Re: Why SRS really sucks
Tom Lahti <[email protected]> Mon, 27 Mar 2006 10:46:28 -0800
| Newsgroups | gmane.mail.spam.srs.general |
|---|---|
| Message-ID | <[email protected]> |
>I hate to tell you this, but we block specific users all the time - >irrespective of SRS. When '[email protected]' (to take a recent example) sends >us hundreds of spam, into the blacklist he goes. There is no >reason for us to block legit yahoo users just because of one >miscreant. If a bunch of users whose cryptic localpart begins >with 'SRS' start spamming us - into the blacklist they go. Yes, of course. But you are not assigning SEMANTICS to "simon", you are just dropping it. You are not trying to determine that "si" means something and "mon" means something else, which is what "assigning semantics" means. To do THAT -- to rip apart the local part of a MAIL FROM: that is not in your own domain and try to determine what parts of it mean, is the RFC violation. I don't think that having a one-to-one policy of localpart@domainpart => action is bad or a violation of RFC. If you try to take the local part apart and divide it up somehow and try to decide what the pieces mean, then you have a problem. The sending MTA constructed that, and you really don't know how, even when you think you do. Of course, "blacklisting" specific SRS signed MAIL FROM: only works for a short time period, until the hash changes. In this case, if you want to be effective and stay RFC compliant, you are left with blocking the entire domain. This is not your fault -- the sending domain administrator made that choice when he decided to SRS sign. Don't treat him special just because he might have a "well-known" domain. I suspect that this is precisely why domains like yahoo.com will probably never use SRS. They know they will leave administrators wishing to remain RFC compliant with only one choice. -- -- ========================= Tom Lahti Tx3 Online Services (888)4-TX3-SVC (489-3782) http://www.tx3.net/ -- =========================