[imp] hardening imp against spammers

Jon Lewis jlewis at lewis.org
Wed Jun 29 20:32:41 PDT 2005


On Wed, 29 Jun 2005, Michael M Slusarz wrote:

> DNSBL is a *very bad thing*.  See
> http://www.acme.com/mail_filtering/shame_frameset.html for a good
> description of the issues.

Overgeneralized and throwing out the baby with the bathwater.  I know the
people who run the DNSBLs I plan to use.  I'm not at all worried about
them becoming power hungry weenies.

> Personal example: user sets up a machine on a home-based network that
> is on a business broadbank link (i.e. small business operator from
> home).  The business broadband provider also happens to provide home
> broadband support also.  Complete idiot DNSBL maintainers blacklist the
> user's address because a few (most definitely not all or even some)
> users on the home broadband have either infected computers or are doing
> bad things.  Therefore, because DNSBL maintainers are lazy or
> uneducated or both, instead of marking the individual addresses as bad
> they instead mark the entire block of addresses registered to the
> broadband provider as "bad" (We are talking entire Class C blocks
> here).

I think there's alot you don't understand about DNSBLs.

> Quite honestly, it is a subtle form of discrimination in that DNSBL
> maintainers can, by their actions, make certain broadband providers
> less desirable due to the fact that their network connection is now
> "tainted".

If you live in an IP ghetto, complain to your landlord or move.  Don't
blame the DNSBLs for calling a spade a spade.

Besides, the DNSBL data I'm using for IMP blocking is almost entirely
machine generated (not some lazy DNSBL operator) via spamtraps and actual
open proxy testing in response to received mail.

Now, sure, it would be really foolish to use any DUL sort of DNSBL for
blocking access to IMP, but that's not the DNSBL's fault...it's just a
foolish application of the data.

----------------------------------------------------------------------
 Jon Lewis                   |  I route
 Senior Network Engineer     |  therefore you are
 Atlantic Net                |
_________ http://www.lewis.org/~jlewis/pgp for PGP public key_________


More information about the imp mailing list