On Fri, Nov 21, 2003 at 03:56:39PM -0500, John R Levine wrote:
|
| Spamcop tries to estimate the total nummbers from the number of queries on
| the BL relative to the number of spam reports, but as we all know, both
| the numerators and denominators can be a lot way from reality. Or look at
| senderbase, which is about as good as your're going to find, but people
| who should know say that their volume estimates aren't great either.
|
Correct me if I'm wrong, but the "sender" in Senderbase seems to be the
PTR domain name of an SMTP client, not the MAIL FROM envelope sender.
Thus its results are not terribly meaningful, no matter what their
volume actually is.
I would dispute your assertion that those results are as good as I'm
going to find. I see at least a million messages a day, and I expect
plenty of other not-terribly-large mail systems do too. Even after
discarding all transactions that do not meet SPF-best-guess=pass, we can
start producing reasonably accurate reputation scores remarkably
quickly. I expect such a procedure to identify, say, rm04.net,
maildeliverer.com, someonelikesyou.com, and so on. If it does, and if
SPF manages to encourage spammers to spam using their own domain names,
that means we'll be able to find them using automated means.
These are the messages from my spam folder which passed SPF-Guess.
There are a few false positives in there, mostly order confirmations
from stores that later spammed customers with "this is your
complimentary subscription to our Specials e-newsletter!"
I'll be able to run some stats against the overall mailstream to see
establish correlations later.
20031121-16:09:20 mengwong(_at_)dumbo:~/Mail/Lists% grep '^X-SPF' spam.200311
| sort -f
X-SPF-Guess: pass: seems reasonable for abbas(_at_)hknetmail(_dot_)com to
mail through 202.67.240.32
X-SPF-Guess: pass: seems reasonable for
admopen(_at_)blue1(_dot_)open(_dot_)org to mail through 199.2.104.15
X-SPF-Guess: pass: seems reasonable for
admopen(_at_)blue2(_dot_)open(_dot_)org to mail through 199.2.104.16
X-SPF-Guess: pass: seems reasonable for amazu(_at_)freenet(_dot_)de to mail
through 194.97.50.131
X-SPF-Guess: pass: seems reasonable for
b2b(_at_)mailout(_dot_)s-infotech(_dot_)com to mail through 67.33.18.70
X-SPF-Guess: pass: seems reasonable for
bam-friends-request(_at_)bounce(_dot_)netcentral(_dot_)net to mail through
216.33.114.151
X-SPF-Guess: pass: seems reasonable for
bamm-fiction-request(_at_)bounce(_dot_)netcentral(_dot_)net to mail through
216.33.114.151
X-SPF-Guess: pass: seems reasonable for betog(_at_)mvdistribuidora(_dot_)com
to mail through 200.49.88.122
X-SPF-Guess: pass: seems reasonable for bolhk65(_at_)rr(_dot_)com to mail
through 24.170.63.144
X-SPF-Guess: pass: seems reasonable for
bounce-a5im23mhw8zsdsmqc2voqvwd(_at_)eqm0(_dot_)us to mail through 64.32.63.85
X-SPF-Guess: pass: seems reasonable for
bounce-a5imay2hw8zsdsmq82voq9ub(_at_)eqm0(_dot_)us to mail through 64.32.63.88
X-SPF-Guess: pass: seems reasonable for
bounce-a5qw3phgw8zsdsmqj2voqvja(_at_)eqm0(_dot_)us to mail through 64.32.63.84
X-SPF-Guess: pass: seems reasonable for
