http://www.ieee-pses.org/symposium http://www.emc2004.org/
-------------------------------------------------- 
http://www.ieee-pses.org/symposium http://www.emc2004.org/
-------------------------------------------------- 

Richard,

  Just a few data points for you:

 

(*) Delays and Internet Message Headers

-          In order to check where the primary bottleneck(s) a delayed message
is, you need to examine the Internet message header.  Many e-mail clients have
features to display this.  I’ve attached the header of the message you sent
to me.  

-          A full analysis requires many different tests that sending
reference messages a different times of the day/night, obtaining routing
stats, etc.  Suffice to say, a quick and dirty method would be to examine the
headers on this message when you receive it (don’t use the timestamps in the
attached header for your receipt calculation except to compare the relative
server exchange times).

-          The key areas to examine from the header is the first
“Received” timestamp (In this case when my POP server received your
message) which is 16 Aug 2004 09:02:32 -0700 or 19 Aug 2004 02:02:32 GMT) and
the various “Received from” timestamps from any contributing servers along
the way.  

-          I’ll leave the full analysis up to you, but in this particular
case a substantial delay occurred (did you strip off the original message for
brevity?). The timestamps look suspect.   

-          Internet Headers can be spoofed and timestamps are no exception. 
This is still moderately tolerated by individuals using port-25 (SMTP) mass
mailing zombies (soon I hope this changes), but for an ISP server to
intentionally modify a timestamp on an e-mail message would be a criminal act
and cause for an investigation.

-          Distribution lists like this one will naturally have a delay. The
processing of 1000’s of SMTP messages takes a considerable amount of server
and network resources.

 

(*) Spam Filtering (Server-Based)

-          AOL has spent millions in advertising campaigns regarding SPAM
“blocking”.  Some server-based SPAM filters will DELETE perceived SPAM
e-mail, while others (such as SpamAssasin) will still strip certain artifacts
(such as any HTTP referrer blocks) and still send a modified version of the 
message, warn you of the decision it made, plus provide the metrics it used in
the analysis.  I don’t know what AOL is using for server-based SPAM
filtering.  Below is an example of a SpamAssasin report:

 

Content analysis details:   (6.3 points, 5.0 required)

 

 pts rule name              description



 2.9 DATE_IN_FUTURE_03_06   Date: is 3 to 6 hours after Received: date

 3.4 FORGED_MUA_EUDORA      Forged mail pretending to be from Eudora

 

(*) Federal Monitoring

-          Carnivore and Echelon may have effects in delays, but they should
be minimal as they are classified law enforcement tools and should run
transparent to the end user (i.e., they don’t exist).

-          The latest belief is that (hold onto your hat) ALL e-mail is
monitored by the federal agencies.  I am told there are at least 15 US
intelligence agencies.  The NSA has the largest computer facilities on this
planet and (and federal budget of the 15) and monitors every form of
electronic communication.  The FBI is trying their best to find terrorists
which is fine by me (Google Carnivore).  

-          My belief is that that 911 may have changed the amount of data
duplicated (for post data mining purposes), but traffic analysis is probably
used much more than keyword locality analysis, stenography detection, and
cipher strength detection techniques combined.  Carnivore and Echelon would
certainly have the capability to spoof timestamps, but there is little reason
for it (unless the message is super huge and the network congestion just
happens to be very high).

 

YOUR E-MAIL HEADER AS SEEN FROM MY END 

 

Return-Path: <[email protected]>

Delivered-To: mcpherson.net%[email protected]

Received: (cpmta 23380 invoked from network); 16 Aug 2004 09:02:32 -0700

Received: from 140.98.193.10 (HELO ruebert.ieee.org)

  by smtp.c000.snv.cp.net (209.228.32.87) with SMTP; 16 Aug 2004 09:02:32 -0700

X-Received: 16 Aug 2004 16:02:32 GMT

Received: from emstatus.ieee.org (boldfish.ieee.org [140.98.194.25])

            by ruebert.ieee.org (Switch-3.1.0/Switch-3.1.0) with ESMTP id
i7GG2P7m003877;

            Mon, 16 Aug 2004 12:02:25 -0400 (EDT)

Received: from engine (engine.ieee.org [140.98.193.23])

            by emstatus.ieee.org (8.9.3+Sun/8.9.3) with ESMTP id MAA06017;

            Mon, 16 Aug 2004 12:02:21 -0400 (EDT)

