I'm all of a sudden starting to get a lot of bounce messages on accounts that I'm filtering for. It's the trick where the spammer co-opts either a domain name or a full address, and proceeds to send out their spam with the co-opted address. I previously ran into issues with forging viruses sending notifications to my users, and started to filter those out figuring that almost all of them were incorrect.

So I'm wondering what the best approach is to the problem. Do I target all bounces for deletion? I'm wondering if this will create problems with my users not getting their bounces when servers like AOL seem to accept the message only to issue their own response instead of letting my server, or my customer's server handle the errors. I've been seeing about 10 a day for the last week, and I'm only capturing about half of them (the returned content tends to trip filters).

Personally, I've had all outgoing bounce messages turned off for about 6 months, and the only Declude actions that I have on are for non-vunerability hits for viruses. It seems that between the spammers and the virus programmers, error reporting has been ruined, and it will remain that way until the whole system is overhauled. In my opinion, bounces should only be sent when the MAILFROM matches the REVDNS domain, but that would still leave plenty without the rightful benefit of such a thing.

Matt



---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.JunkMail mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.JunkMail".  The archives can be found
at http://www.mail-archive.com.

Reply via email to