Co-operating with forgery-checkers: case SPF

Reijo Korhonen <[email protected]> Fri, 08 Oct 2004 01:17:19 +0300
Newsgroups gmane.mail.spam.active-spam-killer.general
Organization Reijo.local
Message-ID <[email protected]>
Hi,

I get a lot of spam with forgery from-field as most of us do. One 
solution would be is to put this kind of mail into trash at once. Now 
Ask sends confirmation maybe to wrong people and this is not good thing. 
My ISP thinks also so and they thougt I was a spammer, because a lot of 
mails looking like a spam was sent from my machine.

My idea is to use spf <http://spf.pobox.com/>. Spf-check libspf2 
<http://www.libspf2.org> includes headers like this

Received-SPF: fail (spfquery: domain of testdomain does not designate 
1.2.3.4 as permitted sender) client-ip=5.6.7.7; 
envelope-from=testsender@testdomain;

If I add lines like

header ^Received-SPF: fail

in my ignorelist-local.txt, them Ask won't send confirmation request to 
those forgerys that spf find out. My ISP would like this very much!

My project is still at work state, needs some procmail script to analyse 
email origin ip and sender to check, but if some are interested, I will 
report later, how I succeeded.

Spf in not only solution. Maybe it would be good idea to chain these 
forgery finders, but I start with spf.

Another idea. I would like to accept digitally signed mail from my 
private keyring. I know that this can be done using procmail, headers 
and adding that header into my whitelist. Not time to touch that for a 
while.

-- 
Reijo Korhonen




-------------------------------------------------------
This SF.net email is sponsored by: IT Product Guide on ITManagersJournal
Use IT products in your business? Tell us what you think of them. Give us
Your Opinions, Get Free ThinkGeek Gift Certificates! Click to find out more
http://productguide.itmanagersjournal.com/guidepromo.tmpl