RE: ISP outbound SMTP filtering

"Kevin Kargel" <kkargel-BvA0c2rBOuxWk0Htik3J/[email protected]>
Newsgroups gmane.org.operators.internet-access
Message-ID <70DE64CEFD6E9A4EB7FAF3A063141066706F9E@mail>
I agree port 25 blocking isn't going to hurt anyone.  On the contrary it
is necessary.  I block port 25 outgoing on my dynamic networks.  

What does hurt people, and networks, and the image the public has of us
all is when autocratic administrators impose unduly strict restrictions
on customers without reasonable cause.  

In actuality many of my customers do relay through my mail server.
Others prefer to deliver directly from their own mail server.  This is a
choice they should be able to make so long as they are well behaved.

I am cautious with spam issues, and do not have an issue with RBL's..  I
even have a good relationship with AOL and their postmaster reports any
issues directly to me to deal with.  Our network is very pro-active when
it comes to anti-spam issues.  We go so far as to offer incoming and
outgoing spam filtering for free to our customers as an inducement to
relay through our mail server, even if they are running their own mail
server.  So far this carrot is working much better than a stick.  We
also provide bidirectional spam/virus filtering on all local user
accounts as a basic feature at no additional charge to the customer
because it is better for our network and for the internet community at
large.  

Another thing I do that I thought would be more popular, but so far has
not taken off, is to offer free validation of personal email
certificates for authentication and encryption.  It appears that what
people really want is out-of-box functionality, and that is going to be
what satisfies them.  

Where I have the problem is when people consider non-standard practices
such as forcing general public customers to custom ports to be best
practice.  In theory it is a great idea, but when you are dealing with
customers who often have to relearn how to double-click it gets
expensive and frustrating for all parties involved.  I suspect this is
done as a work-around to avoid the either costly or admin intensive task
of effective spam/virus filtering.  As soon as port 587 becomes widely
used the zombies and viruses will raid the local email configs for
credentials and start using that service.  Running and hiding from
zombies will work for a time, but it will be a temporary fix.  

If you consider port 58x delivery to be a standard practice, I would
suggest looking in the pull-down configuration of the most common email
clients and see how many list that port as a built-in alternative to
port 25.  

I will disagree when you say that the number of people who would even
notice the port 25 block is miniscule.  When we first implemented that
policy (after ample advance announcements) it was the number one call
topic at the help desk for weeks.  More and more people have work email
addresses where their corporate policies require them to use the
non-local corporate mail servers.  At the same time these people work
with internet connections on non-corporate IP blocks.  The corporate
solution (which is a good measure) is to require SMTP Auth and/or Pop
before SMTP Auth.  

Couple port 25 blocking (a very necessary evil) with local ISP policy
(IMHO a good one) prohibiting the ISP mail server from delivering email
with envelope addresses "From:" non-authorized domains and you will have
a problem.   Again, don't get me wrong, I do block port 25 on all
dynamic IP blocks.  If my customers need port 25 access I require a
static IP for easy accountability.  

I continue this thread because I do think it is still on-topic and
germane and I welcome rational discussion.  

 

> -----Original Message-----
> From: [email protected] 
> [mailto:[email protected]] On Behalf Of [email protected]
> Sent: Tuesday, June 05, 2007 12:32 PM
> To: [email protected]
> Subject: RE: ISP outbound SMTP filtering
> 
> Kevin Kargel wrote:
> > It just sounds like you really like to light the god sign over your 
> > desk and flex your admin muscles, tell your clients how 
> they have to 
> > run their networks, and don't give them any input to the policies.
> > That is a real good recipe for forcing an ISP out of business. 
> > People will move to where it is friendlier, where their business is 
> > appreciated and to where they have a modicum of control.
> > 
> > If you are in a captive market (school, military, internal corporate
> > network) where you customers have no choice of who to get 
> service from 
> > your method will work, but if not I wanted to get my dibs 
> in for cheap 
> > networking hardware when you don't need it any more..  :)
> 
> 
> Honestly, you sound exactly like the people 15 years ago or 
> so when we figured out that open relays maybe weren't such a 
> good idea.  Or when ISP's finally cut off the last of their 
> UUCP clients.  Lots of wailing and gnashing of teeth over 
> "don't tell me how to run my server/network/raise my kid" in 
> the face of overwhelming evidence that things had changed and 
> were never going to be the same.  This thread has gone on for 
> a few days now and no one has presented a single rational 
> reason why you or your customers can't simply configure 
> your/their mail server to relay through the ISP's mail 
> server.  Just like how sometime in the 90s you had to stop 
> picking SMTP servers at random and start using your 
> provider's (or run your own), things have changed, we all must adapt.
> 
> And blocking port 25 isn't going to put *anyone* out of 
> business.  The percentage of clients who even know it's being 
> done, much less care enough about it to leave and go 
> elsewhere is so miniscule it's laughable.  I'm sure you could 
> build a nice niche business catering to that tiny minority, 
> and probably be successful doing so.  Just don't complain 
> when you find yourself effectively RBL'd off the 'net, just 
> like those like-minded people who steadfastly maintained 
> their open relays...
> 
> Andrew
> 
> _______________________________________________
> "Eat sushi frequently". - Avi
> [email protected] is the human contact address.
> [email protected] is the list posting address.
> See below URL for subscribe/unsubscribe and list options:
> http://inet-access.net/mailman/listinfo/list
> 
_______________________________________________
"Eat sushi frequently". - Avi
[email protected] is the human contact address.
[email protected] is the list posting address.
See below URL for subscribe/unsubscribe and list options:
http://inet-access.net/mailman/listinfo/list
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.