ietf-clear
[Top] [All Lists]

[ietf-clear] HELO + DNS correctness stats

2004-12-02 01:54:28
On Wed, 1 Dec 2004, John Leslie wrote:

   (One question though: how do repeat attempts for the same email
count here?)

They're counted for each attempt. Our temporary rejection rate is about
0.5 per second compared to our total rejection rate of 10-13 per second.

Of the rejected messages, 80% have a completely bad HELO domain, and 2%
have a HELO domain that's correct only in the forward direction.

   (I'm not sure why you reject that 2%.)

Common reasons are incorrect recipient address, nonexistent MAIL FROM
domain, blacklisted sending host, attempts to use us as an open relay,
and other fairly obvious criteria.

   I would definitely expect to continue much the same HELO checks you
now do (when CSV becomes well-deployed), and merely use CSV to bypass
the rejection for sessions both authenticated and authorized (or at least,
for _some_ of those).

Actually, CSV would replace one of our tests which is to reject clients
that say HELO cam.ac.uk or any of our other mail domains. We won't
use CSV to bypass our other checks until decent reputation services are
available.

Tony.
-- 
f.a.n.finch  <dot(_at_)dotat(_dot_)at>  http://dotat.at/
MALIN HEBRIDES: NORTHEAST 4 OR 5 INCREASING 6. RAIN LATER. GOOD BECOMING
MODERATE.