Sorry, Len, but I'm going to keep correcting you. ... "Content-scanning" isn't at issue here (unless you choose for it to be).
I'm recommending blocking subscriber networks, which has nothing to with content-scanning.
You said "I know the content-scanning people are religiously convinced this is a fatal flaw, doomed to fail, incapable of succeeding..."
Accepting the DATA command, and reading/scanning/analyzing it for il/legitimacy (eg, FP) IS content-scanning.
Content scanning is scanning the contents of an E-mail (such as phrase filtering, naive Bayes analysis, etc.). By rejecting an E-mail, you can't do content scanning. By accepting an E-mail, you can choose whether or not to do content scanning. The problem is that you are implying that by accepting an E-mail, you *must* do content scanning. Note that our software does not do content scanning by default.
Other mail admins choose to keep the crap out of their networks, rejecting before the DATA command, and handle complaints case by case. They are not fixated on false positives.
That's because you preach to those admins that there is no need to worry about false positives.
I never preach that or that to anybody.
Come on, Len, do you really want me to go through the archives of this list? You've said it many, many times.
You show phony data (like the post that started this thread) that makes it look like your ACL test has 0 false positives
I posted the FROM and HELO data (and the qty of unknown user rejects) for Charer PTRs so people could judge for themselves. That log data was not my "opinion" and was in no way bogus.
You made it very clear that your opinion was that every one of those E-mails was spam.
Can I ask you why you bothered posting all that data
To show the volume and kind of crap that comes from subscriber networks, and why declaring them illegitimate is a reasonable and effective policy.
But, the data you posted assumes that you've already blocked legitimate E-mail for months, and that those people are either no longer doing business with you or have taken the effort to re-route their E-mail to you. Going back to my example of the city hiring you to determine if the water in the 100 local lakes is safe, it's like you cleaning the 10 lakes that you sample before you sample them, and saying "Ah, they ARE clean!". Without saying that you cleaned the lakes, everyone will think that the lakes are all clean -- even though the other 90 are dirty.
Or, put another way, it's like me saying that our customers blocked 10 million spams yesterday. That sounds like a cool stat (and makes for neat marketing information), but without other information, it is meaningless.
Blocking subscriber networks is not in any way a radical or innovative policy, as it has been, and is, the continuing practice of many mail admins to define ACLs that block entire country's TLDs, or Class A's (eg, apnic), 100s of Class Cs, or PTR domains (eg, flowgo) or 100's of @sender.domains (eg, the list compiled at imgfx by Declude users, or spamdomains at easynet.nl ) for exactly the same reason: it's effective and reliable based on the crap and behavior originating from those sources.
And can have a very, very high FP ratio if each and every admin doesn't do research first. Most admins don't want to bother doing research.
How about changing your approach, and specifying in your statistical posts things like "By false positive, I mean any E-mail that this test was not designed to catch but it did catch", "Impossible means that my interpretation of the data suggests that it is very unlikely", "Warning: You should not block E-mail based on my ACL test without first testing to see if it will well for you."
rather than just saying "I choose to consider any E-mail that fails my ACL test as illegitimate
In the case of subscriber networks, I said EXACTLY that.
therefore my ACL test has no false positives."
I said EXACTLY that.
Yes, you said that after I prompted you to. Your original post, though, was very misleading. In order for people to get the good pieces of information out of your original E-mail, they will have to wade through this whole thread. Next time, I would urge you to put all the relevant facts in your original post. That will make it much better for the readers of your post (saving them time and/or problems), it will save me time (in correcting you), and save you time (in responding to me). And, it has the added benefit of reducing bandwidth, reducing the number of posts on this list, etc.
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask about our free 30-day evaluation.
--- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
