For details of this crap, I reference my post a couple days ago of the long list of rejects from Scott's network provider, charter, whose subscriber nets are spam factories.

Len, could you please lay off the personal attacks?

Would you please thicken your skin? There was ono personal attack there.


To recap, you are saying "I don't mind blocking some legitimate E-mail, if I can block a lot of spam."

I think you are finally getting the picture.


Again, you're welcome to do this, if you don't mind false positives.

damn, you aren't getting the picture. Since we aren't "testing" for spam, but rather _intending_ to block 100% of subscriber-network-sourced email, there are no false positives.


And you're welcome to encourage others to do this

thank you


just so long as they know that they will be blocking legitimate E-mail

I apparently have much higher regard for the readers of this list than you.


and that there are alternatives.

see above


However, you can achieve much better results by using EASYNET-DYNA (which includes the attbi.com IPs, but excludes the ones used by known mailservers).

ok, I'm willing to run an experiment, started a couple of minutes ago, 19:30 US central time, at a high-volume ISP who runs the subscriber filter at the top of this restrictions.


From 00:00 to 19:30, his rejects are:

      1 RBL spamdomains.blackholes.easynet.nl
      2 SMTP invalid [EMAIL PROTECTED]
      2 SMTP Exceeded Hard Error Limit after CONNECT
      4 SMTP Exceeded Hard Error Limit after END-OF-MESSAGE
      6 DNS no A/MX for @recipient.domain
      8 ACL helo_hostnames
     14 ACL header checks
     25 ACL unauthorized relay
     27 SMTP Exceeded Hard Error Limit after ETRN
     29 SMTP Exceeded Hard Error Limit after HELO
     30 SMTP helo hostname invalid
     33 ACL mta_clients_bw
     33 SMTP invalid [EMAIL PROTECTED]
     48 ACL bogon network header
     67 ETRN Mail theft attempt
     70 ACL HTML obfuscation
     89 RBL list.dsbl.org
    101 SMTP unauthorized pipelining
    117 ACL to_local_recipients unknown recipient
    166 RBL proxies.relays.monkeys.com
    171 RBL relays.ordb.org
    226 RBL korea.services.net
    257 DNS nxdomain for MTA PTR hostname (forged @sender.domain)
    328 ACL PTR hostname does not match hostname (forged HELO)
    372 SMTP Exceeded Hard Error Limit after MAIL
    393 RBL dynablock.easynet.nl  <<<<<<<<<<<<<<<<<<
    479 DNS timeout for MTA PTR hostname (forged @sender.domain)
    527 ACL forged @sender.domain not from sender PTR domain
    578 RBL dnsbl.njabl.org
    648 ACL from_senders_bw
    938 DNS no A/MX for @sender.domain
   1504 SMTP helo hostname is an IP
   1802 ACL from_senders_imgfx
   2007 SMTP helo hostname not fully qualified
   2168 RBL sbl.spamhaus.org
   3963 RBL blackholes.easynet.nl
  10981 ACL from_senders_slet
  13426 ACL mta_clients_dict
  23380 SMTP Exceeded Hard Error Limit after DATA
  73277 SMTP Exceeded Hard Error Limit after RCPT
 114506 ACL to_relay_recipients unknown recipient
 127015 ACL subscriber network   <<<<<<<<<<<<

379818 TOTAL rejects

I will move the :

reject_rbl_client dynablock.easynet.nl,

from well down the list (we don't prefer RBLs since they don't do much for us and they are "expensive") to just before:

check_client_access pcre:/etc/postfix/mta_clients_subscriber.regexp,

and let's see what it happens in the next 24 hours.

Whatever doesn't get blocked in dynablock.easynet.nl will get blocked by the subscriber filter, and I will report of the subscriber filter blocks.

And you can significantly reduce your false positives

But, we don't have any false positives with our subscriber filter.


Len



_____________________________________________________________________
http://MenAndMice.com/DNS-training: San Jose; Wash DC; Dallas; Atlanta
IMGate.MEIway.com: anti-spam gateway, effective on 1000's of sites, free


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to