spf-discuss
[Top] [All Lists]

[spf-discuss] Interesting usage observation

2006-06-06 13:59:40
We've been tracking the usage of our SPF records through the use of both
a blacklist zone as well as an 'exists' mechanism for the last six
months.  During that time, queries which "fall through" the MX and IP4
mechanisms have doubled from something on the order of 6k/day to around
12k/day.

We had published SPF records for the approximately 300 domains and
subdomains (with wildcards to cover all host-based addressing within
those domains) in early January (after some testing during the two
months prior using just a few domains).

Inspecting the queries shows that in March, spammers started using the
SPF-record-only domain for our "no mail sent from this domain" for their
garbage and usage has increased from zero to over 300 queries a day
now.  It's ironic that they would latch onto an SPF record to try an
exploit like this.

Cheers,
  Kurt

-- 
Kurt Andersen <kurta(_at_)agilent(_dot_)com>
Agilent Technologies Postmaster
Global Messaging Team, Agilent Technologies
+1 (509) 921-3792

-------
Sender Policy Framework: http://www.openspf.org/
Archives at http://archives.listbox.com/spf-discuss/current/
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname=spf-discuss(_at_)v2(_dot_)listbox(_dot_)com

<Prev in Thread] Current Thread [Next in Thread>