spf-discuss
[Top] [All Lists]

Re: Unified SPF Algorithm (was: moving on from MARID)

2004-10-01 02:11:43

Rejecting based upon RCPT TO alone is a significant logical hole it allows
automated address harvesters to poll an MTA with random addresses so that
it can build up a list of valid ones.

Do you have any evidence that this is taking place?

My impression is that such dictionary attacks for address harvesting may have been a tactic in the late 90's, but the volume of spam today seems to be running completely open loop, with spammers not bothering to check which names are delivered/rejected, not cleaning their databases, but just sending volumes blindly.

And, even if there is address harvesting taking place, since when is having the address of a valid recipient sufficient for delivery?

Len


_____________________________________________________________________
http://IMGate.MEIway.com : free anti-spam gateway, runs on 1000's of sites