ietf-asrg
[Top] [All Lists]

RE: [Asrg] Ban the bounce; improved challenge-response systems

2003-04-06 05:34:47
You also assume that mail is delivered to directly connected systems
only.  What about, say, domains sitting behind UUCP or ETRN links
wherein the relay box *HAS* no knowledge of accounts 
configured on that
domain as it has no organisational ties to it other than as an MX.

I think twenty years is more than enough time to phase out
an obsolete protocol. If stopping spam breaks UUCP then UUCP
breaks, don't give it a second's thought, that is a problem
for the UUCP diehards to solve, on their own.

I would start from a different premise, I would not 'ban the bounce'
instead I would observe that bounces are going to be much less
likely to get through in the future.

One approach we could take is to add in an authenticator token
into outgoing messages in such a way that it will be returned
in the bounce. That way an MTA can know if a bounce is legit
and not spam.

This is fairly easy to do with a standard secret & MAC 
protocol.

However that is only solving one part of the problem. The
bounce messages should carry the same info as SMTP error
codes and it should be possible for the MTA to process 
bounces in a transparent fashion without showing the bounce
message.


                Phill
_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg



<Prev in Thread] Current Thread [Next in Thread>