Nice debate :) I agree with Melvin on blocking 25 for everything BUT the isp's mail server. With the premise that someone should still be able to set up their mail server, if they request it, maybe pay a tax. etc. At least they'll have their name on the record. Or if they don't want to block 25 they can limit the amount of emails/user to 20/50/100/ you name it per one hour or something, and allow bulk mailers for legitimate companies. I think there are ways if people bother to. How about even just implementing ASSP for outbound 25 port traffic, with just some invalid HELO rules. That would stop 50-60% or more of spam right away, without ANY false positives.
However I didn't mean "going after ISP's" in my previous posts, but just be forced to do the most basic security measures. For their own sake even. For example, in my country Romania many times they do nothing...alot of people send alot of spam, phishing e-mails and virii from their own computers registered at the ISP with their name, and they don't even close their accounts! Give them an e-mail, a phone call, nothing...that wouldn't be hard to do now would it? For instance, my ISP has an UCEPROTECT Level 3 ban for years, but they don't care at all. I doubt they're even aware :) - you can check that easily with my mail server, on this domain. Thank god not alot use uceprotect and I haven't had many problems with it. @Scott: Great story! Enjoyed it...at least they 'try' to enforce the laws there, here I have never heard of anyone getting any attention for spam -----Original Message----- From: Melvin [mailto:[email protected]] Sent: Thursday, June 18, 2009 3:11 AM To: Scott Haneda Cc: For Users of ASSP Subject: Re: [Assp-user] Dutch ban all spam e-mails Scott Haneda wrote: <big snip> > I am going to move one server to use ASSP, and with that, mandate port > 587, and not accept any port 25 authenticated users at all, I > personally am not looking forward to that day at all. I'm not talking about changing ports, I'm talking about what I see more commonly which is port 25 is blocked for all outbound traffic except to the ISP mail servers. Mail sent through those servers requires authentication before you can send mail. That usually means that what is required is that the user check the box that says 'my server requires authentication' and nothing more. Sometimes they have to tell the client app to use the same credentials as the inbound mail settings. Yes I realize that lots of folks would just look at it and say ????? but when Bellsouth did it a few years back they sent out a message to all the users with a link to their support page which had excellent step by step on how to do it for about 3 or 4 most common apps. How many calls did it generate? I'm sure it was several, but that's part of doing business at that scale in my opinion. ------------------------------------------------------------------------------ Crystal Reports - New Free Runtime and 30 Day Trial Check out the new simplified licensing option that enables unlimited royalty-free distribution of the report engine for externally facing server and web deployment. http://p.sf.net/sfu/businessobjects _______________________________________________ Assp-user mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/assp-user
