<snip> Hmm...don't agree with that. Designating the Comcast MXs in SPF records eliminates the suspicion of forgery in the sense that I think you're using. </snip>
I'm quite sure I don't understand the nitty gritty of SPF...it took some help from the esteemed Scott Perry to get mine put in place. what I meant by forgers is that the home-worker who can't reach his company mail server because of the port 25 block simply changes to the Comcast MX but continues to use their company email address on all their email, thus the sender domain says one thing and the network it came from says something else entirely, and is then suspect. I don't know if an SPF aware gateway is supposed to pull SPF records from the sender domain, or attempt to dig from the sender IP to find SPF records for that network, or both (admitting ignorance but willing to learn!). For the record, not an absolute rejection trigger, but within the scope of my tiny environment such a forgery is cause for an X-header in a weighting system. Depending on who one tends to get mail from one's mileage may vary, even to the point of worthless, but it fits us here. If a provider is going to block 25, then maybe they should also override the SMTP envelope to use the customer's email address in the Mail From. Certainly they should be able to allow customers that request it to use 25 normally on a per-case basis. I'm sure there are companies out there that have policy about company mail must go through company servers, and they are then forced to provide for access on other ports in addition to 25, pushing the cost of the problem onto those companies. Chris ----- Original Message ----- From: Sanford Whiteman To: Chris Langsenkamp Sent: Wednesday, May 26, 2004 8:29 PM Subject: Re[2]: [IMail Forum] Spam and Comcast > I still say removing all the RDNS records for all those customer > cable modem addresses would make it easy enough for us to refuse > them at the gateways. "All those" meaning the zombies? The prob with that is that without the PTR, you don't have a near-authoritative way of knowing that they are a Comcast block anymore, so you can't do a sure-fire combo test--and it's still not feasible for many servers to reject on no PTR alone. Now, _changing_ the PTR to include 'abuser-' would be interesting. :) > I just can't see port 25 blocking as a good idea...it just makes the > users into forgers, and that's just as bad. Hmm...don't agree with that. Designating the Comcast MXs in SPF records eliminates the suspicion of forgery in the sense that I think you're using. Unfortunately, that is the theoretical side; in practice, the fact is that many of the high-falutin' providers do not know how to provision mail services for uptime and performance, and thus smarthosting through consumer-level gateways is often completely unacceptable. Still, I take the position that $18 billion companies should apportion funds to police abuse at any level. If, because of lack of interest or claimed lack of funds, they can't do the job on their outgoing mail--even with the tacit approval of the privacy hounds for egregious misuse--they should be hit hard. Anyway, if their selective "reconfigure the cable modem" method works, that would theoretically be fine, but why on earth are they so afraid to do this at the core, instead letting hackable CPE do the job? --Sandy ------------------------------------ Sanford Whiteman, Chief Technologist Broadleaf Systems, a division of Cypress Integrated Systems, Inc. e-mail: [EMAIL PROTECTED] SpamAssassin plugs into Declude! http://www.mailmage.com/products/software/freeutils/SPAMC32/download/release/ Defuse Dictionary Attacks: Turn Exchange Addresses into IMail Aliases! http://www.mailmage.com/products/software/freeutils/exchange2aliases/download/release/ To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
