spf-discuss
[Top] [All Lists]

Re: Co-operative 'bulk mail' alerting

2004-08-16 06:29:20
On Mon, 16 Aug 2004 12:40:59 +0100, Chris Haynes wrote
It occurs to me to form a 'club' of small-scale MTA operators. We 
find a way of collating current observed activity, so that we can 
jointly be warned that a host is spewing out large volumes of mail.

I don't plan any judgements about the messages, no spam vs. ham 
decisions, no long-term history.

Except for the "no judgements" part, this is essentially what SpamCop does. 
If you can find a way to implement it without the problems SpamCop has, it
might be a good idea.

The main problems I see with SpamCop are:
- It's easy to game the system and get arbitrary hosts blacklisted.  When this
happens, there's no accountability.  You just have to wait for the listing to
expire.
- Hosts that have a low volume of mail to SpamCop subscribers end up with a
lot of false positives, since any single piece of mail submitted as spam is
enough to push their ratio over into blacklist-land.