. 

I also wanted to respond to the "spammers just buy lots of domains" 
argument.  Whilst in a black and white argument, you are right, people can 
just buy more, if you expand the argument to encompass the overwhelming 
adoption of email as a communicative medium by the entire world, a "globally 
deployed" SPF could have strong value. 

Hear me out of course.. RHBL (Right Hand BL's) could be implemented.  RHBL's 
only work if domain names can't be spoofed.  But of course there is the 
delay in time between a domain name getting picked up as a new spamming 
domain and it getting into an RHBL.  I know this could be argued back and 
forth, and I realize that its still not an effective solution, it makes more 
sense to push for something like IM2000 hence why I have been working on 
SES. 

I'm looking to contribute to whatever helps combat smtp forgery now, but 
also provides a potential transitional move over to IM2000. 

Just my $0.02, not intending to start a pointless debate about SPF, please I 
know that SPF is not worth talking about, its all been hashed out, I just 
wanted to interject the point about RHBL's. 

I'm also not looking to start a discussion about SES specifically, but more 
so I wanted to see what was thought of this technique to prevent forgeries 
and if it has any relevence to IM2000. 

Cheers, 

James 

James Couzens,
Programmer
 -----------------------------------------------------------------
http://libspf.org -- ANSI C Sender Policy Framework library
http://libsrs.org -- ANSI C Sender Rewriting Scheme library
 -----------------------------------------------------------------