Re: SPF and bouncing

Michael Deutschmann <[email protected]> Fri, 4 May 2012 12:38:24 -0700 (PDT)
Newsgroups gmane.mail.spam.spf.discuss
Message-ID <%[email protected]>
On Fri, 4 May 2012, Scott Kitterman wrote:
> Spammers to have not adapted to SPF by moving to null mail from's.

It's not an adaptation to SPF, and is indeed counterproductive for the
spammer /at this time/.  It's an adaptation to sender address
whitelisting combined with harsh standards to accept non-whitelisted
mail, perhaps to the extreme of goldlisting.

Goldlisting has two chinks in the armor.  The first is that the spammer
may guess an e-mail address that the victim corresponds with, and ride on
that person's reputation.  The second is that the spammer uses <> and the
sysadmin, refusing to be "RFC-Ignorant", lets it through on the off chance
it might be a genuine bounce.

The first threat doesn't worry me, since we have SPF.  Sure, I have
plenty of correspondents with weak/absent SPF policies, but should the
spammer find one, I can apply concentrated pressure to that specific
friend to have his ISP deploy -all.  Once that hole is plugged, the
spammer has to start all over.

But I don't see a good "next move" for the good guys if spammers use the
second strategy, other than refusing all putative DSNs.  VERP (such as
BATV) doesn't count since, unless a VERP-decoding SPF extension is
adopted, your whitelisting only works if your correspondents don't VERP.
 
---- Michael Deutschmann <[email protected]>