Re: Why SRS really sucks

"Johann Steigenberger" <[email protected]> Mon, 3 Apr 2006 14:10:56 +0000 (UTC)
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
Hi Julian,=0D
 =0D
>Only if your goal is to reject as much mail as possible, legitimate or not.
=0D
>But then you could just as well reject _all_ mail you receive, and no =0D
>longer have to worry about someone trying to comply with -- and thus =0D
>"bypass" -- your security measures.=0D
 =0D
The goal is not to reject as much mail as possible:-)=0D
The goal is to reject as much spam as possible ...=0D
Facts are that, if you have a really good policy, you will not have =0D
many cases, for which an exception must be done.=0D
 =0D
Do not think we are only using:=0D
IP, PTR, HELO, MAIL FROM and RCPT TO :-)=0D
There are multiple other things we detect and which find their way=0D
into the policys decision ...=0D
Only decision happens always after rcpt to ...=0D
 =0D
>So if I take your message and resend it with all the headers unmodified, =
=0D
>just using my own envelope sender, then it is a fake? No, it isn't! It =0D
>is a perfectly legal case of the layer separation between RFC 2821 and RFC=
 =0D
>2822.=0D
 =0D
If you regulary resend the message this is something different to just
rewrite the Env-from.=0D
Resend means headers would reflect that ...=0D
If you leave headers unmodified it is logically a fake even if RFCs do not
explicitley forbid it....=0D
 =0D
-- =0D
 =0D
Johann Steigenberger =0D
Blacklistmaster at UCEPROTECT-Network =0D
http://www.uceprotect.net