procmail
[Top] [All Lists]

Re: regarding a possible filter

2006-07-30 11:36:28
Hrm, this spent a while in my outbox because I got busy with some 
construction work...

At 13:31 2006-07-25 -0500, TLD Procmail wrote:
like "pookie" don't apply, as we're required to put at least our first
or last name.

So, you can enforce addressing standards on your employees - but I rather 
doubt these are the people who are the source of your spam problems - 
surely it's the mail FROM OUTSIDE your network which is what you're 
concerned with?

As for it being arbitrary, so are the individual tests that comprise
most scanners like spamassassin.

Not really true.  Names and how someone has YOUR address in THEIR 
addressbook will be a lot more arbitrary than you think.  NAMES are not 
governed by internet standards.  The addresses themselves are.

Look at how many variations there are in the name portion on posts to 
discussion lists (i.e. the name associated with the list address).  Take 
this list for example.


       1 To: "'[procmail] Mailing List'" 
<procmail(_at_)lists(_dot_)RWTH-Aachen(_dot_)DE>
       6 To: "[procmail] List Mailing" 
<procmail(_at_)lists(_dot_)RWTH-Aachen(_dot_)DE>
       7 To: "[procmail] Mailing List" 
<procmail(_at_)lists(_dot_)RWTH-Aachen(_dot_)DE>
      19 To: "[procmail]" <procmail(_at_)lists(_dot_)RWTH-Aachen(_dot_)DE>
       1 To: Procmail <procmail(_at_)lists(_dot_)RWTH-Aachen(_dot_)DE>
       1 To: Procmail List <procmail(_at_)lists(_dot_)RWTH-Aachen(_dot_)DE>
      78 To: procmail(_at_)lists(_dot_)RWTH-Aachen(_dot_)DE
       1 Cc: "[procmail]" <procmail(_at_)lists(_dot_)RWTH-Aachen(_dot_)DE>
       4 Cc: procmail(_at_)lists(_dot_)RWTH-Aachen(_dot_)DE

This is just for the past month, Note the HUGE difference between the count 
of unadorned addressing (82 posts) versus the next closest form (20), and 
everything else is single digits.

The majority of regular contributors here don't bother with a name text.

  The lack of a name won't be an end all, be all, of course, but due to
the fact that
a large portion of the emails we get *do* have a name provided, the rare
few that
don't have them (and are legit) should be negligible.

I suspect that the only ones you'll get that will conform to a standard are 
REPLIES to messages which your employees have sent (since they'd presumably 
have carried their name out in the From: field in the proscribed fashion), 
and when the recipient clicks [REPLY], their email program SHOULD pull up 
the complete contents of the From: field and use it in the new 
To:).  Anyone who keys in an email address from a business card or phone 
exchange is unlikely to take the extra steps to type someones name in as a 
comment.  That's where you're going to run into trouble.  If they key a 
name/comment, it may be the COMPANY name, or company/deparment, because 
they don't have a personal relationship with the person - they're just an 
extension of the company.

I don't save spam, no.  But I have been watching the spam coming through
for the last 6 months or so and have noticed this pattern.

Er, that spammers use just email addresses, and not associated names?  No 
surprise.

Well, good luck with it anyway.

---
  Sean B. Straw / Professional Software Engineering

  Procmail disclaimer: <http://www.professional.org/procmail/disclaimer.html>
  Please DO NOT carbon me on list replies.  I'll get my copy from the list.


____________________________________________________________
procmail mailing list   Procmail homepage: http://www.procmail.org/
procmail(_at_)lists(_dot_)RWTH-Aachen(_dot_)DE
http://MailMan.RWTH-Aachen.DE/mailman/listinfo/procmail

<Prev in Thread] Current Thread [Next in Thread>