On 28 Oct 2017, at 4:12 (-0400), Benjamin BILLON via mailop wrote:

This basically makes JMRP irrelevant for ESPs: we don't
have reliable metrics,

You must know already that ESP "metrics" are laughable to begin with, right?

For example, I have multiple freemail accounts, some of which exist only to act as spamtraps. Nothing sent to those by so-called "legitimate" ESPs has ever generated any indication back to the spammer that it has been seen or read, since I never access email with a web browser or allow a MUA I'm using to act like a web browser.

You may believe that I'm just one cranky old sysadmin whose disdain for HTML mail is rare enough to ignore, and that may be true. However, I have been doing security policy and user safety training for a long time and have directly spread the religion of Don't Load Remote Content and Don't Click On Email Links to multiple corporate policies, many individuals, and at least one commercial MUA. Coming in second behind "that's how modern security attacks work" as a compelling evangelistic argument is "you're giving an ESP private information for free."

Bill Cole
b...@scconsult.com or billc...@apache.org
(AKA @grumpybozo and many *@billmail.scconsult.com addresses)
Currently Seeking Steady Work: https://linkedin.com/in/billcole

mailop mailing list

Reply via email to