I had a client ask me today to turn on an email confirmation request service like "SpamLion" (http://www.spamlion.com/)

The "bounce" message that SpamLion sends is:
----------
An e-mail you have just sent to [EMAIL PROTECTED] is
being held until you complete a simple one-time-only registration.

To verify you are a real person, just click on the link below:
http://mail.domain.com/642302363309

Alternatively, you can use the reply button on your e-mail program to send
this message back to [EMAIL PROTECTED]

That's it!  You're done! Your original message will be on its way.

This one-time registration allows you to freely send messages to any address
at Our Company LLP.
------------------------
Below is the response that I sent him as to why a "service" like that is a bad idea. What say you other Mail Admins?
-----------
This is something I would have to turn on at the mail server level which I would not want to do and would strongly recommend against that type of software even if it could be installed at the "client" level.


There has been much discussion among the Mail Administrator community on this type of "service". One of the big reasons against doing it is that it requires the sender to respond. That works fine if the sender is a "person" but what happens when the sender is a "service" like a bank sending a statement (for example my bank sends me an activity report every day and my Scottrade account does so every month too), a travel service (Travelocity, Priceline, Southwest Airlines, etc) sending confirmation of a reservation, notice from eBay of a winning auction, and the list of "system" generated emails goes on and on. A service like you are wanting would continue to block those emails because the sender is not a person that is capable of responding.

Another reason is that most spam uses a "spoofed" return address - meaning that the person listed as having sent it did not really do so rather their address was just "used" by the spammer. This type of system will see the innocent person whose email address was stolen getting swamped with these type of confirmation requests. All he has to do is register his frustration that he is getting killed with these type of confirmations is to reply and now all the email that is using his address will be allowed right in to your email box because it is now "trusted".

A good example of the weakness of this type of system would be that you would have my email address in your "trusted" list, but checking the last week (back to 12/13/2004) worth of spam that I have quarantined (6,175 pieces of email) on the server shows that four messages sent by a computer that is infected with a virus is using my return address as the sender. No telling how many more email messages spoofing either mine or other email addresses that you would "trust" out of the +29,000 pieces of email that failed spam checking to the point that the email was deleted without going to quarantine.
--------------------



To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to