bounce-a5qw3x1hw8zsdsmqc2voqkjb(_at_)eqm0(_dot_)us to mail through 64.32.63.85
X-SPF-Guess: pass: seems reasonable for
bounce-a5qwdgmgw8zsdsmqc2voqkac(_at_)eqm0(_dot_)us to mail through 64.32.63.85
X-SPF-Guess: pass: seems reasonable for
bounce-a5yugbjhw8zsdsmqj2voqkxd(_at_)eqm0(_dot_)us to mail through 64.32.63.84
X-SPF-Guess: pass: seems reasonable for
bounce-actcraygw8zsdsmq82voqv1b(_at_)eqm0(_dot_)us to mail through 64.32.63.88
X-SPF-Guess: pass: seems reasonable for
bounceto-1149-690944167(_at_)bounceto(_dot_)shysterbob(_dot_)com to mail
through 64.191.36.197
X-SPF-Guess: pass: seems reasonable for
bounceto-1149-690944167(_at_)bounceto(_dot_)shysterbob(_dot_)com to mail
through 64.191.36.209
X-SPF-Guess: pass: seems reasonable for
bounceto-1149-690944167(_at_)bounceto(_dot_)shysterbob(_dot_)com to mail
through 64.191.36.228
X-SPF-Guess: pass: seems reasonable for
bounceto-1149-690944167(_at_)bounceto(_dot_)shysterbob(_dot_)com to mail
through 64.191.36.241
X-SPF-Guess: pass: seems reasonable for
bounceto-1301-690944167(_at_)bounceto(_dot_)BlingMail(_dot_)com to mail through
64.191.36.55
X-SPF-Guess: pass: seems reasonable for brg(_at_)insuranceiq(_dot_)info to
mail through 65.217.159.80
X-SPF-Guess: pass: seems reasonable for bsmg(_at_)insuranceiq(_dot_)info to
mail through 65.217.159.80
X-SPF-Guess: pass: seems reasonable for
c7gg5qdukiuqy5sfqc9u(_at_)hotmail(_dot_)com to mail through 65.54.245.101
X-SPF-Guess: pass: seems reasonable for
ChristianDebtManagement(_at_)IJST5(_dot_)com to mail through 66.63.165.64
X-SPF-Guess: pass: seems reasonable for
clubs(_at_)cybersyn7(_dot_)cyber-synergism(_dot_)com to mail through
65.59.224.153
X-SPF-Guess: pass: seems reasonable for
collectiblestodaycom(_at_)IJST5(_dot_)com to mail through 66.63.165.22
X-SPF-Guess: pass: seems reasonable for ConsumerAdvisor(_at_)IJST5(_dot_)com
to mail through 66.63.165.41
X-SPF-Guess: pass: seems reasonable for dan_willy230(_at_)fsmail(_dot_)net to
mail through 193.252.22.158
X-SPF-Guess: pass: seems reasonable for
dbrown(_at_)c80-217-203-203(_dot_)cm-upc(_dot_)chello(_dot_)se to mail through
80.217.203.203
X-SPF-Guess: pass: seems reasonable for
diane(_at_)pool-68-160-216-188(_dot_)ny325(_dot_)east(_dot_)verizon(_dot_)net
to mail through 68.160.216.188
X-SPF-Guess: pass: seems reasonable for directqlick(_at_)dq08(_dot_)net to
mail through 66.151.88.154
X-SPF-Guess: pass: seems reasonable for directqlick(_at_)dq08(_dot_)net to
mail through 66.151.88.156
X-SPF-Guess: pass: seems reasonable for directqlick(_at_)dq08(_dot_)net to
mail through 66.151.88.165
X-SPF-Guess: pass: seems reasonable for directqlick(_at_)dq08(_dot_)net to
mail through 66.151.88.202
X-SPF-Guess: pass: seems reasonable for directqlick(_at_)dq08(_dot_)net to
mail through 66.151.88.225
X-SPF-Guess: pass: seems reasonable for directqlick(_at_)dq08(_dot_)net to
mail through 66.151.88.233
X-SPF-Guess: pass: seems reasonable for
dmc(_dot_)yarley(_at_)laposte(_dot_)net to mail through 81.255.54.11
X-SPF-Guess: pass: seems reasonable for emiliano(_at_)armatuviaje(_dot_)com
to mail through 200.73.183.174
