ietf-asrg
[Top] [All Lists]

RE: [Asrg] article: port 25 blocking

2005-04-11 23:45:36
Blocking port 25 harms a lot of legitimate uses.  Why not do the following
to deal with the issue as a whole.

*  Start banning all non-SPF compliant domains within a certain deadline
which would effectively make port 25 blocking moot.
*  Then we deal with the problem of ISPs who don't implement SMTP AUTH and
who won't implement some reasonable rate limiting schemes.
*  Then start requiring some sort of official registration or bonding of
domains who bulk send (based on Distributed Checksum Clearinghouse
measurements) so that we can either easily track you down for prosecution or
we confiscate the bond for any kind of abuses from an SPF abusive domain.

These steps would seem to me a lot more effective and cause a lot less
collateral damage.  As the owner of a few small personal domains and someone
who uses outbound 25 for legitimate SMTP relay, I'd much rather you force me
to put in a few SPF records than blocking my outbound port 25 access.  We're
essentially talking about the same thing here only from different sides of
the problem.  Do we create an ACL (Access Control List) that denies all
non-SMTP servers of the world or do we create an ACL that permits all
legitimate SMTP servers of the world?  It would seem to me that the latter
is a much smaller database and much easier to implement than the former.


George Ou


-----Original Message-----
From: asrg-bounces(_at_)ietf(_dot_)org 
[mailto:asrg-bounces(_at_)ietf(_dot_)org] On Behalf Of Gadi
Evron
Sent: Monday, April 11, 2005 9:38 PM
To: 'asrg(_at_)ietf(_dot_)org'
Subject: [Asrg] article: port 25 blocking

Larry has been asking a ton of questions of people online, and participating
in professional discussions on the subject, on other lists. Here is the
result of the information he gathered:

http://www.eweek.com/article2/0,1759,1784276,00.asp

        Gadi.

_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg


_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg