4 ms·
Blacklists weren't exactly a great solution to start with.
by idive 16y ago
Blacklists weren't exactly a great solution to start with.
- mike-cardwell 16y agoTrue, but they are the best defence we currently have available. I would like it if the largest players in email (Microsoft, Yahoo, Google, AOL) got together to organise the creation of an independent not-for-profit organisation which would run a public whitelist. They could set a cut off date after which they would no longer accept email from non-whitelisted addresses. Email admins who don't usually pay much attention would suddenly notice their mail being rejected, would be forced to register on the whitelist, and would ideally implement the db themselves on their systems. The difficult part would be deciding how IPs get onto the whitelist and under what circumstances they are removed. And its day to day management of course.
- InclinedPlane 16y agoNo, they are not the best defense available. They are a questionably effective interim band-aid at best and a useless hack at worst (since they reduce the effectively useful IPv4 space). Other methods such as baysian filtering and sender authentication are far more useful.
- mike-cardwell 16y agoI have been an email administrator for an ISP and a University, and I have been active in many spam related forums/mailing lists for many years now, and I completely disagree. Blacklists catch far more spam than bayes, are far easier to administer and far less resource intensive. Personally, I try to deploy both, with blacklists first in line, then bayes to catch some stuff that the blacklists miss. "Sender authentication" is a vague term. If you mean verification of the sender address via various DNS lookups, then yes, that's quite useful, but still nowhere near as useful as blacklists. This is how I see people setting up their spam filters in the industry. It might not be idealistic, but it is effective and wide spread.
- tomjen3 16y agoThere are better methods than just doing a dns check. Actually signing the messages works too, as does whitelisting of ips by the domain owner.
- mike-cardwell 16y agoYou're describing SPF and DKIM. Both of which can be used by people sending legitimate mail, and people sending spam... SPF and DKIM are good for preventing some false positives. They're not good for stopping spam. I would bet that currently, well over 90% of spam that is rejected, is rejected because of blacklist lookups.
- deleted 16y ago[deleted]
- idive 16y agoIsn't that what SPF and DomainKeys are supposed to do? Being able to administer DNS for a domain is usually a pretty good indication that you know what IPs are allowed to send emails from it.