X-SPF-Guess: pass: seems reasonable for enxlp(_at_)ms1(_dot_)hinet(_dot_)net
to mail through 168.95.4.176
X-SPF-Guess: pass: seems reasonable for
errors(_at_)youwantedthismailing(_dot_)net to mail through 209.249.6.167
X-SPF-Guess: pass: seems reasonable for exhibitions(_at_)ieo(_dot_)ae to mail
through 195.229.241.85
X-SPF-Guess: pass: seems reasonable for
expert(_at_)internationalwinecellar(_dot_)com to mail through 65.214.48.91
X-SPF-Guess: pass: seems reasonable for
f(_dot_)solidaria(_at_)speedy(_dot_)com(_dot_)ar to mail through 200.51.80.17
X-SPF-Guess: pass: seems reasonable for FinancialAdvisor(_at_)IJST5(_dot_)com
to mail through 66.63.165.65
X-SPF-Guess: pass: seems reasonable for frangi(_at_)arnet(_dot_)com(_dot_)ar
to mail through 200.45.191.23
X-SPF-Guess: pass: seems reasonable for frangi(_at_)arnet(_dot_)com(_dot_)ar
to mail through 200.45.191.24
X-SPF-Guess: pass: seems reasonable for frkptrgl(_at_)insuranceiq(_dot_)info
to mail through 65.217.159.80
X-SPF-Guess: pass: seems reasonable for fthn2551(_at_)hotmail(_dot_)com to
mail through 65.54.245.23
X-SPF-Guess: pass: seems reasonable for
fundacioncane(_at_)fibertel(_dot_)com(_dot_)ar to mail through 200.89.155.100
X-SPF-Guess: pass: seems reasonable for georgeattah(_at_)fsmail(_dot_)net to
mail through 193.252.22.158
X-SPF-Guess: pass: seems reasonable for
golcpgrgvbsil(_at_)nw(_dot_)com(_dot_)au to mail through 203.33.253.251
X-SPF-Guess: pass: seems reasonable for
hhwqvjbne(_at_)ms2(_dot_)hinet(_dot_)net to mail through 168.95.4.143
X-SPF-Guess: pass: seems reasonable for
info-9FF99E1D83FA455435F5(_at_)hostnet-mars(_dot_)com to mail through
64.152.131.116
X-SPF-Guess: pass: seems reasonable for
info-9FF99E1D83FA455435F5(_at_)innovationmillenium(_dot_)com to mail through
207.182.145.6
X-SPF-Guess: pass: seems reasonable for info(_at_)artaddiction(_dot_)com to
mail through 194.242.43.188
X-SPF-Guess: pass: seems reasonable for info(_at_)artauction(_dot_)net to
mail through 194.242.43.188
X-SPF-Guess: pass: seems reasonable for info(_at_)artinfobank(_dot_)net to
mail through 194.242.43.188
X-SPF-Guess: pass: seems reasonable for
info(_at_)gamblingshows(_dot_)com(_dot_)ar to mail through 200.80.42.129
X-SPF-Guess: pass: seems reasonable for
info(_at_)heritageclassicmusic(_dot_)com to mail through 66.139.75.93
X-SPF-Guess: pass: seems reasonable for
info(_at_)maconventioncollective(_dot_)com to mail through 194.242.43.187
X-SPF-Guess: pass: seems reasonable for
jaderesto(_at_)arnet(_dot_)com(_dot_)ar to mail through 200.45.191.24
X-SPF-Guess: pass: seems reasonable for
jaderesto(_at_)arnet(_dot_)com(_dot_)ar to mail through 200.45.191.5
X-SPF-Guess: pass: seems reasonable for
jyjeventos(_at_)gamblingshows(_dot_)com(_dot_)ar to mail through 200.80.42.129
X-SPF-Guess: pass: seems reasonable for lisa(_at_)resourcedns(_dot_)com to
mail through 205.138.96.61
X-SPF-Guess: pass: seems reasonable for list(_at_)artaddiction(_dot_)com to
mail through 194.242.43.187
X-SPF-Guess: pass: seems reasonable for list(_at_)artauction(_dot_)net to
mail through 194.242.43.188
