Sebby has left a new comment on the post "Barracuda Networks and their customers could to do...": Agreed, being a several-hundred-a-day backscatter victim is worse than death. Apparently, I'm a Russian lady looking for love (probably not so very far from the truth except that I'm not Russian and not a lady, so if it weren't for the backscatter, CR notices, vacation notices and everything else, maybe I should be thanking the spammer ;-) ). My address seems to be continuously picked on for this purpose. So far nobody has actually responded, which hopefully says something bad about the campaign.
I'd look into BATV and see if you can use it. I can't because I don't yet want to upgrade my Sendmail. Still, it depresses me how some people just don't get SMTP enough to do something about unwanted crap pre-accept phase. Just one thing, though - isn't autoresponding to postmaster itself kind of a bit evil? I mean, you do check you're sending valid mail to valid recipients before you do it, don't you? Presumably, it's a template you get your MUA to submit for you. I'd not go setting up completely automated systems - you might one day classify a legitimate bounce as spam, and that'd be bad, to be pissing off a real postmaster. And besides, remember, it's falsely being accused we're complaining about, not getting DSNs in the first place. DSNs are great in and of themselves and tell us stuff we want to know (and, in fact, I even ask for success DSNs when the remote MTA will do them in many instances where I want interactive confirmation that now it's there problem for my mail to be delivered). While I think on here ... There are only two further problems needing a solution: smarthosts and backup MXs. I'm a backup, my reasonable compromise solution is a script which probes forward MXs. If they're up, I'll tempfail mail; if they're down, I'll take it in for later. I can't and don't maintain user lists at the primary because that'd be inconvenient, so I only generate backscatter when the primaries are actually down which they are very occasionally. Smarthosts are a different problem: there is a conflict between port 25 blocking and a picky smarthost. A smarthost should only accept mail from senders inside the domain, yet a portblock on tCP 25 makes the ISP mail service essentially unusable for anything serious. This means, I think, that the only solution is to portblock by default and enforce strict per-user sender lists, but then to allow port 25 on a customer request basis. Then they can run their own MTA if they wish, assuming anybody will listen to what they have to say, what with being a second-class citizen because they're on a dynamic IP and all. I even get backscatter from Hotmail because they'll actually let you forge as long as you're authenticated to them! And then there's orange.fr - they don't even try to validate - they tank absolutely everything, without fail. Anyway, great post, and thanks for that. I shall point it out to others who need any coroboration. Cheers, Sabahattin [EMAIL PROTECTED]@P - NO REAL MAIL HERE, PLEASE: [EMAIL PROTECTED] My homepage for real address Post a comment: https://www.blogger.com/comment.g?blogID=5181500149232975507&postID=6152967822888062567&ext-ref=comm-sub-email Unsubscribe to comments for this post: http://www.blogger.com/comment-unsubscribe.g?blogID=5181500149232975507&postID=6152967822888062567 Posted by Sebby to Victims of Email Backscatter at October 12, 2008 11:56 AM -- [email protected] mailing list Send administrative requests (subscribe, unsubscribe, change options) to: [EMAIL PROTECTED] (use "help" in the Subject line for a summary of common options) You can also use the web interface at: https://sabahattin-gucukoglu.com/cgi-bin/lsg2.cgi For assistance, contact: [EMAIL PROTECTED]
