Sebby has left a new comment on the post "Barracuda Networks and their
customers could to do...":
Agreed, being a several-hundred-a-day backscatter victim is worse than
death. Apparently, I'm a Russian lady looking for love (probably not so
very far from the truth except that I'm not Russian and not a lady, so
if it weren't for the backscatter, CR notices, vacation notices and
everything else, maybe I should be thanking the spammer ;-) ). My
address seems to be continuously picked on for this purpose. So far
nobody has actually responded, which hopefully says something bad about
the campaign.

I'd look into BATV and see if you can use it. I can't because I don't
yet want to upgrade my Sendmail. Still, it depresses me how some people
just don't get SMTP enough to do something about unwanted crap
pre-accept phase.

Just one thing, though - isn't autoresponding to postmaster itself kind
of a bit evil? I mean, you do check you're sending valid mail to valid
recipients before you do it, don't you? Presumably, it's a template you
get your MUA to submit for you. I'd not go setting up completely
automated systems - you might one day classify a legitimate bounce as
spam, and that'd be bad, to be pissing off a real postmaster. And
besides, remember, it's falsely being accused we're complaining about,
not getting DSNs in the first place. DSNs are great in and of
themselves and tell us stuff we want to know (and, in fact, I even ask
for success DSNs when the remote MTA will do them in many instances
where I want interactive confirmation that now it's there problem for
my mail to be delivered).

While I think on here ... There are only two further problems needing a
solution: smarthosts and backup MXs. I'm a backup, my reasonable
compromise solution is a script which probes forward MXs. If they're
up, I'll tempfail mail; if they're down, I'll take it in for later. I
can't and don't maintain user lists at the primary because that'd be
inconvenient, so I only generate backscatter when the primaries are
actually down which they are very occasionally. Smarthosts are a
different problem: there is a conflict between port 25 blocking and a
picky smarthost. A smarthost should only accept mail from senders
inside the domain, yet a portblock on tCP 25 makes the ISP mail service
essentially unusable for anything serious. This means, I think, that
the only solution is to portblock by default and enforce strict
per-user sender lists, but then to allow port 25 on a customer request
basis. Then they can run their own MTA if they wish, assuming anybody
will listen to what they have to say, what with being a second-class
citizen because they're on a dynamic IP and all. I even get backscatter
from Hotmail because they'll actually let you forge as long as you're
authenticated to them! And then there's orange.fr - they don't even try
to validate - they tank absolutely everything, without fail.

Anyway, great post, and thanks for that. I shall point it out to others
who need any coroboration.

Cheers,

Sabahattin

[EMAIL PROTECTED]@P - NO REAL MAIL HERE, PLEASE: [EMAIL PROTECTED]

My homepage for real address

Post a comment:
https://www.blogger.com/comment.g?blogID=5181500149232975507&postID=6152967822888062567&ext-ref=comm-sub-email

Unsubscribe to comments for this post:
http://www.blogger.com/comment-unsubscribe.g?blogID=5181500149232975507&postID=6152967822888062567

Posted by Sebby to Victims of Email Backscatter at October 12, 2008
11:56 AM


-- 
[email protected] mailing list
Send administrative requests (subscribe, unsubscribe, change options) to:
[EMAIL PROTECTED]
(use "help" in the Subject line for a summary of common options)
You can also use the web interface at:
https://sabahattin-gucukoglu.com/cgi-bin/lsg2.cgi
For assistance, contact:
[EMAIL PROTECTED]

Reply via email to