Hello Scott, On Monday, November 25, 2002 at 4:31:39 PM you [S] wrote (at least in part):
>> At last - in 90% you'll got on your fake bounce real bounce from real MTA >> - "User not found"... forged from in spam - common technique > Hmmm, interesting point. Might cause a few problems with wierd mail > loops. Although at some point, you'd think a mailserver would kill > the chain... No. No correctly configured MTA will do so, as this ain't a 'mail loop' but a 'mail ping-pong'. A big difference. It's _not_ the same mail being delivered over and over again (classical mail loop) but different mails being sent. The way out is one of the parties sets an empty Return-Path '<>' which tells the next bouncing party to treat the 'bounce' as 'double bounce' and handle it in a special way. This does work because a 'bounce' in general is _not_ directed to 'From:' from original mail but to 'Return-Path'. Nevertheless in most cases your type of automated reply will not lead to anything positive. Most Return-Paths of spam mails are simply faked, as From headers are as well. So the best you can achieve is the postmaster of your ISP is getting angry about the amount of double bounces in his inbox, tracing back these mails and telling _you_ to stop. It's pure abuse of bandwidth sending faked bounces, the most simply, time effective, bandwidth saving way of handling is deleting recognized spam. The second best way is making use of SpamCop or similar institutions that deal with blacklists. This does not prevent your _directly_ from getting spam, but chances are high you don't get the next one from same spammer using same ISP too soon. HTH Pit P.S.: Scott: could you try to break your lines at around 72-75 characters? Makes it easier to reply in a readable way :-) -- Regards Peter Palmreuther (The Bat! v1.62/Beta7 on Windows 2000 5.0 Build 2195 Service Pack 1) Apt natural. I have a gub. ________________________________________________________ Current beta is 1.62b5 | "Using TBBETA" information: http://www.silverstones.com/thebat/TBUDLInfo.html

