spf-discuss
[Top] [All Lists]

Re: [spf-discuss] Backscatter auto-complaints

2006-03-01 07:21:31
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Chris Drake wrote:
I turned on a catch-all recently, and measured about 1gig of
backscatter junk (bounces coming in to me from emails (spam) that I
did not send) arriving per day.

Would it be out-of-order to script a robot to parse all this, then
automatically send daily digest complaints to the networks involved,
telling them to (A) switch SPF on so they don't accept forged mail in
the first place, and (B) asking them not to accept mail to invalid
recipients, so they don't then have to originate bounces anyhow?

I think Stuart D. Gathman (participant in this list) has done something 
similar once.  IIRC, he sent DSNs to notify forgery victims (i.e. domain 
owners who were joe-jobbed).[1]

This kind of bulk notifying was somewhat controversial, but I think sending 
notifications with moderate frequency (one per recipient in every two days 
or so) is legitimate as long as it is guaranteed that the alleged sender 
address, i.e. the recipient of the notification, is correct and that the 
notification is materially warranted.

References:
 1. http://www.gossamer-threads.com/lists/spf/discuss/17867
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)

iD8DBQFEBa3JwL7PKlBZWjsRAkNhAJ9iT5BkTW0KEuxhdHskBUV3MEkGxgCg+Fc+
fw0Xxc6p7GiXJn/KO0ObzAE=
=6K4I
-----END PGP SIGNATURE-----

-------
Sender Policy Framework: http://www.openspf.org/
Archives at http://archives.listbox.com/spf-discuss/current/
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname=spf-discuss(_at_)v2(_dot_)listbox(_dot_)com

<Prev in Thread] Current Thread [Next in Thread>
  • Re: [spf-discuss] Backscatter auto-complaints, Julian Mehnle <=