Re: Re: SRS: is there a stable implementation for postfix yet?

"Johann Steigenberger" <[email protected]> Tue, 28 Mar 2006 04:16:54 +0000 (UTC)
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
 >>And in answer to your third question -- of _course_ misdirected bounces
>>are a problem, and you know my solution.
 
>Actually, we don't. Is it the same as Johann's laughable "solution"; 
>the equivalent of running SpamAssassin?
 
Hey never said that this is the final solution :-)
I said it is one possibility to do so ....
I never had a need to use Spamassaissin or bayes or similair content based
crap
[OFFTOPIC ON]
We are doing Spamdefense all on envelopes and some more advanced things on
tcp protocoll level and thats very efffective.
This all is done under control of a very flexible policy, where the clue is
that you can
have rules that are absolute and rules that depend on other rules....
 
Only for Information you can combine rules as:
Per default reject mail from Systems detected to be Dialups.
If a external System which is detected to be a Dialup is responsible MX for
claimed 
sender domain, make an exception and accept that.
 
The power comes from setting rules lumping them together to have a great
policy.
 
[OFFTOPIC OFF]
 
But back to the thread:
 
There are much easier ways to reject faked bounces at SMTP-Envelope,
and you do not need to implement SRS to be also effective ...
 
Example:
 
Your emailadresses are in form of: [email protected]
Just establish a subdomain exclusive for real bounces and set IP to your MX.
Set your MTA that all outgoing messages get a envelope-from like:
[email protected] while the from address in the mail stays
untouched .
 
This way you can reject every bounce coming to [email protected], becuse you
know its a fake.
 
You see you really dont need SRS for this.
It is also very unlike that Spammers find out what your secret subdomain is 
...
 
--
 
Johann Steigenberger 
Blacklistmaster at UCEPROTECT-Network 
http://www.uceprotect.net