RE: ISP outbound SMTP filtering
"Kevin Kargel" <kkargel-BvA0c2rBOuxWk0Htik3J/[email protected]>
| Newsgroups | gmane.org.operators.internet-access |
|---|---|
| Message-ID | <70DE64CEFD6E9A4EB7FAF3A063141066706F9E@mail> |
I agree port 25 blocking isn't going to hurt anyone. On the contrary it is necessary. I block port 25 outgoing on my dynamic networks. What does hurt people, and networks, and the image the public has of us all is when autocratic administrators impose unduly strict restrictions on customers without reasonable cause. In actuality many of my customers do relay through my mail server. Others prefer to deliver directly from their own mail server. This is a choice they should be able to make so long as they are well behaved. I am cautious with spam issues, and do not have an issue with RBL's.. I even have a good relationship with AOL and their postmaster reports any issues directly to me to deal with. Our network is very pro-active when it comes to anti-spam issues. We go so far as to offer incoming and outgoing spam filtering for free to our customers as an inducement to relay through our mail server, even if they are running their own mail server. So far this carrot is working much better than a stick. We also provide bidirectional spam/virus filtering on all local user accounts as a basic feature at no additional charge to the customer because it is better for our network and for the internet community at large. Another thing I do that I thought would be more popular, but so far has not taken off, is to offer free validation of personal email certificates for authentication and encryption. It appears that what people really want is out-of-box functionality, and that is going to be what satisfies them. Where I have the problem is when people consider non-standard practices such as forcing general public customers to custom ports to be best practice. In theory it is a great idea, but when you are dealing with customers who often have to relearn how to double-click it gets expensive and frustrating for all parties involved. I suspect this is done as a work-around to avoid the either costly or admin intensive task of effective spam/virus filtering. As soon as port 587 becomes widely used the zombies and viruses will raid the local email configs for credentials and start using that service. Running and hiding from zombies will work for a time, but it will be a temporary fix. If you consider port 58x delivery to be a standard practice, I would suggest looking in the pull-down configuration of the most common email clients and see how many list that port as a built-in alternative to port 25. I will disagree when you say that the number of people who would even notice the port 25 block is miniscule. When we first implemented that policy (after ample advance announcements) it was the number one call topic at the help desk for weeks. More and more people have work email addresses where their corporate policies require them to use the non-local corporate mail servers. At the same time these people work with internet connections on non-corporate IP blocks. The corporate solution (which is a good measure) is to require SMTP Auth and/or Pop before SMTP Auth. Couple port 25 blocking (a very necessary evil) with local ISP policy (IMHO a good one) prohibiting the ISP mail server from delivering email with envelope addresses "From:" non-authorized domains and you will have a problem. Again, don't get me wrong, I do block port 25 on all dynamic IP blocks. If my customers need port 25 access I require a static IP for easy accountability. I continue this thread because I do think it is still on-topic and germane and I welcome rational discussion. > -----Original Message----- > From: [email protected] > [mailto:[email protected]] On Behalf Of [email protected] > Sent: Tuesday, June 05, 2007 12:32 PM > To: [email protected] > Subject: RE: ISP outbound SMTP filtering > > Kevin Kargel wrote: > > It just sounds like you really like to light the god sign over your > > desk and flex your admin muscles, tell your clients how > they have to > > run their networks, and don't give them any input to the policies. > > That is a real good recipe for forcing an ISP out of business. > > People will move to where it is friendlier, where their business is > > appreciated and to where they have a modicum of control. > > > > If you are in a captive market (school, military, internal corporate > > network) where you customers have no choice of who to get > service from > > your method will work, but if not I wanted to get my dibs > in for cheap > > networking hardware when you don't need it any more.. :) > > > Honestly, you sound exactly like the people 15 years ago or > so when we figured out that open relays maybe weren't such a > good idea. Or when ISP's finally cut off the last of their > UUCP clients. Lots of wailing and gnashing of teeth over > "don't tell me how to run my server/network/raise my kid" in > the face of overwhelming evidence that things had changed and > were never going to be the same. This thread has gone on for > a few days now and no one has presented a single rational > reason why you or your customers can't simply configure > your/their mail server to relay through the ISP's mail > server. Just like how sometime in the 90s you had to stop > picking SMTP servers at random and start using your > provider's (or run your own), things have changed, we all must adapt. > > And blocking port 25 isn't going to put *anyone* out of > business. The percentage of clients who even know it's being > done, much less care enough about it to leave and go > elsewhere is so miniscule it's laughable. I'm sure you could > build a nice niche business catering to that tiny minority, > and probably be successful doing so. Just don't complain > when you find yourself effectively RBL'd off the 'net, just > like those like-minded people who steadfastly maintained > their open relays... > > Andrew > > _______________________________________________ > "Eat sushi frequently". - Avi > [email protected] is the human contact address. > [email protected] is the list posting address. > See below URL for subscribe/unsubscribe and list options: > http://inet-access.net/mailman/listinfo/list > _______________________________________________ "Eat sushi frequently". - Avi [email protected] is the human contact address. [email protected] is the list posting address. See below URL for subscribe/unsubscribe and list options: http://inet-access.net/mailman/listinfo/list