Re: SPAM: dealing with it

From: Christian Weisgerber (naddy@mips.inka.de)
Date: Sun May 19 2002 - 16:35:13 MDT


Robert J. Bradbury <bradbury@aeiveos.com> wrote:

> It gave me a *lot* of pleasure to switch my SPAMREPLY
> code from the test mode to the mode where the messages
> get bounced and their ISP's get notified... :-;

I advise against bouncing spam. The bounce will not get back to
the spammer. It may be undeliverable, just disappear somewhere,
or end up at another victim.

Similar caution needs to be exercised when identifying the point
of origin for further action. The only information you can trust
is the Received stamp from the last host you consider trustworthy.
Typically, it will mention the IP address of the machine that
delivered the message. All preceding Received lines, envelope
addresses, and the normal header can be entirely fictitious. Be
very, very careful that you don't shoot an innocent person.

> So, I'm now saving time by not having to sort the messages
> myself though the downside is that I need to review
> multiple folders for email (there ought to be meta-folder
> with the folders with unread mail according to some
> priority system -- anyone know of an email system that
> has this, esp. for Linux?).

Personally, I feed all mailing lists to a mail-to-news gateway that
posts the messages to local newsgroups which I read along with a
bit of USENET news. Newsreaders have been optimized to deal with
lots of traffic. There is enough legitimate but just as annoying
crap on public lists and in newsgroups that it drowns out spam
there.

Only personal messages and spam addressed to me still end up in my
mailbox.

> What I have discovered is that there is a *lot* of spam
> traffic out there and it seems to be increasing.

Yes.

> I'm up to getting 2-3 copies a day of the same message from
> different sources in some cases. I wasn't aware of this
> last year because I was using the sendmail Black List
> code to block the receipt of most of this.

Oh, the upstream servers that accept my mail all employ a variety
of basic filtering mechanisms such as subscribing to the RBL and
similar services. This is elementary. I don't know how much of
the tide it stems.

-- 
Christian "naddy" Weisgerber                          naddy@mips.inka.de


This archive was generated by hypermail 2.1.5 : Sat Nov 02 2002 - 09:14:13 MST