Oh come on Matt: This is too much fun... I am keeping score - so far:
Scott - on the right corner: 5 Len- on the left corner: 4 Sandy- on the sidelines: 1 I suggest we start Round III. Regards, Kami -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Matthew Lohr Sent: Wednesday, September 17, 2003 8:30 AM To: [EMAIL PROTECTED] Subject: RE: Re[2]: [IMail Forum] Certain ISP's failure/IMail Everybody is a liar and I am too so I will not add anything new. Len is happy blocking all mail from networks that don't have their act together no matter what the purpose of each individual email is. Scott would rather look at each message and try to determine whether or not that email has a legitimate reason for being there. They are two totally different policies that may not ever come together. I think we could have peace in the Middle East before this issue gets straightened out. So can we talk about other more easy going topics like religion and politics. -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Len Conrad Sent: Wednesday, September 17, 2003 1:33 AM To: [EMAIL PROTECTED] Subject: RE: Re[2]: [IMail Forum] Certain ISP's failure/IMail >It absolutely amazes me that folks can get away with blocking legitmate mail. Who's blocking legitimate mail? I say "block subscriber networks", and Scott's FUD goes "this _can_ have very, very high FPs". Until he can prove that blocking subscriber networks really does have the nebulous "very, very high" FPs, it's FUD. Put up or shut up. What's an acceptable FP rate? Obviously varies from ISP to ISP to corps. The charter example I quoted was about 1500 rejects, and Scott says "maybe" 1 or 2 or 3 legit recognized in there. My recommendation gets trashed as lying and misleading for that FP rate? GMAFB >even one legitimate email from a client I get ripped a new one. Maybe I've >spoiled my clients with virus protection, and they want spam filtering to >be just as accurate. So you are claiming 100% accuracy? FP rate of 0% and all spam is blocked? What are your typical numbers for total rejects and total legit per day? Applying subscriber blocking can done intelligently, although one wouldn't believe it from Scott's hammering. >be able to compare what other people are doing to what I am doing. Nearly >every day I learn something on this list that I can do to make my service >better, and that is fantastic. Sure, I make recommendation, and it's basically "Scott Bait". I don't go trashing and nannying Scott's posts (and I sure don't agree with all of them), but WTF is he doing nannying my posts? I'm lying, misleading, hiding info, tricking people, WTF is all that about?? >If we can't agree that it is a False Positve, let's come up with a new >term. Len, how about we call these messages "Unreceived legitimate email". >Does that make it easier somehow? whatever. >For me, the bottom line is that you can't talk to me about spam filtering >without talking about "Unreceived legitimate email". Correct. And due to the nature of business, it's extremely hard to be 100% accurate. And nobody wants to block legit mail, and will rapidly whitelist any complainers. >I wish I was in a position to be more aggressive, but for my company it >would be bad business. If other businesses can do it, that is great for >them. Exactly. If you think my recommendation of blocking subscriber networks wouldn't work for you, don't do it. And above all, don't let me trick, hide, or otherwise mislead you into doing it, your poor stupid Imail list member. :)) The subscriber block is a little special though, due to who is known to responsible for those networks. See my response to Sandy about the "repercussions" of collateral damage, as tiny as it is (but the more MXs that block subscribers, the better). Do ISPs who get into RBL servers go nutz until they get out? Then why do we let big, fat, known US/Canada networks operations get away with spewing us with abuse?? If everybody started blocking subscriber networks, then the network operators would go nutz to stop the abuse from their nets and to stop the blanket blocking. Actually, widespread blocking of subscriber networks would generate almost no complaints to the networks operators, since there are almost no legit senders on subscriber networks to do the complaining. And the revenue from these legit senders is far outweighed by the revenue from the mass of spammers. The subscriber network operators should absolutely not be NOT policing their nets. They absolutely should NOT be putting dynamic/residential PTR hostnames in domains indistinguishable from their business clients. They should NOT be unwilling/able to NEITHER delegate reverse subnets to clients' DNSs NOR give them the client's PTR hostname in their network DNSs. But they aren't, and the results are horrendous. Is it doable? YES! All "collateral damage outcomes" I listed are highly desirable and do-able, and are being done by other networks operators. Trying to fight spam from spam factories and overseas sources, mailer worms, open proxies, and who knows what/where else, is hard enough, but we should NOT have to accept/live with the horrendous spam spew from US/Canada subscriber networks. btw, my experiment has been running about 4.5 hours now. Here are the results between 19:30 and about 23:50, with dynablock running first, and subscriber filter running next: # cat /var/tmp/dynasub.txt | spam-stats.pl - 17603 RBL dynablock.easynet.nl 15980 ACL subscriber network ============================== 33583 TOTAL So dynablock is letting pass nearly 16k msgs that are blocked by the subscriber filter. Is Scott going to say that all 16k are legit since dynablock didn't block them?? Dynablock sucks as a replacement for my subscriber filter. Again, total rejects, all categories, all day, are: 2 SMTP invalid [EMAIL PROTECTED] 2 SMTP Exceeded Hard Error Limit after CONNECT 3 RBL spamdomains.blackholes.easynet.nl 5 SMTP Exceeded Hard Error Limit after END-OF-MESSAGE 6 DNS no A/MX for @recipient.domain 10 ACL helo_hostnames 16 ACL header checks 32 SMTP Exceeded Hard Error Limit after HELO 36 SMTP helo hostname invalid 37 SMTP Exceeded Hard Error Limit after ETRN 40 SMTP invalid [EMAIL PROTECTED] 42 ACL mta_clients_bw 44 ACL unauthorized relay 54 ACL bogon network header 77 ACL HTML obfuscation 91 ETRN Mail theft attempt 111 SMTP unauthorized pipelining 117 ACL to_local_recipients unknown recipient 138 RBL list.dsbl.org 197 RBL relays.ordb.org 272 RBL korea.services.net 291 DNS nxdomain for MTA PTR hostname (forged @sender.domain) 315 RBL proxies.relays.monkeys.com 410 SMTP Exceeded Hard Error Limit after MAIL 507 ACL PTR hostname does not match hostname (forged HELO) 522 DNS timeout for MTA PTR hostname (forged @sender.domain) 690 RBL dnsbl.njabl.org 766 ACL forged @sender.domain not from sender PTR domain 800 ACL from_senders_bw 1086 DNS no A/MX for @sender.domain 1889 SMTP helo hostname is an IP 2210 ACL from_senders_imgfx 2492 SMTP helo hostname not fully qualified 2803 RBL sbl.spamhaus.org 5495 RBL blackholes.easynet.nl 13929 ACL from_senders_slet 17318 ACL mta_clients_dict 18485 RBL dynablock.easynet.nl <<<<<<<<<<<<<<<<< about 18k in my experiment 27029 SMTP Exceeded Hard Error Limit after DATA 89192 SMTP Exceeded Hard Error Limit after RCPT 137179 ACL to_relay_recipients unknown recipient 139129 ACL subscriber network <<<<<<<<<<<<<<<<<<<< ============================== 463869 TOTAL and just to provide another sanity check and reference and POV, the entire populations of the following ISPs are sending these totals of accepted msgs (not blocked by all our filters) in the same period: # egrep -ic "nqmgr.*aol\.com" /postfix/log/maillog 752 # egrep -ic "nqmgr.*yahoo\.com" /postfix/log/maillog 2356 (....typically lots of yahoo groups list traffic exploding the number compared to the other 3 ISPs) # egrep -ic "nqmgr.*hotmail\.com" /postfix/log/maillog 494 # egrep -ic "nqmgr.*msn\.com" /postfix/log/maillog 214 Now, let's say that's the 136K rejects of subscribers nets has a 1% rate for blocking legit mail. That's, hypothetically, 1390 legit msgs blocked as being from illegitmate networks. Does the entire population of legit senders on subscriber nets ( how many businesses are on DSL AND running mailservers? 10K? 20K?) manage to send as much legit mail, 1390, to this MX as the combined populations of AOL + MSN + Hotmail (150+ million users?). I think not at all. So if we scale our legit mail from subscribers to the total of legit mail from the big 4, you can see that the legit msgs blocked by subscriber filter is probably well under 500, out of 139K. Can anybody live with a filter that has legit-blocked rate of 0.5%, or less? A kicker is the additional behavior, counted separately from the rejects, in these lines: 27029 SMTP Exceeded Hard Error Limit after DATA 89192 SMTP Exceeded Hard Error Limit after RCPT These lines are not rejects, but disconnects, discos, by our MX after the MX has sent 2 5xx rejects, and then got a command, probably RCPT TO, that caused a 3rd 5xx, click, we hang up. 125K times did we do that. In there, I'm sure there are 50k to 75k discos against subscriber IPs who are hitting us with multiple RCPT TOs, which is HIGHLY improbable behavior by legit senders, 98% of whom send 1 RCPT TO per SMTP session. ie, discos are additional convicting behavior against subscriber nets. As an implementation approach, you can pre-empt blocking of legit mail from subscriber networks by running the subscriber filter in warn_if_reject mode for a week, identify the tiny handful of habitual legit senders, whitelist their IPs, and then promote "warn_if_reject" to "reject". Wham, the reject rate of legit senders in subscriber networks tumbles into total insignificance. Len _____________________________________________________________________ http://MenAndMice.com/DNS-training: San Jose; Wash DC; Dallas; Atlanta IMGate.MEIway.com: anti-spam gateway, effective on 1000's of sites, free To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
