4 ms·
> It is not. There's still a significant amount of spam that doesn't have SPF, there's a lot of forgery and it's easier to filter if everyone used the holy trin
by wakeupcall 4y ago
> It is not. There's still a significant amount of spam that doesn't have SPF, there's a lot of forgery and it's easier to filter if everyone used the holy trinity.
Absolutely. But but again, this will _not_ solve SPAM as the parent implied.
> That's what you see on and from gmail, but it's not the majority of spam.
There's a huge variability on sources, depending also on the class of users you have on your server. However I do keep all copies of spam that could pass greylisting for classification purposes since the early 2010' from various sources and honeypot addresses -- correctly signed spam _is_ the vast majority.
Low-effort spammers are pretty easy to weed out. And while rejecting messages without SPF is still not feasible, it wouldn't _improve_ the ham/spam filtering ratio in my case.
- Avamander 4y ago> But but again, this will _not_ solve SPAM as the parent implied. Nothing will, it's an unreasonable standard to set for a proposal intended to improve the situation. > it wouldn't _improve_ the ham/spam filtering ratio in my case. But for many it would. Plus it would force legitimate e-mail senders to stay on-par with the spammers'.
- wakeupcall 4y agoIt's a very subjective view, but while I do absolutely recommend for every single system to have SPF at the very minimum, I didn't see any practical advantage for spam filtering for newer proposals such as DMARC/DKIM. Any spammer that has SPF enabled, will have the rest.