Re: Re: SRS: is there a stable implementation for postfix yet?
"Johann Steigenberger" <[email protected]> Tue, 28 Mar 2006 04:16:54 +0000 (UTC)
| Newsgroups | gmane.mail.spam.srs.general |
|---|---|
| Message-ID | <[email protected]> |
>>And in answer to your third question -- of _course_ misdirected bounces >>are a problem, and you know my solution. >Actually, we don't. Is it the same as Johann's laughable "solution"; >the equivalent of running SpamAssassin? Hey never said that this is the final solution :-) I said it is one possibility to do so .... I never had a need to use Spamassaissin or bayes or similair content based crap [OFFTOPIC ON] We are doing Spamdefense all on envelopes and some more advanced things on tcp protocoll level and thats very efffective. This all is done under control of a very flexible policy, where the clue is that you can have rules that are absolute and rules that depend on other rules.... Only for Information you can combine rules as: Per default reject mail from Systems detected to be Dialups. If a external System which is detected to be a Dialup is responsible MX for claimed sender domain, make an exception and accept that. The power comes from setting rules lumping them together to have a great policy. [OFFTOPIC OFF] But back to the thread: There are much easier ways to reject faked bounces at SMTP-Envelope, and you do not need to implement SRS to be also effective ... Example: Your emailadresses are in form of: [email protected] Just establish a subdomain exclusive for real bounces and set IP to your MX. Set your MTA that all outgoing messages get a envelope-from like: [email protected] while the from address in the mail stays untouched . This way you can reject every bounce coming to [email protected], becuse you know its a fake. You see you really dont need SRS for this. It is also very unlike that Spammers find out what your secret subdomain is ... -- Johann Steigenberger Blacklistmaster at UCEPROTECT-Network http://www.uceprotect.net