3 ms·
This is fully misguided. Did you ever maintain a mail server and/or check your spam? SPAM is for the vast majority SPF/DKIM/whatever compliant (in fact, my regu
by wakeupcall 4y ago
This is fully misguided. Did you ever maintain a mail server and/or check your spam? SPAM is for the vast majority SPF/DKIM/whatever compliant (in fact, my regular email has less DKIM signatures). The joke was always that SPAM was passing all these checks _earlier_ than real email systems.
Why?
SPAM is mostly sent through illegitimately acquired accounts on big-brand servers now. Add a new check? Well, sorry to break it to you, your spam is going to have it too. In fact, on the systems I manage, 70%+ of all spam is coming from gmail itself.
People conflate SPF/DKIM/DMARC with spam checking.. they're not systems to prevent spam. They're intended to prevent forgery.
Realistically, to protect from the dumbest forms of forgery (which is what spam initially was leveraging on), SPF is really all you need.
If a spam email can leave a system configured with SPF, in practice it's already a problem with the organization that let that message out. No system is going to help you with such a problem, and so they're equally useless as spam filters.
- Avamander 4y ago> This is fully misguided. It is not. There's still a significant amount of spam that doesn't have SPF, there's a lot of forgery and it's easier to filter if everyone used the holy trinity. > SPAM is mostly sent through illegitimately acquired accounts on big-brand servers now. That's what you see on and from gmail, but it's not the majority of spam.
- wakeupcall 4y ago> It is not. There's still a significant amount of spam that doesn't have SPF, there's a lot of forgery and it's easier to filter if everyone used the holy trinity. Absolutely. But but again, this will _not_ solve SPAM as the parent implied. > That's what you see on and from gmail, but it's not the majority of spam. There's a huge variability on sources, depending also on the class of users you have on your server. However I do keep all copies of spam that could pass greylisting for classification purposes since the early 2010' from various sources and honeypot addresses -- correctly signed spam _is_ the vast majority. Low-effort spammers are pretty easy to weed out. And while rejecting messages without SPF is still not feasible, it wouldn't _improve_ the ham/spam filtering ratio in my case.
- Avamander 4y ago> But but again, this will _not_ solve SPAM as the parent implied. Nothing will, it's an unreasonable standard to set for a proposal intended to improve the situation. > it wouldn't _improve_ the ham/spam filtering ratio in my case. But for many it would. Plus it would force legitimate e-mail senders to stay on-par with the spammers'.
- wakeupcall 4y agoIt's a very subjective view, but while I do absolutely recommend for every single system to have SPF at the very minimum, I didn't see any practical advantage for spam filtering for newer proposals such as DMARC/DKIM. Any spammer that has SPF enabled, will have the rest.
- dane-pgp 4y ago> People conflate SPF/DKIM/DMARC with spam checking.. they're not systems to prevent spam. They're intended to prevent forgery. That's why I said that mandating these things was the easy half. Once spoofing isn't possible, we have to build a proper (decentralised) system of domain reputation, with financial penalties attached. (And in order to get all existing internet users to agree to this, we have to exempt them and only burden future domain registrants, since there are no lobbyists for corporations that don't exist yet). My understanding is that a lot of spam comes from cheaply and temporarily registered domains which are discarded as soon as the emails have been sent, because the domain's reputation is trashed within hours. If doing that caused the spammers to lose even $100, it would put their costs up considerably, and hopefully destroy their profit margin.