Scott Haneda wrote: <big snip> > I am going to move one server to use ASSP, and with that, mandate port > 587, and not accept any port 25 authenticated users at all, I > personally am not looking forward to that day at all. I'm not talking about changing ports, I'm talking about what I see more commonly which is port 25 is blocked for all outbound traffic except to the ISP mail servers. Mail sent through those servers requires authentication before you can send mail. That usually means that what is required is that the user check the box that says 'my server requires authentication' and nothing more. Sometimes they have to tell the client app to use the same credentials as the inbound mail settings. Yes I realize that lots of folks would just look at it and say ????? but when Bellsouth did it a few years back they sent out a message to all the users with a link to their support page which had excellent step by step on how to do it for about 3 or 4 most common apps. How many calls did it generate? I'm sure it was several, but that's part of doing business at that scale in my opinion.
<more snippage> > Comcast is a strange beast. Almost everything that happens on their > network depends on where you are. For example, I used to be on their > 24. block, basically my entire town. When I was, port 25 was open, so > long as you were connected through their modem. I assume they do a > MAC id check of some form, and that is their "blind" authentication. > > I was then moved from 24. to 76., and that changed, I can not touch > port 25 at all. I bet a lot of this is carry over from the @home.com > merger as well. I'll agree with that for sure. :) We run into the same sort of thing at work doing things for all the major telecoms. Every office is still operating the same way they did when they were all little phone companies before they got swallowed back up or even back before when it was still Ma Bell and the little rural co-ops. The only problem with that is they're all doing it differently. Dozens, maybe even hundreds of independent databases with 99% the same basic information, but all with some different values for the same field. Hey, but it keeps us in business cleaning it up for them. :) <even more snippage> > Thats the other problem. "If they want to bother". I think that is > the core issues here to be honest. Were I in their shoes, port 25, > 587, or any port for that matter... If I saw more than x mails over it > in y time, I think some sort of event could happen. Maybe as evil as > a http redirect to a message telling them to call, who knows. Either > way, they have the ability to make all machines on their network > clean, they just have to chose to "want to bother". > > Probably email throttling is the best thing. Allow one email per x > seconds, more than that, drop the connection for y seconds. I think > this is perhaps the biggest mistake they could fix and not get many > support calls at all: > ( http://postmaster.comcast.net/ ) > > #9 Comcast allows 1000 recipients per message. > > That is just insane, it is as if they are inviting spammers in to > either CC or BCC a single message. I have a lot of crap head friends > who still think forwarding emails is cool, but to date, I have not > seen anyone break 50 addresses. I think 100 is more than than fair, > above that, prove you are trusted, and get more. > > Thanks for the reply and conversation. I'm not 100% sure because I've long since left for other providers, but I believe that Bellsouth at that time was capping at 100 addresses. And yes, you're right, the policies which make it easy for spammers are one of if not the major cause of most spam. But that all goes back to the 'follow the money' theory. If they shut down the spammers who would profit? Maybe we're approaching this from the wrong end of the chain. Instead of hunting down the spammers and doing unspeakable acts to them maybe we should be hunting down the idiots who actually respond and make it profitable. The stats for bulk snail mail used to say that if you got a 1-2% response you could make money. With email it's probably smaller, but I think with a concerted effort we could track them all down. Darwin says they shouldn't have survived anyway, so... Sorry, I didn't mean to ramble. :) later... ------------------------------------------------------------------------------ Crystal Reports - New Free Runtime and 30 Day Trial Check out the new simplified licensing option that enables unlimited royalty-free distribution of the report engine for externally facing server and web deployment. http://p.sf.net/sfu/businessobjects _______________________________________________ Assp-user mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/assp-user
