There was a big cry recently when Cox cable blocked customer access to all SMTP servers except their own. Do they show up in the abuse profile?
For Friday, connects from cox IPs:
4 wsip-24-120-32-56.lv.lv.cox.net[24.120.32.56] 1 wsip-24-234-119-166.lv.lv.cox.net[24.234.119.166] 4 lakemtao04.cox.net[68.1.17.241] 2 lakemtao03.cox.net[68.1.17.242] 4 lakemtao02.cox.net[68.1.17.243] 9 lakemtao01.cox.net[68.1.17.244] 1 ip68-102-116-160.ks.ok.cox.net[68.102.116.160] 1 ip68-102-155-241.ks.ok.cox.net[68.102.155.241] 2 ip68-102-90-127.ks.ok.cox.net[68.102.90.127] 1 ip68-11-136-112.br.no.cox.net[68.11.136.112] 1 wsip-68-110-134-19.lu.dl.cox.net[68.110.134.19] 1 wsip-68-15-222-135.at.at.cox.net[68.15.222.135] 2 wsip-68-15-27-237.sd.sd.cox.net[68.15.27.237] 1 wsip-68-15-49-243.ri.ri.cox.net[68.15.49.243] 1 fed1mtao08.cox.net[68.6.19.123] 2 fed1mtao07.cox.net[68.6.19.124] 1 fed1mtao06.cox.net[68.6.19.125] 1 fed1mtao05.cox.net[68.6.19.126] 1 fed1mtao04.cox.net[68.6.19.241] 2 fed1mtao02.cox.net[68.6.19.243] 1 fed1mtao01.cox.net[68.6.19.244] 2 wsip-68-99-60-100.pn.at.cox.net[68.99.60.100]
Not too bad at all. The one with "mta" are their outbound machines, so we don't block them in the subcriber filter.
Earthlink seems to have port 25 bock that is more effective, "mail" being their MTAs:
4 collamer.mail.atl.earthlink.net[199.174.114.9]
6 grouse.mail.pas.earthlink.net[207.217.120.116]
14 harrier.mail.pas.earthlink.net[207.217.120.12]
1 albatross.mail.pas.earthlink.net[207.217.120.120]
8 pintail.mail.pas.earthlink.net[207.217.120.122]
3 swan.mail.pas.earthlink.net[207.217.120.123]
6 turkey.mail.pas.earthlink.net[207.217.120.126]
8 goose.mail.pas.earthlink.net[207.217.120.18]
5 capitol.mail.pas.earthlink.net[207.217.120.180]
4 epic.mail.pas.earthlink.net[207.217.120.181]
4 sire.mail.pas.earthlink.net[207.217.120.182]
3 stork.mail.pas.earthlink.net[207.217.120.188]
5 heron.mail.pas.earthlink.net[207.217.120.189]
5 hawk.mail.pas.earthlink.net[207.217.120.22]
2 flamingo.mail.pas.earthlink.net[207.217.120.232]
1 mallard.mail.pas.earthlink.net[207.217.120.48]
2 scaup.mail.pas.earthlink.net[207.217.120.49]
10 avocet.mail.pas.earthlink.net[207.217.120.50]
9 conure.mail.pas.earthlink.net[207.217.120.54]
11 snipe.mail.pas.earthlink.net[207.217.120.62]
1 falcon.mail.pas.earthlink.net[207.217.120.74]
3 gull.mail.pas.earthlink.net[207.217.120.84]
2 firecrest.mail.pas.earthlink.net[207.217.121.247]
1 fowl.mail.pas.earthlink.net[207.217.121.50]
1 blackbird.mail.pas.earthlink.net[207.217.121.90]
2 fallback02.mail.atl.earthlink.net[207.69.200.241]
1 hsa083.pool042.at101.earthlink.net[216.249.111.83] <<<<<<<< ooopsThat step may be the only solution for the big providers.
The problem is so bad nearly all of them that they are not doing any policiing
Korea is way ahead of the US in deploying broadband to residential subscribers. This may have been what caused the Korean spam blizzard of 1-2 years ago. I see almost nothing by comparison; they seem to have gotten the problem under control.
I read that .kr blocking was hurting legit businesses so the businesses got the spamming acted upon. I hear China is doing the same. Collateral damage works.
Len
_____________________________________________________________________ http://MenAndMice.com/DNS-training: San Jose; Wash DC; Dallas; Atlanta IMGate.MEIway.com: anti-spam gateway, effective on 1000's of sites, free
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
