Re: How come couple of Chinese ISPs not getting blocked yet?
"Mike Easter" <[email protected]> Sat, 7 Jan 2006 14:33:25 -0800
| Newsgroups | gmane.mail.spam.spamcop.email |
|---|---|
| Organization | SpamCop |
| Message-ID | <[email protected]> |
Ilgaz Ocal wrote: > I get spam mainly from 2 ISPs in China. There are some very non-responsive .cn and .kr and other providers. > Based on what I know, system > works as follows: You are not correct in your understanding. > 1) User reports spam A spamcop reporter, quick reporter, or spamtrap submits a spam to the parser. The parser determine the spamsource on all 3 types of submissions. The spamvertisers are handled differently than the spamsources for reporters vs other.. > 2) As postmaster/admin you get a spam report telling you must fix the > issue in 48 hours and tell what you have done No. A spamsource pm/admin can refuse all SC reports, accept all reports and do whatever such as devnull them, or accept reports and act against the spamsource or secure it. There is no requirement for reporting back. Whatever the pm/admin does, the spamsource counts toward the SCbl unless the parse is a mistake and convincingly rebutted by the admin. SC is a parsing reporting system and a spamsource blocklisting system. SC is not a 'policeman' that some admin answers to. SC's only power is in the popularity of its blocklist with those who use it as a part of a spam defense plan. The notification process is a courtesy to spamvertiser providers - spamveriders - and spamsources. > 3) If you ignore that message or lie to Spamcop that it is fixed, you > get blocked. What happens as a consequence of a spamsource being reported is mathematical. If a sufficiently high number of spamsource reports are made compared to the 'traffic' or reputation of an IP address, the IP will be listed, regardless of whether an admin accepts or answers reports or not. Accepting and/or answering are immaterial. All that matters is how many spamsource reports there are compared to the traffic or non-spam activity of the IP. > So, how come these 2 open proxy heavens which I highly suspect that > are open on purpose doesn't get blocked by Spamcop? Your tracker showed a source 221.195.98.111 no rDNS of CNCGROUP Hebei Province which IP is CBL listed as an open proxy. SC doesn't provide us with the information about reports on unlisted IPs, but I can see at senderbase that the IP is usually not active, that it has been more active in the past month, and that its current activity over the last day is about zero. So, my guess would be that it might have been SC listed in the past month, but not necessarily, and that there aren't too many reports on it. It has been listed at CBL since yesterday. > I mean, is there anything special? Also will there be a filtering > system in future that will check spam sites in mail too? I don't know what that sentence means. > Here, just a random example. > www.spamcop.net/sc?id=z853256549zda560ff3f051cd753253384280f95733z > > As I said, 90% of spam to my account is from China. With my spamfilter, I could filter out all of my spam from .cn IPs, and I could whitelist any known goodmail from .cn IPs I was going to get. Your tracker also shows that the item was recognized as spam by your SC filtering. -- Mike Easter kibitzer, not SC admin