Re: How I spent my Christmas vacation - Email found in subject

  • From: "Ball, Dan" <DBall@xxxxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Tue, 3 Jan 2006 15:00:28 -0500

1. I have to send NDRs out to people sending in mis-typed addresses, we
deal a lot with get general public, people make typos on e-mail
addresses all the time.  Without the NDRs, many people would send e-mail
and "assume" it went through, and plan their activites according to
those assumptions.  We don't know if the originating addresses are valid
until we attempt to send the NDR.

2. Due to the wide variety of SMTP servers connecting to us, we cannot
"require" them to use a certain type of protocol just to send us e-mail.
Thus, we allow everything to come in, and then deal with the results.
Too many people in the education industry run the cheapest software they
can get, whether it is freeware or stuff that is 10-15 years old it
doesn't matter.  As long as it is free.

3.  Unfortunately, no-one can identify spammers by their e-mail address
or originating server, so it is impossible to tell if we're sending
e-mail to spammers or not. 

The proposed backscatter solution is just a dream.  While I agree that
it IS a problem, and that there are several ways around it, there is no
"practical" solution at this time.  Unless we can get EVERYONE running
completely compatible DNS servers, it will remain an illusive dream.  In
the meantime, we contribute to the e-mail backscatter problem daily not
by choice but by necessity.  Blocking e-mail that doesn't come from a
"compatible" server is entirely out of the question for us right now.


-----Original Message-----
From: Danny [mailto:nocmonkey@xxxxxxxxx] 
Sent: Tuesday, January 03, 2006 2:05 PM
To: [ISAserver.org Discussion List]
Subject: [isalist] Re: How I spent my Christmas vacation - Email found
in subject

http://www.ISAserver.org

On 1/3/06, Joseph Danielsen <JDanielsen@xxxxxxxxxxxxxxxx> wrote:
> Dan:
>
> In my case, I do filter Recp not in AD, but I read GFI's manual which
> suggested that sending the NDR to spammers would simply convince them
to
> take the email address off of their list. Even IF that were true (and
> it's not) the cost was too high.

1) Do not *send* (this means a new message; I am not referring to
rejecting the email in the original SMTP conversation [that should be
your goal]) NDR's to anyone outside of your domain/organization
2) Do not accept email sent to recipients that do not exist!
3) Do not send email to spammers

> It seems as though I stopped making changes like that about the same
> time I stopped eating pills found on the ground...just to see what
> they'd do to me :)
>
> > Please don't beat me up on this one <

Google: email backscatter

...D


Other related posts: