On 8/27/19 03:54, Andy Smith via mailop wrote:
Last week or so I noticed that I can no longer send SpamCop reports
to a large hosting provider. The option now shows up as:
abuse#[email protected]
with no explanatory text.
Spamcop doesn't send reports to well known spammers because it doesn't
cause them to alter their behavior in a good way (such as stopping the
spam). Often they alter their behavior in a bad way such as listwashing,
or they do nothing.
In the past when I have seen this, I have assumed that SpamCop was
unable to find a reporting address, or the address bounces, or the
provider has told SpamCop to stop sending them reports.
There are different errors where the spam source refuses munged reports
or user-defined reports, or indeed no functional reporting address can
be found.
Since…
a) I know this used to work, and
b) this is a pretty big provider that I am often sending reports to, and
So you're receiving spam from them, you're often sending reports to them
about it, and the spam keeps coming. That's a hint.
c) I know that provider is represented on this list
There are lots of providers on this list, and a recurring theme from
some of them is, "Help, I'm on $BLOCKLIST, how do I get off of it?"
Being represented on this list doesn't preclude someone from being a
spammer.
…yesterday I sent the representative of that provider a direct email
asking why they are no longer accepting SpamCop reports.
Today they kindly replied to let me know that they still welcome
SpamCop reports but SpamCop has decided that their customers have
been listwashing and for that reason SpamCop will not send them any
further reports.
The fact that said provider still is taking money from those customers
and sending mail on their behalf despite multiple complaints from
Spamcop is another hint.
I don't know any more details, particularly I don't know the scale
involved here. I suppose I could see an argument that if there's a
huge number of reports then the provider is letting their customers
listwash when they should be enforcing AUP on them. But is that
SpamCop's fight?
Spamcop isn't in the business of facilitating spamming, their goal is
just the opposite. Listwashing facilitates spamming as it reduces the
complaint percentage while allowing the spam to continue.
From my end as the reporter I'm not really seeing much of an uptick
in reports to this large provider, and I do sometimes get a response
from them to say they're dealing with stuff, so I'd prefer that I
could continue sending reports.
Are you still seeing spam from this provider? Despite their occasional
responses that they're "dealing with stuff" does the spam continue?
That's another hint.
Given the choice of either not reporting or risking listwashing, I
think I would rather risk the listwash. I can do my own analysis to
decide whether to stop reporting and start blocking more
aggressively.
Don't use Spamcop then. Send your complaints directly to the abuse desk.
Let us know if it does any good.
Or take the chance and hit the "Unsubscribe" link on something to which
you never subscribed. This risks the possibility that your address will
be sold to other spammers as "one who has responded to similar offers".
The spammer knows that you took the time to read the message, and you
did in fact respond.
If SpamCop really wants to take a stance on listwashing then I would
much rather they gave an option on their reporting page. At the
moment there are some providers who do not accept the anonymised
SpamCop reports and for these SpamCop leaves the checkbox unchecked.
Spamcop reports really aren't very thoroughly anonymized. Most bulk
senders embed tracking bug spyware in the message that Spamcop doesn't
redact. Spamcop cleans the headers but leaves the body intact.
When you check it, it pops up a warning saying that your real email
address will be passed along if you continue. Perhaps they could do
similar for the providers they deem to allow too much listwashing?
Fundamentally, the way it is now, it is not possible to distinguish
providers who refuse reports from providers who SpamCop refuses to
report to, and I think that is not ideal.
To me it's pretty obvious. When you see a valid abuse reporting address
modified to @devnull.spamcop.net it's an indication that the provider
doesn't care. It doesn't make any real difference whether they refuse
reports entirely or continue spamming despite receiving reports, they're
going to keep spamming.
In fact, I have used SpamCop's ability to send reports or not as
part of my stance on how aggressively to deal with email from
various providers before, thinking that it's always down to the
provider. I now realise that may have been an incorrect assumption.
What are the list's thoughts?
The sender's reputation is bad enough that Spamcop has given up on them
and you're still seeing spam after you've been sending complaints for a
long time. It may be 5.7.1 time. Or deal with it at layer 3 before it
gets to your MX.
Are you seeing any ham from that source?
Is there some other service other than SpamCop that I should be
using to send reports? I do not have time to check headers and send
emails to individual abuse addresses on individual samples of spam.
Checking SpamCop's workings and then hitting send is much more
convenient, but this has really dented my confidence in it.
On the other side as a very small hoster, I occasionally receive
SpamCop reports about my customers and generally find them
actionable and useful so this is a real shame.
Spamcop's reports are indeed very likely to be actionable, and thank you
for indeed taking action. In cases where senders receive multiple
actionable reports and take no action or the wrong action, Spamcop gives
up on sending them reports. Would you have bothered to send spam reports
to Sanford Wallace back in the day?
--
Jay Hennigan - [email protected]
Network Engineering - CCIE #7880
503 897-8550 - WB6RDV
_______________________________________________
mailop mailing list
[email protected]
https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop