Re: Sending Non Delivery Reports? (was Pump and Dump)

Garen Erdoisa <[email protected]> Fri, 05 May 2006 22:53:38 -0600
Newsgroups gmane.mail.spam.spamcop.user
Organization SpamCop
Message-ID <[email protected]>
Blammo wrote:
> On 05 May 2006, - Garen Erdoisa entered spamcop and left
> news:[email protected]: 
> 
>> Thousands of sites use it with no problems. The only problems it might
>> cause that I am aware of are for relay servers, and there are 
>> workarounds for those situations that which are discussed in the
>> protocol. 
>>
> 
> A "workaround" fix for broken software is not acceptable except for those 
> use that software. SPF is broken and they expect everyone else to fix it.

How do you define "broken"?

The Internet is constantly evolving. I have rarely seen a piece of 
software that wasn't "broken" such that it didn't ever require a fix or 
workaround, or update, or patch, or tweak, or whatever to make it work 
the way you wanted it to work.

New protocols can cause problems when getting them to interface with 
older protocols. This doesn't mean the new protocol is broken, nor does 
it mean the old one is. It can make them somewhat incompatible without 
adjustments and compromises being made. Sometimes making the time to do 
such adjustments is more desirable than doing nothing.

The SPF protocol is still in RFC Draft form. So is DKIM-Signature: and 
Domainkey-Signature: (a trial run of DKIM). Yet people are making use of 
the protocols, software has been and is being developed and improved, 
the protocols are being discussed and updated, eventually I'm sure that 
in the not to distant future, full fledged RFC's will be issued.

IMHO, in the case of SPF, the benefits of using SPF now, far outweigh 
the hassle of making the necessary software adjustments or attitude 
adjustments, or waiting until RFC's are issued.

This is especially true if you are a victim of having your domain name 
forged into the from lines of spam.

I have have been the victim of such forgery, and when searching for a 
solution I found SPF. I chose along with many other sites to adopt it early.

Speaking from experience here, it had the effect almost immediately of 
cutting down to a trickle the amount of  DSN (Delivery Status 
Notification) emails I had been getting prior to that.

I'm sure if I disabled the record, I would soon have a ton of DSN's to 
deal with again instead of the one or two a week I see now from sites 
that haven't implemented SPF. I used to get hundreds a day prior to 
implementing SPF. It was almost as big a problem as spam was before 
implementing SPF.

> 
> And I have seen complaints to ISPs that use SPF records, from their users, 
> probably because they were using SPF-Fail, but then again you never know 
> these days why someone might reject your mail.

That is possible, but I have never personally seen any complaints about 
SPF. If I ever do, I'll deal with that situation as appropriate.
Admittedly there is a learning curve with it, and if it's mis configured 
it can potentially cause horrendous problems. The same can be said of a 
lot of networking software. :-)

>