spammers using SPF more than anyone else
Adam Back <[email protected]>
| Newsgroups | gmane.mail.spam.hashcash |
|---|---|
| Message-ID | <[email protected]> |
http://it.slashdot.org/it/04/09/03/1825214.shtml?tid=111&tid=95&tid=218 > SPF and Sender ID (SID) aren't nearly as effective as we expected > them to be when combatting spam. The reason? Spammers are able to > publish their own records, too. 'Spammers are now better than > companies at reporting the source of their e-mail,' says Paul Judge, > noted spam researcher and CipherTrust CTO. I've been trying to tell people this, now can say "told you so". SPF just forces spammers to jump through SPF hoops it doesn't stop them spamming. But you can't charge individuals much for SPF hoops, therefore spammers can create SPF hoops just fine. It turns out they can in fact create them more reliably than everyone else at present. Other nice quotes (from the article): > three times more spam passes SPF checks than fails it, > 34 percent more [SPF marked msggs] are spam than legitimate e-mail About the only good thing you could say about SPF is that if it got to 100% deployment, CAMRAM's current Sender address keyed whitelisting would be less risky. But at the cost of breaking many current email scenarios, and adding to roaming users config headaches I think it's a net loss. And domainkeys (or CAMRAM's discussed header signature based whitelists) if deployed 100% could achieve the same more simply. Adam