<snip>
Hmm...don't  agree  with  that.  Designating  the  Comcast  MXs in SPF
records  eliminates the suspicion of forgery in the sense that I think
you're   using.
</snip>

I'm quite sure I don't understand the nitty gritty of SPF...it took some help from the 
esteemed Scott Perry to get mine put in
place.  what I meant by forgers is that the home-worker who can't reach his company 
mail server because of the port 25 block simply
changes to the Comcast MX but continues to use their company email address on all 
their email, thus the sender domain says one thing
and the network it came from says something else entirely, and is then suspect.  I 
don't know if an SPF aware gateway is supposed to
pull SPF records from the sender domain, or attempt to dig from the sender IP to find 
SPF records for that network, or both
(admitting ignorance but willing to learn!).

For the record, not an absolute rejection trigger, but within the scope of my tiny 
environment such a forgery is cause for an
X-header in a weighting system.  Depending on who one tends to get mail from one's 
mileage may vary, even to the point of worthless,
but it fits us here.

If a provider is going to block 25, then maybe they should also override the SMTP 
envelope to use the customer's email address in
the Mail From.  Certainly they should be able to allow customers that request it to 
use 25 normally on a per-case basis.  I'm sure
there are companies out there that have policy about company mail must go through 
company servers, and they are then forced to
provide for access on other ports in addition to 25, pushing the cost of the problem 
onto those companies.

Chris
----- Original Message ----- 
From: Sanford Whiteman
To: Chris Langsenkamp
Sent: Wednesday, May 26, 2004 8:29 PM
Subject: Re[2]: [IMail Forum] Spam and Comcast


> I  still  say  removing  all the RDNS records for all those customer
> cable  modem  addresses  would  make it easy enough for us to refuse
> them  at  the  gateways.

"All  those"  meaning  the zombies? The prob with that is that without
the  PTR, you don't have a near-authoritative way of knowing that they
are  a  Comcast  block  anymore,  so  you  can't  do a sure-fire combo
test--and it's still not feasible for many servers to reject on no PTR
alone.

Now, _changing_ the PTR to include 'abuser-' would be interesting. :)

> I just can't see port 25 blocking as a good idea...it just makes the
> users into forgers, and that's just as bad.

Hmm...don't  agree  with  that.  Designating  the  Comcast  MXs in SPF
records  eliminates the suspicion of forgery in the sense that I think
you're   using.  Unfortunately,  that  is  the  theoretical  side;  in
practice,  the fact is that many of the high-falutin' providers do not
know  how  to  provision mail services for uptime and performance, and
thus  smarthosting through consumer-level gateways is often completely
unacceptable.  Still,  I  take the position that $18 billion companies
should  apportion  funds  to police abuse at any level. If, because of
lack  of  interest  or claimed lack of funds, they can't do the job on
their  outgoing  mail--even  with  the  tacit  approval of the privacy
hounds for egregious misuse--they should be hit hard.

Anyway, if their selective "reconfigure the cable modem" method works,
that  would theoretically be fine, but why on earth are they so afraid
to do this at the core, instead letting hackable CPE do the job?

--Sandy


------------------------------------
Sanford Whiteman, Chief Technologist
Broadleaf Systems, a division of
Cypress Integrated Systems, Inc.
e-mail: [EMAIL PROTECTED]

SpamAssassin plugs into Declude!
  http://www.mailmage.com/products/software/freeutils/SPAMC32/download/release/

Defuse Dictionary Attacks: Turn Exchange Addresses into IMail Aliases!
  
http://www.mailmage.com/products/software/freeutils/exchange2aliases/download/release/


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to