Aside: Clicking Reply-All in Microsoft Outlook only put Luis and Andy into the To: box. I had to manually add mailop.
My view is that (generally), Operations that're so big as to receive many reports a day, grossly under-resource their abuse-response capability and don't particularly care about 'minor' (read: non newsworthy) cases of abuse on their networks. I once managed abuse@ for what in my country was officially a very large ISP - 500k customers. There was about 1.3FTE dedicated to abuse@ and I was the .3. We made a valiant attempt to keep up with inbound complaint loading but all too often, the complaints would essentially roll-off the queue (complaints >1month old were harder to investigate as the logs required to track back offending users, were archived after that). This is many years ago - early 2000's. I don't imagine a lot has changed. Mark. -----Original Message----- From: mailop [mailto:[email protected]] On Behalf Of Luis E. Muñoz via mailop Sent: Wednesday, 28 August 2019 11:54 a.m. To: Andy Smith <[email protected]> Cc: [email protected] Subject: Re: [mailop] SpamCop and listwashing On 27 Aug 2019, at 16:23, Andy Smith via mailop wrote: > So, where else can one go to streamline the spam reporting process? > This page lists only SpamCop and Abusix: > > https://en.wikipedia.org/wiki/Spam_reporting > > As far as I can see Abusix in this context is only an > IP-to-abuse-contact lookup tool. Years ago, while in charge of anti-abuse operations for a sizable group of users, I tried hard to address this challenge. SpamCop was around, Abusix wasn't. Long story short, we ended up implementing direct abuse contact lookup using WHOIS — at that time this was still a feasible exercise. Our reports included logs about the incident — mail headers, ACL logs, whatever was appropriate — and we had actual people, me included, manning the Reply-To of those. The results were mixed and in retrospect, perhaps interesting. Operations that were large enough so as to receive many reports a day — we sent one report per "incident"/day — often complained or outright blocked / devnulled our reports. Complaint receivers that got lots of complaints often claimed that they were unable to process them in such volumes. Based on the traffic we saw from them, their lack of time wasn't related to preventing hostile traffic from leaving through their door. Operators with only the occasional report were in some cases responsive, as we saw the abuse stopped. Some even responded. Some asked us to make special arrangements for their reports to go to a special address, which we were happy to oblige. We got to know who were the good guys and who were just making the right noises. As I'm sure does SC. All this said and done, a huge proportion of the reports we sent to published points of contact for network level objects simply bounced. I guess I'm trying to say is that getting abuse complaints to the right hands, at scale, is way harder than it seems. "Streamlining" the process is hard, and once you walk that path I'm sure you'll get to a similar conclusion: Some folks don't deserve the bits used to send the complaint. -lem _______________________________________________ mailop mailing list [email protected] https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop _______________________________________________ mailop mailing list [email protected] https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop
