We appreciate your work and all the other blacklists out there but we better come up with some new plays because we're losing this game. The fact that we have to setup and maintain all this is ridiculous and we spend more and more time on it as this goes on. I think targeting the spammer customers was the right idea and apparently they were worried as well.

Matt wrote:

I'm afraid to say that this person is in fact in danger of being blacklisted. I run a private blacklist with 6 return codes and over 1 million IP's that were manually collected (in blocks), and will frequently tag all space related to a particular spammer. So if I looked up one block in ARIN and then found the others by association, I would generally research those as well. Chances are that this situation would confuse me and there's no telling how I might list such a thing since I can't say that I can recall ever finding such a block that I was aware of. I'm sure that several other blacklists do this as well, and most with much less care in terms of research.

There are also other blacklists that will do collateral damage to spam hosting companies. Everyone should know that SPEWS does this, but Spamhaus will also do this on some occasions. I don't participate in any collateral damage, especially since it would be quite ineffective with only a few systems using the zones that I maintain.

It is very wise for everyone to make sure that ARIN no longer lists the company's information with old blocks of IP's that are no longer delegated to you. Contacting the IP provider and having them change it (demanding) is the proper course of action.

Matt



R. Scott Perry wrote:


About ten years ago we changed our ISP and got a new block of IPs to use. Our domain name stayed the same. The old ISP never cleaned out the contact information on the old block of IPS.

Apparently someone is now spamming through our old block of IPs. Anyone doing a whois on the old block would find our domain info. I've contacted the ISP and they've corrected the info on that block, but I'm wondering...

Would I have been in danger of being blacklisted?



No.

Very, very few blacklists work on domains instead of IPs. Those that do must be careful not to blacklist any innocent domains, as domains can *always* be forged by spammers.

Of course, there are some exceptions (for example, lists of spammer URLs often aren't checked), but those shouldn't apply. Anyone smart enough to find your contact info will know that it could be faked (or old, in this case).

-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000.
Declude Virus: Ultra reliable virus detection and the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask for a free 30-day evaluation.



----
This outgoing message is guaranteed to be authentic by Message Level users.
Guarantee the authenticity of your email @ http://www.messagelevel.com.
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]



To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/







To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to