Received: from LISTSERV.IEEE.ORG by LISTSERV.IEEE.ORG (LISTSERV-TCP/IP release

          1.8e) with spool id 13508 for [email protected]; Mon, 16 Aug

          2004 12:02:23 -0400

Received: from hormel6.ieee.org (gemini3.ieee.org [140.98.193.188]) by

          engine.ieee.org (Switch-3.1.2/Switch-3.1.2) with ESMTP id

          i7GG2MQr015395 for <[email protected]>; Mon, 16 Aug 2004 12:02:22

          -0400 (EDT)

Received: from imo-m14.mx.aol.com (imo-m14.mx.aol.com [64.12.138.204]) by

          hormel6.ieee.org (8.12.11/8.12.11) with ESMTP id i7GG1q1w014862 for

          <[email protected]>; Mon, 16 Aug 2004 12:01:52 -0400

Received: from [email protected] by imo-m14.mx.aol.com (mail_out_v37_r3.4.) id

          b.1ed.27f171b1 (4426); Mon, 16 Aug 2004 12:01:58 -0400 (EDT)

From: [email protected]

Message-ID: <[email protected]>

List-Post: [email protected]
Date: Mon, 16 Aug 2004 12:01:58 EDT

Subject: Re: Lost messages

To: [email protected], [email protected]

MIME-Version: 1.0

Content-Type: multipart/alternative;

              boundary="-----------------------------1092672118"

X-Mailer: 9.0 for Windows sub 631

X-UCE-Filter-Settings: 90_OPT_OUT

X-Scanned-By: IEEE UCE Filtering Service

Sender: [email protected]

Precedence: list

Status: U

X-UIDL: QSDamNHkIFdbWgE

 

 

/// Mike

 

 


From: [email protected] 
mailto:[email protected]] On Behalf Of [email protected]
Sent: Monday, August 16, 2004 9:02 AM
To: [email protected]; [email protected]
Subject: Re: Lost messages

 

Folks,

 

Thanks to those who have replied to my original question.

 

Some of the messages I received suggested that there could be a time delay
whereby the original message is received after the reply.  Certainly I have
noticed this myself in the past, but in this case the original message has not
been received after several days.  If the sender had sent the message surface
mail from the USA to the UK it would have got here sooner!

 

I had a look in my junk mail folder, which did not contain any messages from
this forum.  So it seems that AOL's spam filter had not decided that the
message was offensive or from an unwanted source.

 

Since this is my home account there is no concern that corporate spam filters
are cutting in.

 

While it may be that there could be problems transmitting data between the USA
and certain other countries, hopefully the UK is not one of them.  In
addition, AOL is based in the USA and so this should not be a problem unless
there is some filtering within the AOL network (and if it is that, then why
are replies containing the original mail let through if the original is not?).

 

A continuing mystery, it seems.

 

Regards,

 

Richard Hughes

 

In a message dated 08/16/2004 08:51:39 GMT Standard Time, [email protected]
writes:

Still now and then a message is getting
lost, easy to recover, because most answers on a message
include the original question (good habit, opposite to
the advice from most list moderators not to include that).

 

------------------------------------------- 

This message is from the IEEE Product Safety Engineering Society emc-pstc
discussion list. 


IEEE PSES Main Website: http://www.ieee-pses.org/ 


To post a message send your e-mail to [email protected] 


Instructions for use of the list server: 


http://listserv.ieee.org/listserv/request/user-guide.html 


List rules: http://www.ieee-pses.org/listrules.html 


For help, send mail to the list administrators: 


Ron Pickard: [email protected] Dave Heald: [email protected] 


For policy questions, send mail to: 


Richard Nute: [email protected] Jim Bacher: [email protected] 


All emc-pstc postings are archived and searchable on the web at: 


http://www.ieeecommunities.org/emc-pstc
------------------------------------------- 


This message is from the IEEE Product Safety Engineering Society emc-pstc
discussion list. 


IEEE PSES Main Website: http://www.ieee-pses.org/ 


To post a message send your e-mail to [email protected] 


Instructions for use of the list server: 


http://listserv.ieee.org/listserv/request/user-guide.html 


List rules: http://www.ieee-pses.org/listrules.html 


For help, send mail to the list administrators: 


Ron Pickard: [email protected] Dave Heald: [email protected] 


For policy questions, send mail to: 


Richard Nute: [email protected] Jim Bacher: [email protected] 


All emc-pstc postings are archived and searchable on the web at: 


http://www.ieeecommunities.org/emc-pstc


Reply via email to