spf-discuss
[Top] [All Lists]

RE: Is anyone else getting DoS'd by relay attacks?

2005-01-10 13:13:34
I have been getting buried under backscatter since about Dec 1st myself. These messages come from non SPF aware mailservers by definition and are readily identifiable by the fact that they are being bounced to blatantly fake nonexistent usernames on my domain. My mailserver originally rejected those with the default comment but I have changed it to specifically pick out that backscatter (about 99.9% of the traffic arriving at my server alas) and reject it with:

550 Recipient address rejected: Recipient unknown. Please consider implementing SPF (http://spf.pobox.com) to avoid bouncing mail to spoofed senders. Thank you.

The way I see it, why shouldn't the spammers advertise SPF for us thousands of times a day? With any luck some small percentage of mailserver admins will look at their logs, notice one of the messages, and say "SPF, what's that?" and look into it. I imagine it'd make a much bigger impression if someday they saw not just a couple rejects imporing them to use SPF, but dozens from many different other mailservers.

I'm in the middle of typing up some instructions on how to configure a mailserver like mine (Postfix using recipient map checking) to do this, and was going to submit it to be placed on spf.pobox.com so others can benefit. I'd like to include information on doing it on as many different setups as possible so if anybody else with a different system has done the same thing or figures out how to do it, let me know. Thanks!

--Kaas

<Prev in Thread] Current Thread [Next in Thread>