For details of this crap, I reference my post a couple days ago of the long list of rejects from Scott's network provider, charter, whose subscriber nets are spam factories.
Len, could you please lay off the personal attacks?
Would you please thicken your skin? There was ono personal attack there.
To recap, you are saying "I don't mind blocking some legitimate E-mail, if I can block a lot of spam."
I think you are finally getting the picture.
Again, you're welcome to do this, if you don't mind false positives.
damn, you aren't getting the picture. Since we aren't "testing" for spam, but rather _intending_ to block 100% of subscriber-network-sourced email, there are no false positives.
And you're welcome to encourage others to do this
thank you
just so long as they know that they will be blocking legitimate E-mail
I apparently have much higher regard for the readers of this list than you.
and that there are alternatives.
see above
However, you can achieve much better results by using EASYNET-DYNA (which includes the attbi.com IPs, but excludes the ones used by known mailservers).
ok, I'm willing to run an experiment, started a couple of minutes ago, 19:30 US central time, at a high-volume ISP who runs the subscriber filter at the top of this restrictions.
From 00:00 to 19:30, his rejects are:
1 RBL spamdomains.blackholes.easynet.nl
2 SMTP invalid [EMAIL PROTECTED]
2 SMTP Exceeded Hard Error Limit after CONNECT
4 SMTP Exceeded Hard Error Limit after END-OF-MESSAGE
6 DNS no A/MX for @recipient.domain
8 ACL helo_hostnames
14 ACL header checks
25 ACL unauthorized relay
27 SMTP Exceeded Hard Error Limit after ETRN
29 SMTP Exceeded Hard Error Limit after HELO
30 SMTP helo hostname invalid
33 ACL mta_clients_bw
33 SMTP invalid [EMAIL PROTECTED]
48 ACL bogon network header
67 ETRN Mail theft attempt
70 ACL HTML obfuscation
89 RBL list.dsbl.org
101 SMTP unauthorized pipelining
117 ACL to_local_recipients unknown recipient
166 RBL proxies.relays.monkeys.com
171 RBL relays.ordb.org
226 RBL korea.services.net
257 DNS nxdomain for MTA PTR hostname (forged @sender.domain)
328 ACL PTR hostname does not match hostname (forged HELO)
372 SMTP Exceeded Hard Error Limit after MAIL
393 RBL dynablock.easynet.nl <<<<<<<<<<<<<<<<<<
479 DNS timeout for MTA PTR hostname (forged @sender.domain)
527 ACL forged @sender.domain not from sender PTR domain
578 RBL dnsbl.njabl.org
648 ACL from_senders_bw
938 DNS no A/MX for @sender.domain
1504 SMTP helo hostname is an IP
1802 ACL from_senders_imgfx
2007 SMTP helo hostname not fully qualified
2168 RBL sbl.spamhaus.org
3963 RBL blackholes.easynet.nl
10981 ACL from_senders_slet
13426 ACL mta_clients_dict
23380 SMTP Exceeded Hard Error Limit after DATA
73277 SMTP Exceeded Hard Error Limit after RCPT
114506 ACL to_relay_recipients unknown recipient
127015 ACL subscriber network <<<<<<<<<<<<379818 TOTAL rejects
I will move the :
reject_rbl_client dynablock.easynet.nl,
from well down the list (we don't prefer RBLs since they don't do much for us and they are "expensive") to just before:
check_client_access pcre:/etc/postfix/mta_clients_subscriber.regexp,
and let's see what it happens in the next 24 hours.
Whatever doesn't get blocked in dynablock.easynet.nl will get blocked by the subscriber filter, and I will report of the subscriber filter blocks.
And you can significantly reduce your false positives
But, we don't have any false positives with our subscriber filter.
Len
_____________________________________________________________________ http://MenAndMice.com/DNS-training: San Jose; Wash DC; Dallas; Atlanta IMGate.MEIway.com: anti-spam gateway, effective on 1000's of sites, free
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
