spf-discuss
[Top] [All Lists]

Re: Re: SPF HELO checking

2004-12-14 10:01:52
Hi !!

The heart and soul of our anti-spam solution is 100^% based on applying a
STRICT SMTP compliancy.  I don't believe you can sole the abuse problem
without applying strict compliancy.

the problem is that rfc do not sufficiently enforce such this checks,
at least in a clear way.

In addition, there will be a few Bulk/Batch spammers who will ignore the
HELO rejection and just continue to try again, again, again, again, again
and again, etc, until the transaction is satisfy.  I just had this happen
last week, where our connection rates skyrocketed from an average of 9K to
12, 25, and 50K connections per day, all with the SAME moronic sender
failing with a domain literal check and just kept trying over and over
again.

you could reject at a later stage (mail from or rcpt to) so you also
discard clients using smtp auth.

--
Best regards ...

It's a fine line between fishing & standing still

----------------------------------------------------------------
   David Saez Padros                http://www.ols.es
   On-Line Services 2000 S.L.       e-mail  david(_at_)ols(_dot_)es
   Pintor Vayreda 1                 telf    +34 902 50 29 75
   08184 Palau-Solita i Plegamans   movil   +34 670 35 27 53
----------------------------------------------------------------



<Prev in Thread] Current Thread [Next in Thread>