Re: Understanding dsbl?
"John E. Malmberg" <[email protected]>
| Newsgroups | gmane.mail.spam.spamcop.help |
|---|---|
| Organization | SpamCop |
| Message-ID | <[email protected]> |
Alan Harper wrote: > One of the computers that a colleague uses has an IP in dsbl.org. The > IP is 200.79.150.31, and it has been in dsbl for presumably over 1 > year. > > http://dsbl.org/listing?200.79.150.31 > I assume that this is a dynamically allocated IP, and that it is in the It is not listed as a DHCP address in the lookups that I know how to do. Is it a DHCP address, if so, that range needs to be submitted to SORBS and NJABL and MAP-DUL for preemptive blocking. The rDNS is red-corp-200.79.150.31.telnor.net, which is a generic name, and many networks are now refusing any E-MAIL from generic I.P. addresses. If this is a dynamically allocated I.P. the DSBL listing should not matter as it is simply not practical to operate a mail server on a DHCP address. DHCP address pool blocking lists are probably more widely used than DSBL.org. > list because another computer at that IP was a source of spam. If that is the case it is still real bad for all of telenor.net's customers on that physical network segment. And a lot of virtual subnets can share a single physical link. When the spammers are pumping spam through that open proxy, it is probably causing so much network congestion that the network is useless for all the other telenor.net customers sharing that link. A competent network owner will prevent an open proxy from sending mail as soon as they discover it and then notify the system owner. And not reconnect it until they are satisfied it is fixed. If a network owner leaves the open proxy connected while they wait for the system owner to fix it, they are hurting their own network and all of their customers. > So I guess my questions are > > * any advice on how to get this IP out of dsbl 1. Get telenor.net or the system owner to verify that the open proxies are fixed. 2. Get telenor.net to fix their e-mail server to accept the removal request. It is currently refusing to accept the removal e-mail. That is not a good sign. The error messages are apparently stating that the required postmaster and abuse e-mail addresses do not exist. And that means that the network will not get any notifications of trouble on their network. 3. Once the required e-mail addresses are working, get telenor.net to read the removal request and open a web page on the link included in the e-mail. Or, put a mail server on that I.P address that will accept the confirmation e-mail at one of the RFC required POSTMASTER or ABUSE accounts to the rDNS domain name. If there is no mail server at this I.P. address, then the DSBL.ORG listing should not be affecting mail sent through the ISP's mail server, unless someone is checking all headers in a message, which most spam filters do not do. Most mail servers only check the I.P. address that they are accepting the e-mail directly from. > * do people really filter email using dsbl Yes, I know of several commercial and non-commercial networks using it. Some of them quite large. If someone is trying to operate a mail server on that I.P. I suspect that they may find quite a bit of the Internet refusing their e-mail. And it is my guess that as people find out about the dsbl.org that the number of mail servers using it is only going to increase. > * is dsbl considered reliable It seems to be. I really doubt that you will be able to convince a mail server operator that is using it to stop. They do exactly what they say they do. An I.P. gets listed by someone getting it to send an e-mail to one of their listing servers. An IP is removed with in 25 hours of the owner of the postmaster and the abuse e-mail boxes as designated by rDNS verifying that they can read at least one of the two required role mailboxes. The process is completely automated. Only one removal request per I.P. address will be process per week once the network owner's mailbox accepts the message. So if they did not fix the problem before delisting, it is likely to get listed again. -John [email protected] Personal Opinion Only