Legitimate list-management systems allow users to change their email
address, but only after verification from the new email. So, from web site:
user requests change, email sent to new address with confirmation code/id,
new email replies through web or email - modification then takes place.
The biggest place for bulk email abuse is transferring old lists to a new
provider. The new provider needs to allow the old list of names to be
mass-uploaded. For this process to be invisible - one needs to trust the
upload as legitimately captured email addresses. Even sending new
confirmations to the uploaded list may result in x2 spam if the uploaded
list was spam to begin with.
To counter this, the uploaded list needs to be scanned first for "spam like
email". If they occur, upload of the list is prevented, the list is stored
temporarily, the list owner is flagged, the uploading individual is flagged,
and only after manual examination and conversation between the uploader and
list provider is the upload allowed (if approved).
And still it's not foolproof.
Stephen R. Cassady
http://www.tallylist.com
List Management, Archiving, and Analysis



<-- Message Reply To -->
Well that is the way that I subscribed to this list so maybe that is what I
saw, but as most mail clients allow users to change their from addresses to
anything they want - you can subscribe anybody via a mail client with very
little effort ( or make a program that could subscribe people in bulk
without their knowledge -- and without any validity check on the address).
I find this lack of security/privacy feature in the list server of this well
regarded mail server somewhat shocking. It must leave lists on its list
server open to abuse and spamming and must be a hole for DoS attacks on the
mail server.

Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Reply via email to