ietf-asrg
[Top] [All Lists]

Re: [Asrg] Whitelisting on Message-ID (Was Turing Test ...) honey pot plug

2003-04-07 09:27:59

On Monday, April 7, 2003, at 08:53  AM, Brad Spencer wrote:

The second is the important one for me. Some people talk as if all we have to do to end spam is close the open relays. I am not so sure this is the
case.

That (all we have to do to end spam is close the open relays) was the belief (apparently) a few years ago. I doubt few believe it now.


I was curious, so I took a quick look. My home system runs no RBLs, no filters, I do my spam filtering in mail.app on OS X right now. So I get a full feed without anything in the way. About 50% of my inbox is flagged as spam, and mail.app now has about a .01 false positive (usually e-newsletters from places like Orbitz and Burpee seeds), and about a 97% hit rate. Not bad.

But it also allows me to go wander through the spam and look at things. I went and looked at 25 random messages that I've gotten since midnight. By evaluating headers, I saw 18 came in direct from the spammer, or were inserted into the delivery box via an open proxy, 1 definitely came in through an open proxy, and six came in through open relays.

So only about 1/4 of the spam came from open relays.

I looked up the various sites in spamcop, just to see what was in there. the one open proxy was also in spamcopy. Of the 18 direct/open relay sites, 10 were blocked in spamcop. Of the 6 open relays, 3 were blocked in spamcop.

and just for your amusement:

http://spamcop.net/w3m?action=checkblock&ip=212.216.22.67


_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg