Re: Tool for validating sender address as spam-fighting technique?
"Matt Grommes" <[email protected]>
| Newsgroups | gmane.org.user-groups.nmlug |
|---|---|
| Message-ID | <[email protected]> |
I think most mail servers will do this for you. It's been awhile since I did my postfix config but I'm pretty sure there's a way to reject malformed email addresses. > To fight spam, I want to validate the address (not necessarily in > real-time) of the a given email sender. Is there a Unix tool that does > this? > > The basics are simple: to validate "kmnyqi-Lqzm/[email protected]", I connect to > the MX record of wnonline.net and go as far as "RCPT TO" as follows: > >> host -t mx wnonline.net > wnonline.net mail is handled by 5 wnspf.bayou.com. > >> telnet wnspf.bayou.com. 25 > Trying 209.209.192.75... > Connected to wnspf.bayou.com.. > Escape character is '^]'. > 220 Welcome to Bayou mxfilter > HELO domaintester.com > 250 mxfilter.bayou.com > MAIL FROM: <test-Gm2Ff2CXt15Wk0Htik3J/[email protected]> > 250 Ok > RCPT TO: <kmnyqi-Lqzm/[email protected]> > 550 <kmnyqi-Lqzm/[email protected]>: Recipient address rejected: 5.1.1 > <kmnyqi-Lqzm/[email protected]>... User unknown > QUIT > 221 Bye > Connection closed by foreign host. > > This tells me kmnyqi-Lqzm/[email protected] is an invalid address and that mail > from that address is probably bogus. > > A more sophisticated tool would cache results, handle temporary > failures (eg, inability to connect to the MX server), handle multiple > MX records, perhaps even publish results [carefully, to avoid giving > spammers a source of legit email addresses!], etc. Plus, I'd prefer to > use a tested tool vs hacking something up myself. > > I realize this technique is far from perfect: > > Spammers spoof legit addresses > > Bounces/Mailing lists/etc legitimately use "do not reply" addresses > > It could be considered unfriendly to the target MX servers > > Some mail servers incorrectly say "user unknown" when they see spam, > figuring it's more of a deterrent than saying "you're a spammer" > > Some mail servers inefficiently accept mail for "[email protected]" (where > xxx.com is one of their domains), figure out if foo exists later, and > send a bounce back to the envelope sender, instead of rejecting email > at the SMTP level (a really good tool would create throwaway addresses > to catch these cases too) > > ... but I still think it might help. > > -- > We're just a Bunch Of Regular Guys, a collective group that's trying > to understand and assimilate technology. We feel that resistance to > new ideas and technology is unwise and ultimately futile. > _______________________________________________ > NMLUG mailing list > [email protected] > http://www.nmlug.org/mailman/listinfo/nmlug > > _______________________________________________ NMLUG mailing list [email protected] http://www.nmlug.org/mailman/listinfo/nmlug