legitimate emails from AT&T and Verizon." The solution given to this query was "subscriber network filter"--blatantly counter to the requirements!
We don't block ATT or Verizon's or any or the network operators' MTAs, only their subscriber networks, and I stated that it solved the horrendous spam spew from att nets for us and under what conditions, (because some people, imagine this, are flexible enough to change their "conditions" if they "can't get there from here").
But it would be absurd for us to claim that there are "no false positives."
I claim "no false positives", without absurdity, because what you and Scott refuse to take on board is that declaring a spam spewing network illegitmate as an MX policy TERMINATES ALL TESTING for SPAM. With no testing, there can be no "false positives" in any sense of that phrase, period, putting it in Scotts beloved "statistical" terms.
It's an anti-spam measure. It makes mistakes as an anti-spam measure. And those mistakes are, unequivocally, false positives.
No, they aren't. Any legit mailer contacting my MX from a subscriber network is by my definition illegit.
Perhaps there should be an additional term in there--"designed FPs," "lost-lead FPs," "pimp hand FPs," or suchlike--but they are FPs.
The term exists, and is widely used: "collateral damage".
Collateral damage is not our primary or any objective, but its (political) repercussions are absolutely delightful:
1. legit users leaving the subscriber nets hurting the $$$ of the irresponsible network operator,
2. bitching to their network providers about being blocked through no fault of their own,
3. changing their PTR hostname OUT of the blocked PTR subdomain (and bitching/leaving if their network operator won't cooperate),
(this actually happened 2 days ago with a Canadian software company blocked by our /hsia.telus.com/ filter (High Speed Internet Access, with all business and other clients under the same PTR domain). When he saw how, and was shown why, we were blocking hsia, he got telus to give him his own PTR. As a result of our subscriber block, he has raised his credentials as a legit mailer. Applause all around. Collateral damage had positive outcome. Always wiling to work with whomever, I sent mail to [EMAIL PROTECTED] and [EMAIL PROTECTED], both rejected:
<[EMAIL PROTECTED]>: host mx01.telus.net[199.185.220.250] said: 550 relaying
mail to mytelus.com is not allowed (in reply to RCPT TO command)<[EMAIL PROTECTED]>: host mx01.telus.net[199.185.220.250] said: 550
relaying mail to mytelus.com is not allowed (in reply to RCPT TO command)4. relaying their outbound through non-subscriber nets,
5. the network operator policing/stopping the spew,
6. the network operator blocking egress from their networks to port 25 (so the block could be lifted),
7. the network operator segregating PTR domains between "residential" and "business" (eg, we don't block biz.rr.com),
etc, etc.
On the other hand, if you frame your anti-spam measure as *not* subordinate to legit message content, then it's *not* primarily an anti-spam measure.
Well, of course it is. It's the spam effluent from subscriber networks that leads us to declare the subscriber networks as illegitmate, primarily, exclusively as an anti-spam measure.
I think one should err on the side of those whose employment is on the line
Why the melodrama, FUD?, about anti-spam policies causing someone to lose their jobs?
and explain the perspective of any highly charged recommendation.
There's no "high charging" in the air, explanations have been clear and unequivocal, and willing to (re) answer seriously even baited, bad will, trash-talking questions repeatedly.
Len
_____________________________________________________________________ http://MenAndMice.com/DNS-training: San Jose; Wash DC; Dallas; Atlanta IMGate.MEIway.com: anti-spam gateway, effective on 1000's of sites, free
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