X-SPF-Guess: pass: seems reasonable for
mail1(_at_)cul-tura(_dot_)com(_dot_)ar to mail through 66.60.7.248
X-SPF-Guess: pass: seems reasonable for
mailing(_at_)partidodelacosta(_dot_)net to mail through 207.36.118.44
X-SPF-Guess: pass: seems reasonable for mar1y(_at_)resourcedns(_dot_)com to
mail through 205.138.96.49
X-SPF-Guess: pass: seems reasonable for mar1y(_at_)resourcedns(_dot_)com to
mail through 205.138.96.61
X-SPF-Guess: pass: seems reasonable for
mariam3(_at_)tiscali(_dot_)co(_dot_)uk to mail through 212.74.114.37
X-SPF-Guess: pass: seems reasonable for mary(_at_)resourcedns(_dot_)com to
mail through 205.138.96.49
X-SPF-Guess: pass: seems reasonable for megalott(_at_)fsmail(_dot_)net to
mail through 193.252.22.158
X-SPF-Guess: pass: seems reasonable for mengwong(_at_)camp4health(_dot_)com
to mail through 69.63.161.44
X-SPF-Guess: pass: seems reasonable for mepo(_at_)yehey(_dot_)com to mail
through 64.211.59.34
X-SPF-Guess: pass: seems reasonable for morineobaseki(_at_)juno(_dot_)com to
mail through 64.136.21.170
X-SPF-Guess: pass: seems reasonable for
mrs(_dot_)howard(_at_)tiscali(_dot_)co(_dot_)uk to mail through 212.74.114.40
X-SPF-Guess: pass: seems reasonable for
mrs_monica_kamara(_at_)katamail(_dot_)com to mail through 213.92.5.21
X-SPF-Guess: pass: seems reasonable for
mundodigital(_at_)infovia(_dot_)com(_dot_)ar to mail through 200.51.80.11
X-SPF-Guess: pass: seems reasonable for
mundodigital(_at_)infovia(_dot_)com(_dot_)ar to mail through 200.51.80.17
X-SPF-Guess: pass: seems reasonable for
n(_dot_)334(_dot_)2368327(_at_)sponsored-sites(_dot_)com to mail through
206.112.88.198
X-SPF-Guess: pass: seems reasonable for
n(_dot_)335(_dot_)2368327(_at_)sponsored-sites(_dot_)com to mail through
206.112.88.209
X-SPF-Guess: pass: seems reasonable for news(_at_)fun-www(_dot_)com to mail
through 213.33.70.236
X-SPF-Guess: pass: seems reasonable for news(_at_)k1-web(_dot_)com to mail
through 213.33.70.236
X-SPF-Guess: pass: seems reasonable for newsletter(_at_)uptilt(_dot_)com to
mail through 66.35.204.220
X-SPF-Guess: pass: seems reasonable for noreply(_at_)geocaching(_dot_)com to
mail through 63.251.163.165
X-SPF-Guess: pass: seems reasonable for
noreturn(_dot_)410192(_dot_)1843713(_dot_)3278309(_at_)returnull5(_dot_)mddailynews(_dot_)com
to mail through 64.88.148.100
X-SPF-Guess: pass: seems reasonable for
notify(_dot_)9GPK(_at_)geocaching(_dot_)com to mail through 63.251.163.165
X-SPF-Guess: pass: seems reasonable for oi6jqlvd(_at_)dsl-verizon(_dot_)net
to mail through 4.34.140.32
X-SPF-Guess: pass: seems reasonable for
okeisnc(_at_)ms4(_dot_)hinet(_dot_)net to mail through 168.95.4.166
X-SPF-Guess: pass: seems reasonable for
okservic(_at_)s5(_dot_)completel(_dot_)fr to mail through 213.244.0.27
X-SPF-Guess: pass: seems reasonable for
online(_at_)laserteam(_dot_)com(_dot_)ar to mail through 200.80.42.125
X-SPF-Guess: pass: seems reasonable for out(_at_)bfiesta02(_dot_)com to mail
through 69.6.43.105
X-SPF-Guess: pass: seems reasonable for
OWNER-NOLIST-DAILY*mengwong**POBOX*-COM(_at_)MAILDELIVERER(_dot_)COM to mail
through 209.216.99.120
