ietf-dkim
[Top] [All Lists]

Re: [ietf-dkim] Thoughts on ADSP discardable messages BCC'ing the postmaster? (akin to a FBL)

2012-06-17 22:07:06
I'm reading the archives on ADSP and haven't seen anyone pitch the idea
that on verification failure, we could have the message in question would
be BCC'd to the domain owner's administrator for review.

I am a teenager with a lot of spare time, so I'm going to send thousands 
of random messages forging your domain, so you get copies of all of them.
Perhaps inventing yet another channel for indirect mailbombing is not a 
good idea.

This is not a hypothetical issue -- my abuse.net domain is forged enough 
that I've gotten 400,000 useless bounces in one day to random addresses in 
the domain.  It would not have been useful to get 400,000 more helpful 
notifications to my postmaster address.

By the way, I'm one of the authors of ADSP, and in my opinion, ADSP 
discardable is completely useless.  There are indeed domains whose mail is 
such a phieh target that it's worth losing a few real messages to get rid 
of all the phishes, but ADSP is not an effective way to find out who they 
are.

Regards,
John Levine, johnl(_at_)iecc(_dot_)com, Primary Perpetrator of "The Internet 
for Dummies",
Please consider the environment before reading this e-mail. http://jl.ly
_______________________________________________
NOTE WELL: This list operates according to 
http://mipassoc.org/dkim/ietf-list-rules.html

<Prev in Thread] Current Thread [Next in Thread>