It was purposeful because I wanted to protect from false positives.  If there are enough of those, we could of course add tests or maybe even mark the domain in some cases.  It's helpful to also know their policy on outbound SMTP and mail server hosting if available.

I think that the following is a candidate for exclusion:

rrcs-nys-###-###-###-###.biz.rr.com
Now I just have to search my hits for .biz.rr.com and see how much spam comes from this domain....Answer: 4 of 1,053 messages tagged, each of which was spam, each of which was also marked as an open relay of some sort.  I'd say that it's a candidate, however I would hate to base a conclusion on just that.  At least we know that these should be business customers, and known open relays seem to get marked if you run enough blacklists tracking them.  Any two open relay-type tests and it won't pass my server (I've seen plenty of examples where people do not send spam from them and the other stuff works at scoring the rest of the points.

Matt



Joshua Levitsky wrote:


On Sep 17, 2003, at 7:31 PM, Todd Holt wrote:

1. Can this filter distinguish between ADSL and SDSL? If not, is this acceptable?
2. Is the filter doing this?
3. Are there any unique instructions for doing this

88.224.57.208.in-addr.arpa. 604800 IN PTR las-DSL224-cust088.mpowercom.net

In the case of your mail.xidix.com, you would not fail that test because they made your PTR have DSL224- rather than -224- where it would have failed. I don't know if this was on purpose in Matthew's filter or not.

I do see benefit in giving some points to a PTR like yours just like I throw points at CHINA or BRAZIL when I actually do get legit mail from Brazil, but I find my legit Brazil email doesn't get enough points to be blocked, and sometimes throwing some points at Brazil can help to catch spam that would not be otherwise. By the same token I would not block DSL like yours, but I would give a couple of points simply to make the other tests more sensitive because then it would take less for you to hit my threshold. I have plenty of mail that has 5 or 6 points and is perfectly legit, and that's fine as long as legit mail doesn't get 50 or 60 points.

-Josh



Reply via email to