X-SPF-Guess: pass: seems reasonable for
OWNER-NOLIST-DAILY*mengwong**POBOX*-COM(_at_)MAILDELIVERER(_dot_)COM to mail
through 209.216.99.121
X-SPF-Guess: pass: seems reasonable for
OWNER-NOLIST-DAILY*mengwong**POBOX*-COM(_at_)MAILDELIVERER(_dot_)COM to mail
through 209.216.99.122
X-SPF-Guess: pass: seems reasonable for
OWNER-NOLIST-DAILY*mengwong**POBOX*-COM(_at_)MAILDELIVERER(_dot_)COM to mail
through 209.216.99.124
X-SPF-Guess: pass: seems reasonable for PayrollServices(_at_)IJST5(_dot_)com
to mail through 66.63.165.68
X-SPF-Guess: pass: seems reasonable for
pedidodevinos(_at_)fibertel(_dot_)com(_dot_)ar to mail through 24.232.0.164
X-SPF-Guess: pass: seems reasonable for
perry(_at_)chil-nrp1-cs-496(_dot_)vdsl(_dot_)bright(_dot_)net to mail through
216.255.1.243
X-SPF-Guess: pass: seems reasonable for pymesformacion(_at_)terra(_dot_)es to
mail through 213.4.129.129
X-SPF-Guess: pass: seems reasonable for
rbb-23899-140793779-pobox(_dot_)com(_at_)cancun(_dot_)rbexpress(_dot_)org to
mail through 64.156.12.216
X-SPF-Guess: pass: seems reasonable for
rbb-24043-140793779-pobox(_dot_)com(_at_)cancun(_dot_)rbexpress(_dot_)org to
mail through 64.156.12.216
X-SPF-Guess: pass: seems reasonable for
rbb-24217-140793779-pobox(_dot_)com(_at_)cancun(_dot_)rbexpress(_dot_)org to
mail through 64.156.12.217
X-SPF-Guess: pass: seems reasonable for RCStuntCar(_at_)IJST5(_dot_)com to
mail through 66.63.165.67
X-SPF-Guess: pass: seems reasonable for rhbdhf217501(_at_)ejeju(_dot_)net to
mail through 211.184.197.194
X-SPF-Guess: pass: seems reasonable for
richters(_at_)twilightsorcery(_dot_)net to mail through 207.245.72.125
X-SPF-Guess: pass: seems reasonable for RiskManager(_at_)IJST5(_dot_)com to
mail through 66.63.165.29
X-SPF-Guess: pass: seems reasonable for Roxio(_at_)ehdhd(_dot_)com to mail
through 66.63.165.100
X-SPF-Guess: pass: seems reasonable for sbn-html2(_at_)spherex(_dot_)info to
mail through 199.227.214.126
X-SPF-Guess: pass: seems reasonable for server2.mail.cogentco.com to mail
through 66.28.3.16
X-SPF-Guess: pass: seems reasonable for sfg(_at_)insuranceiq(_dot_)info to
mail through 65.217.159.80
X-SPF-Guess: pass: seems reasonable for
sigris(_at_)fibertel(_dot_)com(_dot_)ar to mail through 24.232.0.164
X-SPF-Guess: pass: seems reasonable for SingleChristians(_at_)ehdhd(_dot_)com
to mail through 66.63.165.87
X-SPF-Guess: pass: seems reasonable for
solucionesouters(_at_)ciudad(_dot_)com(_dot_)ar to mail through 200.42.0.181
X-SPF-Guess: pass: seems reasonable for
sthydroderm3(_at_)permission-server(_dot_)com to mail through 69.6.58.148
X-SPF-Guess: pass: seems reasonable for StockAlert(_at_)ehdhd(_dot_)com to
mail through 66.63.165.72
X-SPF-Guess: pass: seems reasonable for StockAlert(_at_)ehdhd(_dot_)com to
mail through 66.63.165.80
X-SPF-Guess: pass: seems reasonable for StockAlert(_at_)IJST5(_dot_)com to
mail through 66.63.165.29
X-SPF-Guess: pass: seems reasonable for
support(_at_)oceanicspecials(_dot_)com to mail through 65.110.13.198
X-SPF-Guess: pass: seems reasonable for
support(_at_)oceanicspecials(_dot_)com to mail through 65.110.13.215
X-SPF-Guess: pass: seems reasonable for
sxxdszf-mengwong-pobox(_at_)fulhrctvycy(_dot_)hikespikenotice(_dot_)com to mail
through 65.208.146.140
X-SPF-Guess: pass: seems reasonable for synergy(_at_)insuranceiq(_dot_)info
to mail through 65.217.159.80
X-SPF-Guess: pass: seems reasonable for
temascaps(_at_)caps(_dot_)com(_dot_)ar to mail through 200.80.42.126
X-SPF-Guess: pass: seems reasonable for TheWinery(_at_)IJST5(_dot_)com to
mail through 66.63.165.50
X-SPF-Guess: pass: seems reasonable for
todocdsabm03(_at_)speedy(_dot_)com(_dot_)ar to mail through 200.51.197.72
X-SPF-Guess: pass: seems reasonable for
todocds_uk(_at_)speedy(_dot_)com(_dot_)ar to mail through 200.51.80.3
X-SPF-Guess: pass: seems reasonable for TravelFleaMarket(_at_)ehdhd(_dot_)com
to mail through 66.63.165.87
X-SPF-Guess: pass: seems reasonable for TravelFleaMarket(_at_)IJST5(_dot_)com
to mail through 66.63.165.37
X-SPF-Guess: pass: seems reasonable for TravelFleaMarket(_at_)IJST5(_dot_)com
to mail through 66.63.165.69
X-SPF-Guess: pass: seems reasonable for usafin(_at_)insuranceiq(_dot_)info to
mail through 65.217.159.80
X-SPF-Guess: pass: seems reasonable for
v-174183_90400533(_at_)bounce3(_dot_)rm04(_dot_)net to mail through 129.41.69.87
X-SPF-Guess: pass: seems reasonable for
v-175805_90400533(_at_)bounce3(_dot_)rm04(_dot_)net to mail through 129.41.69.87
X-SPF-Guess: pass: seems reasonable for
v-178260_90400533(_at_)bounce3(_dot_)rm04(_dot_)net to mail through 129.41.69.87
X-SPF-Guess: pass: seems reasonable for
valeria(_dot_)valdettaro(_at_)commtech(_dot_)com(_dot_)ar to mail through
200.69.243.68
X-SPF-Guess: pass: seems reasonable for
ventas1(_at_)damacomp(_dot_)com(_dot_)ar to mail through 200.69.24.12
X-SPF-Guess: pass: seems reasonable for
whadm(_at_)ls10(_dot_)snazzytrac(_dot_)com to mail through 64.94.51.160
X-SPF-Guess: pass: seems reasonable for
whadm(_at_)ls13(_dot_)snazzytrac(_dot_)com to mail through 64.94.51.163
X-SPF-Guess: pass: seems reasonable for willner(_at_)insuranceiq(_dot_)info
to mail through 65.217.159.80
X-SPF-Guess: pass: seems reasonable for
yinfo-t(_at_)realsweetoffers(_dot_)com to mail through 63.215.184.16
X-SPF-Guess: pass: seems reasonable for
yoursecretcrush(_at_)someonelikesyou(_dot_)com to mail through 65.60.35.114
X-SPF-Guess: pass: seems reasonable for
yoursecretcrush(_at_)someonelikesyou(_dot_)com to mail through 65.60.35.37
X-SPF-Guess: pass: seems reasonable for YvesRocher(_at_)ehdhd(_dot_)com to
mail through 66.63.165.72
X-SPF-Guess: pass: seems reasonable for YvesRocher(_at_)ehdhd(_dot_)com to
mail through 66.63.165.79
X-SPF-Guess: pass: seems reasonable for YvesRocher(_at_)IJST5(_dot_)com to
mail through 66.63.165.67
X-SPF-Guess: pass: seems reasonable for YvesRocher(_at_)IJST5(_dot_)com to
mail through 66.63.165.68
-------
Sender Permitted From: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
Latest draft at http://spf.pobox.com/draft-mengwong-spf-02.6.txt
To unsubscribe, change your address, or temporarily deactivate your
subscription,
please go to
http://v2.listbox.com/member/?listname(_at_)©#«Mo\¯HÝÜîU;±¤Ö¤Íµø?¡