That's where you are wrong, for several reasons:
[1] Your sample probably isn't a good one.
It is very probably a good sample, thanks.
As I said, I've done this analysis on two different high volume MXs, with 3 different charter, telus, and comcast PTR domains. All the results are the same. There are IMGate admins who run much higher volume MXs and confirm the same.
How much more sampling must I/we do to find a counter-example that would negate all the sampling so far?
For example, we have a domain that has only 2 valid accounts on it, but that gets a ton of spam. That domain will probably show 98% of the E-mail from France as being spam. But that of course does not mean that 98% of the E-mail from France is spam.
That's a really bad, silly example, and advances the discussion nil, and proves nothing.
I'm not extrapolating the "block subscriber networks" recommendation from spam to one email address.
However, I recommend blocking these French PTR domains:
/(net.*\.noos\.fr)/ /(dsl\.wanadoo\.nl)/ (hey, it's not French, but what the hell!) /(.*abo\.wanadoo\.fr)/ /(dsl\.proxad\.net)/ /(ip.*numericable\.fr)/
[2] You don't take into account that spammers won't remove your E-mail address, but legitimate people will.
What does that have to do with all the alphabet soup senders@, and the forged HELO hostname (not an accident when an rr.com subscriber says HELO as microsoft.com, and 1000's of them do it), and forged @sender.domains, and mismatch between @sender.domain and HELO domain?
To any experienced mail admin:
legitimate PTR + [EMAIL PROTECTED] + HELO hostname LOOKS legitimate, and
illegitimate PTR + [EMAIL PROTECTED] + HELO hostname LOOKS illegitimate.
Adding the fact that these same subscriber networks send 1000s of messages to non-existent users on our domains is more than enough evidence to declare them universally illegit.
At which point, we don't/can't care that 1 in 1000 PTRs is really a non-abusive mailer nor that the 1 legit PTR will send us 1 legit msg among 10K illegit msgs from the same PTR domain. That PTR is illegitimate by association, period.
That "legit" mailer can, upon demand, be whitelisted, but that's their initiative and work, not the MX's.
For example, if someone signs up for one of our mailing lists, and the mail starts bouncing, we will remove them from the list. So your sample doesn't include legitimate E-mailers that have gotten tired of you rejecting their E-mail (or people who re-routed their E-mail to get it to you, because they had been blocked before).
Self-proclaimed "legit" emailers mailing from subscriber PTRs are, by definition of the mail admin setting the MX policy, illegitimate. The mailer doesn't decide the il/legitimate issue, the MX admin does. And once the MX policy is set, there are no false positives.
You're essentially just saying "I don't get legitimate E-mail anymore from people who I have blocked"
Quit attributing to me what I didn't say. I said "blocking subscriber networks is reliable and effective way to stop a horrendous source of mail abuse"
Sending mail to my MX is a right that I grant, not a right you are born with and can ram down my throat.
which means nothing statistically.
I didn't say it, so your false attribution means nothing.
[3] You are assuming that you can tell by an E-mail address that an E-mail is spam.
The report in my msg referred to charter PTR hostname, MAIL FROM, and HELO hostname. Anybody on this list, without any agenda to push, can see
1) charter PTRs were sending 2) crap MAIL FROM and 3) crap HELO hostnames
We don't need to accept the DATA command, and read it to see whether it's legit or not. We all discard junk letters by looking at envelope only. Email is the same.
That isn't the case.
It wasn't the case I was making.
In fact, at least one of the E-mail addresses you posted is from a domain of an IMail customer I recognize (no, not declude.com!). Some appear to be from a mailing list.
So? If they come from subscriber PTRs, they're illegit.
So, it is a perfectly justifiable, defensible policy, based on hard, repeatable data such as the above, to define all subscriber PTR domains to be illegitimate, (which means it is, by definition, impossible to have false positives).
And, in a similar way, about 99.9% of the E-mail we receive from Korea is spam, so you are saying that all E-mail from Korea is illegitimate?
There are many ISPs who block .kr (and other foreign blackholes lists) since they have decided, yes, 99.9% is spam.
