There was a big cry recently when Cox cable blocked customer access to
all SMTP servers except their own.   Do they show up in the abuse profile?

For Friday, connects from cox IPs:


   4 wsip-24-120-32-56.lv.lv.cox.net[24.120.32.56]
   1 wsip-24-234-119-166.lv.lv.cox.net[24.234.119.166]
   4 lakemtao04.cox.net[68.1.17.241]
   2 lakemtao03.cox.net[68.1.17.242]
   4 lakemtao02.cox.net[68.1.17.243]
   9 lakemtao01.cox.net[68.1.17.244]
   1 ip68-102-116-160.ks.ok.cox.net[68.102.116.160]
   1 ip68-102-155-241.ks.ok.cox.net[68.102.155.241]
   2 ip68-102-90-127.ks.ok.cox.net[68.102.90.127]
   1 ip68-11-136-112.br.no.cox.net[68.11.136.112]
   1 wsip-68-110-134-19.lu.dl.cox.net[68.110.134.19]
   1 wsip-68-15-222-135.at.at.cox.net[68.15.222.135]
   2 wsip-68-15-27-237.sd.sd.cox.net[68.15.27.237]
   1 wsip-68-15-49-243.ri.ri.cox.net[68.15.49.243]
   1 fed1mtao08.cox.net[68.6.19.123]
   2 fed1mtao07.cox.net[68.6.19.124]
   1 fed1mtao06.cox.net[68.6.19.125]
   1 fed1mtao05.cox.net[68.6.19.126]
   1 fed1mtao04.cox.net[68.6.19.241]
   2 fed1mtao02.cox.net[68.6.19.243]
   1 fed1mtao01.cox.net[68.6.19.244]
   2 wsip-68-99-60-100.pn.at.cox.net[68.99.60.100]

Not too bad at all. The one with "mta" are their outbound machines, so we don't block them in the subcriber filter.


Earthlink seems to have port 25 bock that is more effective, "mail" being their MTAs:


    4 collamer.mail.atl.earthlink.net[199.174.114.9]
      6 grouse.mail.pas.earthlink.net[207.217.120.116]
     14 harrier.mail.pas.earthlink.net[207.217.120.12]
      1 albatross.mail.pas.earthlink.net[207.217.120.120]
      8 pintail.mail.pas.earthlink.net[207.217.120.122]
      3 swan.mail.pas.earthlink.net[207.217.120.123]
      6 turkey.mail.pas.earthlink.net[207.217.120.126]
      8 goose.mail.pas.earthlink.net[207.217.120.18]
      5 capitol.mail.pas.earthlink.net[207.217.120.180]
      4 epic.mail.pas.earthlink.net[207.217.120.181]
      4 sire.mail.pas.earthlink.net[207.217.120.182]
      3 stork.mail.pas.earthlink.net[207.217.120.188]
      5 heron.mail.pas.earthlink.net[207.217.120.189]
      5 hawk.mail.pas.earthlink.net[207.217.120.22]
      2 flamingo.mail.pas.earthlink.net[207.217.120.232]
      1 mallard.mail.pas.earthlink.net[207.217.120.48]
      2 scaup.mail.pas.earthlink.net[207.217.120.49]
     10 avocet.mail.pas.earthlink.net[207.217.120.50]
      9 conure.mail.pas.earthlink.net[207.217.120.54]
     11 snipe.mail.pas.earthlink.net[207.217.120.62]
      1 falcon.mail.pas.earthlink.net[207.217.120.74]
      3 gull.mail.pas.earthlink.net[207.217.120.84]
      2 firecrest.mail.pas.earthlink.net[207.217.121.247]
      1 fowl.mail.pas.earthlink.net[207.217.121.50]
      1 blackbird.mail.pas.earthlink.net[207.217.121.90]
      2 fallback02.mail.atl.earthlink.net[207.69.200.241]
      1 hsa083.pool042.at101.earthlink.net[216.249.111.83]   <<<<<<<< ooops

That step may be the only solution for the big providers.

The problem is so bad nearly all of them that they are not doing any policiing


   Korea is way ahead of the US in deploying broadband to residential
subscribers.  This may have been what caused the Korean spam blizzard of 1-2
years ago.  I see almost nothing by comparison; they seem to have gotten the
problem under control.

I read that .kr blocking was hurting legit businesses so the businesses got the spamming acted upon. I hear China is doing the same. Collateral damage works.


Len


_____________________________________________________________________ http://MenAndMice.com/DNS-training: San Jose; Wash DC; Dallas; Atlanta IMGate.MEIway.com: anti-spam gateway, effective on 1000's of sites, free


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to