ietf-asrg
[Top] [All Lists]

Re: [Asrg] 1. Inventory of Problems - SMTP

2003-12-17 10:30:40
On Wed, Dec 17, 2003 at 09:26:32AM +0000, Jon Kyme wrote:
Of course, but this policy violates RFCs - what happened to the 100 RCPT
requirement? I'd be happy to see this kind of behavior written up in some
way - revising rfc2821. There's a whole lot of things that work better if
this requirement can be ignored.

Depends on how you see it. According to RFC 2821
------------------------------------------------------------------------
7.7 Scope of Operation of SMTP Servers
   It is a well-established principle that an SMTP server may refuse to
   accept mail for any operational or technical reason that makes sense
   to the site providing the server.  However, cooperation among sites
   and installations makes the Internet possible.  If sites take
   excessive advantage of the right to reject traffic, the ubiquity of
   email availability (one of the strengths of the Internet) will be
   threatened; considerable care should be taken and balance maintained
   if a site decides to be selective about the traffic it will accept
   and process.
------------------------------------------------------------------------

We have operational and technical reasons to act as we do and to
override the 100 RCPT limit imposed by the RFC.
From our observations the only impact on the Internet mail system
is that bulk senders need more circles to get their messages through
so we think we have taken considerable care and still maintained the
balance.
From yesterdays logfile on a machine without the limits (only
connections from external hosts):

count no of rcptto per connection

   1 58
   1 32
   1 28
   1 27
   2 26
   1 25
   1 24
   2 23
  35 20
  12 19
  10 18
   5 17
  20 16
  35 15
  26 14
  17 13
  34 12
  44 11
 208 10
 155 9
 186 8
 199 7
 333 6
 460 5
 673 4
1369 3
5241 2
134885 1

This means e.g. that we had  5241  connections sending 2 rcptto during
one connection and we had 1369 connections sending 3 rcptto during one
connection.

We had 143957 connections in total.
93% of all connections sent only one RCPT TO
Allowing up to 5 RCPT TO per connection makes up for 99.076% of all
connections.

The host with 58 rcptto in one connection was definitely legal email.
It looks like MX sorting and maybe a SMTP MTA on a dialup line, as there
were about 20 different envelope senders (small company sending email to
field staff; we're running the Mailboxes for some of their field staff).

However the next hosts in the "hit list":

32 unknown:216.244.148.251                      dictionary spam
28 unknown:218.28.13.138                        dictionary spam
27 unknown:211.224.65.91                        dictionary spam
26 cmb8-162.dial-up.arnes.si:194.249.38.162     dictionary spam
26 216.93.176.221:216.93.176.221                dictionary spam
25 67-23-157-81.chvlva.adelphia.net:67.23.157.81 dictionary spam
24 unknown:212.6.96.162                         dictionary spam
23 unknown:203.82.168.133                       dictionary spam
23 unknown:81.195.151.34                        dictionary spam

        \Maex

-- 
SpaceNet AG            | Joseph-Dollinger-Bogen 14 | Fon: +49 (89) 32356-0
Research & Development |       D-80807 Muenchen    | Fax: +49 (89) 32356-299
"The security, stability and reliability of a computer system is reciprocally
 proportional to the amount of vacuity between the ears of the admin"

_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg