3 ms·
Subdomains are not as much a problem as you would think. There is a resource ( https://publicsuffix.org/ https://publicsuffix.org/ ) that lists all public suffi
by Ruphin 5y ago
Subdomains are not as much a problem as you would think. There is a resource ( https://publicsuffix.org/ https://publicsuffix.org/ ) that lists all public suffix domains. All direct subdomains of these are in full control of all their own subdomains, and thus can share the same spam reputation.
e.g. when .com is on the list, and .somesite.com is not on the list, mail@somesite.com is from the same entity as mail@subdomain.somesite.com
- kelnos 5y agoDidn't publicsuffix effectively get DoSed by one of Apple's new requirements, causing a ton of people to apply to have their suffixes added to the list? From what I gathered from that, publicsuffix is a poorly-funded semi-volunteer org that shouldn't be relied upon for anything critical.
- cormacrelf 5y agoIf this is how MS/Google want to do email anti-spam, they should fund the public suffix list. Same with Apple for their App Store and WebKit uses. (Btw I’m pretty sure almost everyone is already using domain-based spam scoring.)
- tikiman163 5y agoThey unfortunately use both domain and ip based reputation scores. The problem is there are effectively an infinite number of usable domains. Even after eliminating the sub-domain problem the fact is there are simply too many possible domain names that can be created and discarded on the fly for less than $5 a pop. Given the fact that bad reputation decays, they can simply rinse a repeat that process practically forever so long as they manage to make more than $5 per hour from thier spam. IPv4 addresses however, are far more scarce which is why most spam email opperations try to take over existing legitimate small email servers (commonly small businesses with thier own domain get targeted) in order to send out thier spam. Every time they succeed they use it not only to send spam emails, but Trojan viruses to all users contacts in the hope of infecting other businesses. They can even achieve this without infecting the server itself, but simply getting recipients to unknowingly run a script that tells Outlook to send the emails from whatever addresses the users has access to.