>...
>List Mail User wrote:
>>      tuxorama.com does a SMTP probe for every posting to this list
>> and is one of the very few IPs I have firewalled off.  The probes seem
>> to always come from 81.169.185.26 (now they'll probably change IPs and I'll
>> have to block some other IP or range), so they, while irritating are very
>> easy to block.  Asking them to stop seems to result in them stopping for
>> a week or so, then beginning again.  They likely have one or more users
>> who subscribe to this list.
>
>It's almost certainly someone who uses milter-sender. milter-sender does this
>dummy check before accepting mail. It's taking the "verify MX record of 
>envelope
>sender" one step further and verifying the whole address.
>
>I personally find them rather inoffensive, but then again, I don't find many
>things offensive that some of the right-wing admins go ballistic over.
>
        Actually if they verified the address by a transaction without a
data phase, I'd find them less annoying.  The real problem is they show
up in my reports generated to find "SMTP hunters".  All they do is connect,
then drop the connection (no "quit", no clean close), so I doubt it is any
relatively standard software - probably something homegrown.  If it weren't
for them matching the "hunter" behavior, I'd just ignore them;  I let most
address verifiers run without caring (and Postfix can/will cache verification).
If someone "hits" me for *every* post to a list, I usually ask them to stop,
but since most do, I've never had to take the step of firewalling anyone else.

        Simply, any site that shows up many times a week in my reports means
one of us is doing something not quite right - and I can't distinguish them
from all the probe traffic from Asia, so I just firewall the address they
use for the probe connections (it is not one of their MXs).  Otherwise, I
have to rely on just "knowing" their IP and recognizing it (hence irritating).

        Paul Shupak
        [EMAIL PROTECTED]

Reply via email to