4 ms·
So, while the loss of SORBS is troubling (I mean: yet another initially-volunteer-driven and widely-used project burning out...), it, like other DNSBLs, is not
by PreInternet01 2y ago
So, while the loss of SORBS is troubling (I mean: yet another initially-volunteer-driven and widely-used project burning out...), it, like other DNSBLs, is not very relevant to modern spam filtering anymore.
With, like, 80+% of inbound SMTP traffic coming from Google, Microsoft, Amazon and assorted non-malicious transactional/list-based SaaSes, a simple 'I either like or dislike the sending IP' approach has been infeasible for many years.
- jeffbee 2y agoDNSBLs have been effectively the same as turning your mailer off, for at least 15 years.
- PreInternet01 2y agoSorry, "turning your mailer off" seems outbound-related to me, whereas DNSBLs are typically used for inbound filtering? And in 2009, filtering inbound SMTP traffic using a popular DNSBL or two was definitely effective (as was greylisting). Alas, no more. But I probably misunderstand what you're saying?
- Animats 2y ago> With, like, 80+% of inbound SMTP traffic coming from Google, Microsoft Just do a challenge-response on incoming mail from new addresses on Gmail and Outlook. Send an auto-reply telling them they can get their mail through if they copy a code in the reply. That will kill most spams from those sources.
- mistrial9 2y agoisn't this essentially handing police powers to a duopoly of USA commercial corporations?
- Wingy 2y agoI think they mean that gmail/outlook are highly abused and you can reduce spam by demanding a challenge response from new addresses on those domains when they email your domain.
- Animats 2y agoYes. I'm talking about spam originating from Gmail and Outlook, not received by them.
- immibis 2y agoWe already did that.
- ttul 2y agoA few years ago, I would have said that the challenge-response approach was doomed to failure, but in light of the concentration of spam and phishing emanating from Gmail accounts, Gmail addresses are the new IP addresses. How long before someone starts distributing a Gmail address blocklist?
- johnklos 2y agoThat's a good idea in theory, but considering IPv4 addresses cost money and Gmail addresses are infinite for practical purposes, that wouldn't work. I don't know that I've ever seen the same Gmail address used more than once for spam and phishing. It'd be nice if Google did something about this. Until they do, I tell everyone that uses Google for email that they have to accept that they're hosting with one of the biggest sources of spam on the Internet that, as far as I'm aware, does absolutely nothing when spam from them is forwarded to their abuse addresses.
- PreInternet01 2y ago> Send an auto-reply telling them they can get their mail through if they copy a code in the reply Never auto-reply to any email ever. You're only making the spam problem worse. (Plus, if you think there are not actual persons behind most Outlook/Gmail spam, I've got news for you. They will reply, and beg you for another chance, sometimes in highly emotional terms). "550 5.7.1 The recipient has set a policy that prohibits email from this sender" at the SMTP level is the only way forward here.
- _delirium 2y agoIt certainly doesn't solve the spam problem by itself, but as someone still DIY hosting their email, I find the Spamhaus Zen DNSBL has non-zero usefulness. Mostly filtering out some of the botnet spam that gets past the initial "must have RDNS than matches forward DNS" Postfix check (which gets a bigger chunk of it).
- nurple 2y agoI still love using DNSBL as part of a score-based approach. Add Bayesian filtering, spf/dkim scoring, a greylist, and postfix options like RDNS checks. I see a few spam a week, have never seen a false positive. I think greylisting made the biggest difference after sane-sender checks.
- muppetman 2y agoWhere do you get this 80%+ spam coming from MS etc from? My mailserver still gets heaps and heaps of spam from random IP's that an RBL helps block. I use rspamd which takes a number of RBLs into account. Yes, RBL isn't the only thing it uses (there's Bayes, Neural Net, dmarc/dkim/sfp, razor/pyzor as well as others). Very little spam comes from the big players. I DO see a lot of spam attempts from *.onmicrosoft.com domain names, but no one legit sends from that domain so that's just blocked outright. If the argument is 80%+ of email is _handled by_ MS/Google etc then yea, I agree. But us losers out here still doing our own mail still see masses of spam from random IPs that RBLs still help block. All that said, seeya SORBs. Your data was always hot garbage and so full of false positives as to be useless.
- PreInternet01 2y agoStrict SPF enforcement will get rid of most of the random-IP spam. Then, you'll identify a few hosting providers that actually get SPF right, but are very easy to block based on rDNS or name servers. And then it's really mostly Amazon/Google/Microsoft and assorted transactional/list SaaSes...
- muppetman 2y agoI disagree. Looking at just a random spam I have here, I see it passed both SPF and DKIM happily. But it was marked as spam in HostKarma, Spamhaus, Truncate and flagged as Bulk by Razor. So I dropped it. Looking at heaps of my attempted Spam emails I see the same. It seems most spammers setup SPF before attempting, or are hijacking legit sites/mailservers to send the spam. Pretty much the only Spam I find I reject based on DMARC as well is just the "I hacked your webcam" blackmail spam that tries to "prove" they hacked you by spoofing my email domain. I think if I disabled all RBLs the other huristics rspam gives me would still catch 90% of the Spam, but the RBLs certainly help me still catch 99.9% of the Spam attempts I recieve.
- TwoNineFive 2y ago> With, like, 80+% of inbound SMTP traffic coming from Google, Microsoft, Amazon Factually untrue. You are a teenager spouting self-important garbage.