Re: Why SRS really sucks
"Johann Steigenberger" <[email protected]> Mon, 3 Apr 2006 14:10:56 +0000 (UTC)
| Newsgroups | gmane.mail.spam.srs.general |
|---|---|
| Message-ID | <[email protected]> |
Hi Julian,=0D =0D >Only if your goal is to reject as much mail as possible, legitimate or not. =0D >But then you could just as well reject _all_ mail you receive, and no =0D >longer have to worry about someone trying to comply with -- and thus =0D >"bypass" -- your security measures.=0D =0D The goal is not to reject as much mail as possible:-)=0D The goal is to reject as much spam as possible ...=0D Facts are that, if you have a really good policy, you will not have =0D many cases, for which an exception must be done.=0D =0D Do not think we are only using:=0D IP, PTR, HELO, MAIL FROM and RCPT TO :-)=0D There are multiple other things we detect and which find their way=0D into the policys decision ...=0D Only decision happens always after rcpt to ...=0D =0D >So if I take your message and resend it with all the headers unmodified, = =0D >just using my own envelope sender, then it is a fake? No, it isn't! It =0D >is a perfectly legal case of the layer separation between RFC 2821 and RFC= =0D >2822.=0D =0D If you regulary resend the message this is something different to just rewrite the Env-from.=0D Resend means headers would reflect that ...=0D If you leave headers unmodified it is logically a fake even if RFCs do not explicitley forbid it....=0D =0D -- =0D =0D Johann Steigenberger =0D Blacklistmaster at UCEPROTECT-Network =0D http://www.uceprotect.net