So, in conclusion, the "single criteria" of a PTR hostname being in a charter.com subscriber subdomain is reliably indicative of mail abuse.
That's where you are wrong, for several reasons:
[1] Your sample probably isn't a good one. For example, we have a domain that has only 2 valid accounts on it, but that gets a ton of spam. That domain will probably show 98% of the E-mail from France as being spam. But that of course does not mean that 98% of the E-mail from France is spam.
[2] You don't take into account that spammers won't remove your E-mail address, but legitimate people will. For example, if someone signs up for one of our mailing lists, and the mail starts bouncing, we will remove them from the list. So your sample doesn't include legitimate E-mailers that have gotten tired of you rejecting their E-mail (or people who re-routed their E-mail to get it to you, because they had been blocked before). You're essentially just saying "I don't get legitimate E-mail anymore from people who I have blocked", which means nothing statistically.
[3] You are assuming that you can tell by an E-mail address that an E-mail is spam. That isn't the case. In fact, at least one of the E-mail addresses you posted is from a domain of an IMail customer I recognize (no, not declude.com!). Some appear to be from a mailing list.
So, it is a perfectly justifiable, defensible policy, based on hard, repeatable data such as the above, to define all subscriber PTR domains to be illegitimate, (which means it is, by definition, impossible to have false positives).
And, in a similar way, about 99.9% of the E-mail we receive from Korea is spam, so you are saying that all E-mail from Korea is illegitimate? Come on, Len. Learn statistics before you mis-use words like "impossible".
I'll admit that you *do* make a good point. A lot of the E-mail that Charter customers try to send you is probably spam. But unfortunately that doesn't mean anything without other data, such as [1] Whether or not those E-mails really are spam, [2] What your normal spam-to-legitimate E-mail ratio is, [3] How your "spam profile" compares to that of others, etc.
There may be some vanishingly tiny number of legitimate mailers on subscriber networks dribbling out a few legit messages/day, but they are illegitimate _by definition_ since they are on subscriber networks.
Using publicly available information, I'm aware of one "subscriber network" customer that reportedly sends out about 100,000 legitimate E-mails a day. That's not "a few" or "dribbling". I'm sure there are others.
What can you expect to find as users and machines on subscriber networks?:
You forgot:
* Small businesses in areas where the only reasonably priced business class service comes from a subscriber network
* Hobbyists that run their own mailserver
* Non-profits that get free service from a subscriber network
How about using something like EASYNET-DNSBL, which lists IPs on subscriber networks, but removes ones that send legitimate mail? All of a sudden, you'll improve your false positive rate tremendously.
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask about our free 30-day evaluation.
--- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
