ietf-asrg
[Top] [All Lists]

550 vs discard - Re: [Asrg] 2. Analysis and characterization work

2003-09-03 07:12:45

Hello,

Sorry if I'm a little out of subject of the thread. I'm somewhat new to the 
group.


Terry Sullivan wrote:
On Tue, 02 Sep 2003 10:52:13 +0100, Jon Kyme wrote:


it may be thought useful to make both sets avid for spam, for a period before the study starts, ...

[snip]

However, this gives us two groups, one with stable 550 behaviour (not550->not550) and one in which we have changed the behaviour (not550->550), so the hypothesis is somewhat different.



I'd like to propose to check the effect of "discarding" the spam, instead of 
answering.

Discard here means : if you're really sure the message is a spam, don't answer and do some log, internal report...

This is equivalent to the situation : if someone says something that hurts you, if you answer him, you may start a "flame war".

This is something I'm remarking at our organisation. We use some spam filters and being more and more aggressive against spam. This means sending 550 answers to spammers and gateways sending us spam.

The consequence is that I think spammers are also being more and more agressive, mainly with some DoS attacks and spam being sent with forged users from our domain.

So I'm thinking about simply discarding messages.

What are the consequences ?

If you send a 550 code, the spammer will know his message was rejected, and eventually why. If the code was sent after DATA command, the spammer knows the recipient is a valid recipient, if the client is a computer controled by the spammer. If this isn't the case, someone which has nothing to do will receive the thousands and thousands of bounces...

If you silently discard, the spammer will know that final user MAY exists, but 
his not sure.

I know the problem is some more complex than this, but maybe there is a difference in both cases.

Best regards,

Jose-Marcio


--
 ---------------------------------------------------------------
 Jose Marcio MARTINS DA CRUZ           Tel. :(33) 01.40.51.93.41
 Ecole des Mines de Paris              http://j-chkmail.ensmp.fr
 60, bd Saint Michel                http://www.ensmp.fr/~martins
 75272 - PARIS CEDEX 06      
mailto:Jose-Marcio(_dot_)Martins(_at_)ensmp(_dot_)fr


_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg