4 ms·
> I find IP based mail blacklist services such as BRBL obsolete and possibly harmful. Now that we have domain verification services like DKIM SPF etc. Blacklist
by mark242 5y ago
> I find IP based mail blacklist services such as BRBL obsolete and possibly harmful. Now that we have domain verification services like DKIM SPF etc. Blacklist the domain.
SPF and DKIM require opt-in by the sending domain, of which the majority of non-commercial non-US outgoing MTAs do not do. IP-based blocklists, including Spamhaus PSBL Mailspike etc, are all valuable to catch IP addresses that should not be directly connecting to your MTA. I agree that signing up for an outgoing MTA service such as Sendgrid makes some IP-based checks obsolete but that's not where the majority of spam is coming from. Botnets continue to be the number one source of junk email and will likely continue as we add more and more insecure doorbells, garage openers, refrigerators, etc, to our home networks.
- OJFord 5y ago> Botnets continue to be the number one source of junk email and will likely continue as we add more and more insecure doorbells, garage openers, refrigerators, etc, to our home networks. Surely that's an argument against blocking IPs? Unless I suppose you argue they're predominantly in homes; and homes are predominantly not running (intentional, well-behaved) email servers, so sorry-not-sorry those who are.
- mark242 5y agoYes. The days of running a legitimate MTA at home are unfortunately over. Many US-based consumer ISPs block port 25 entirely except for connections to their own MTAs, but for the ones who don't, very very many of those IP addresses wind up on policy-based blacklists -- eg "this network is a bunch of consumer addresses and should never be connecting directly to an MTA"
- megous 5y agoRunning from home IP sucks for other reasons too, like non-static IP addresses, or lack of public IPv4/use of CGNAT. I certainly would not risk my emails being delivered to someone else's computer just because IP address changed, and DNS still points to the previous one. But having the server and data at home is still possible via VPN.