Scott, Thanks for that information... it's really very helpful. So now, I guess my "jab back at the spammer" is more perceived than real, but that's okay... the main idea is to blacklist the IPs by dropping packets, even if that doesn't actually have an effect on the sending server nowadays.
I bet all of us wish we could send back a "go blow yourself up" packet of some kind, to the biggest offenders. If sending spam became a true risk to the sending machine, I bet we'd see a big drop in spam straight away!! :) I wonder, given your comment below, if pushing the recipient email address to the "harder addresses" list has some sort of effect on future mailings to that address? If, just maybe, it would mean that the address would no longer be "sold" to other lists because it failed? I know, "quality of list" is probably not that important to most spammers, but certainly most would want to purchase a list of email addresses that are "known good". If I was a spammer and I had a list of "hard addresses" that I could pull out of my database before I resold it, I would think that i could sell my list for more because it's more accurate... no? Thinkin out loud... > -----Original Message----- > From: R. Scott Perry [mailto:[EMAIL PROTECTED] > Sent: Friday, March 19, 2004 10:27 AM > To: [EMAIL PROTECTED] > Subject: RE: [IMail Forum] Spam > > > >The IPSec filter seems to be working great, and unless I've got this > >wrong, actually has the net effect of bogging down the > spamming server > >somewhat... because instead of being outright rejected, the > sending server > >simply believes that our machine is unreachable, and keeps > the spam in its > >smtp queue for up to three days (someone correct me if I'm > wrong here!). > > Unfortunately, it won't hurt many of the spammers. Most spam > these days is > sent from spamware that the spammers hired someone to write. > It's designed > simply to get out as much spam as possible. Most likely, if it can't > connect, it will add your E-mail address to a separate list. > Once it's > done sending out the easy E-mail, if the spammer has more > spam to send, > they will send it and forget about the harder addresses. If > they don't > have more spam to send, they will then try the harder > addresses. But if > they do, it's because they have free CPU cycles and other > resources to do so. > > A few years ago, tricks like this worked well, as spammers > were simply > using open relays. Back then, the mailserver would act just > like IMail and > queue the E-mail and try it again later, and keep trying for a few > days. But spammers like using their own spamware better. > That lets them > customize their spamware to their unique needs. > > -Scott > --- > Declude JunkMail: The advanced anti-spam solution for IMail > mailservers > since 2000. > Declude Virus: Ultra reliable virus detection and the leader > in mailserver > vulnerability detection. > Find out what you've been missing: Ask for a free 30-day evaluation. > > --- > [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