The resulting collateral damage to legit .kr (business) mailers caused Korea govt + businesses to attack their massive mail abuse problem, with the resulting drop in spam from .kr, that we have all noted over the past year.
Come on, Len. Learn statistics before you mis-use words like "impossible".
If a mail admin decides his policy is to block all of .kr, edu.tw, ac.tr, dial-up networks, or cable/DSL networks, then it is impossible, by definition, to have false positives. This has nothing to do with statistics or technicalities. It's a policy decision.
I'll admit that you *do* make a good point.
A lot of the E-mail that Charter customers try to send you is probably spam.
But unfortunately that doesn't mean anything without other data, such as [1] Whether or not those E-mails really are spam
Extensive sampling of the triplet PTR hostname + [EMAIL PROTECTED] + HELO hostname triplet is sufficient to see, for anybody who wants to see it, that it is crap.
There may be some vanishingly tiny number of legitimate mailers on subscriber networks dribbling out a few legit messages/day, but they are illegitimate _by definition_ since they are on subscriber networks.
Using publicly available information, I'm aware of one "subscriber network" customer that reportedly sends out about 100,000 legitimate E-mails a day.
Your single counter-example does not offset the dozens of subscriber PTR domains that harbor 10's of 1000's of abusive mailers that send millions of abusive msgs.
That's not "a few" or "dribbling". I'm sure there are others.
But they will never offset the increasing abuse from ever-more-popular subscriber networks, so they don't matter.
If a mail admin's policy is to refuse mail from all subscriber networks as illegitimate, then mail from those networks is, by definition, illegitimate at his MX. The burden proof of legitimacy falls on the 100K/day mailer, not on the MX's mail admin.
What can you expect to find as users and machines on subscriber networks?:
You forgot:
no, I didn't forget
* Small businesses in areas where the only reasonably priced business class service comes from a subscriber network
These people are at a clear disadvantage, (life isn't fair), trying to run a "legit" mailer on a subscriber network infested with spammers. But that's their problem to solve, not mine. There are alternatives for these people. I won't waste a minute of my time on THEIR problem.
* Hobbyists that run their own mailserver
Hobby mailers? GMAFB. We are running a business for our mostly business customers. Hobbyists can amuse themselves by relaying their outbound through their access provider or elsewhere.
* Non-profits that get free service from a subscriber network
They can relay their outbound through their access provider or elsewhere.
How about using something like EASYNET-DNSBL, which lists IPs on subscriber networks, but removes ones that send legitimate mail? All of a sudden, you'll improve your false positive rate tremendously.
Blocking all subscriber networks with my local ACLs:
1) is more efficient and scaleable (no DNS query delays)
2) my mailer is less vulnerable (no near-fatal delays on my mail server because osirus or easynet RBL servers are DDoSed or otherwise unreachable), the very problem you solved for Daniel Ivey which was contributing to killing his IMail. (We can expect the blackhats to take out all popular RBL servers eventually.)
3) and more accurate (no RBL server is can possibly keep up with the huge volumes of DSL/cable networks that are now and will be deployed.)
The base problem is that almost no network operators police their subscriber networks for mail abuse. As a result, MXs of the world are inundated with mail abuse from subscriber networks. Consequently, declaring all subscriber networks to be illegitimate (for exactly the same reasons that we block all dial-up users and that AOL is blocking dynamic networks) is a reasonable and reliable policy. It is a considered policy in reaction to their MISbehavior. They misbehave, they pay, we move on.
Any collateral damage to legit mailers on illegitimate_by_definition subscriber networks is part of the war game (and the ploy apparently worked with .kr).
When the network operators start blocking abuse from their subscriber networks (like all of us responsible mail admins do) so their networks become sources of only legitimate mail, then unblocking subscriber networks will make sense.
Until then, subscriber networks have convicted themselves of illegitimacy by their own behavior, and my recommendation is for everybody is to block them.
Len
_____________________________________________________________________ http://MenAndMice.com/DNS-training: San Jose; Wash DC; Dallas; Atlanta IMGate.MEIway.com: anti-spam gateway, effective on 1000's of sites, free
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
