Re: [Asrg] DNSBL and IPv6

"John Levine" <johnl@taugh.com> Sat, 20 October 2012 21:43 UTC

Return-Path: <johnl@iecc.com>
X-Original-To: asrg@ietfa.amsl.com
Delivered-To: asrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D34E121F873F for <asrg@ietfa.amsl.com>; Sat, 20 Oct 2012 14:43:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -111.721
X-Spam-Level:
X-Spam-Status: No, score=-111.721 tagged_above=-999 required=5 tests=[AWL=0.478, BAYES_00=-2.599, HABEAS_ACCREDITED_SOI=-4.3, RCVD_IN_BSP_TRUSTED=-4.3, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Bt9Dpf6EPbZP for <asrg@ietfa.amsl.com>; Sat, 20 Oct 2012 14:43:26 -0700 (PDT)
Received: from leila.iecc.com (leila6.iecc.com [IPv6:2001:470:1f07:1126:0:4c:6569:6c61]) by ietfa.amsl.com (Postfix) with ESMTP id 0878A21F846F for <asrg@irtf.org>; Sat, 20 Oct 2012 14:43:25 -0700 (PDT)
Received: (qmail 49845 invoked from network); 20 Oct 2012 21:43:20 -0000
Received: from leila.iecc.com (64.57.183.34) by mail1.iecc.com with QMQP; 20 Oct 2012 21:43:20 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=iecc.com; h=date:message-id:from:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:vbr-info; s=50831af8.xn--i8sz2z.k1208; i=johnl@user.iecc.com; bh=IvWERYpOL051FpPVt43VsPdU+oSVqFn8TjeTQxt7xCg=; b=RyMI0qaXPS/rkcHwrWJXgq9MPQmEibNkgfkV7BCfRkac/jP8IcPzclR7IUKyZCkwmMGz6QBLdGBluKwQ3vdw3EhwfPnFT4qy/5ZJY2/S2SazT8DxRhdoBHLlJpiDqcgfyhMQPVCPZ7qPG+g4Q+UK6cbqVj6foVzsYTYr1hIrlc0=
DKIM-Signature: v=1; a=rsa-sha256; c=simple; d=taugh.com; h=date:message-id:from:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:vbr-info; s=50831af8.xn--i8sz2z.k1208; olt=johnl@user.iecc.com; bh=IvWERYpOL051FpPVt43VsPdU+oSVqFn8TjeTQxt7xCg=; b=d76H7B90ACEZR8E0dTs3h2Zrnn44SIo53KUqwxDFrEz3PI/DZ9njAle2Y/m4NeOIPucstwX2s2WIaMvhFpIsWo7WqPrbrbIYQCFJ3UiNNIjlNK0vFKEov8RgrmSlVpQspYEwMs6GJ4Bc1Nl4rVdlv5uWI06JoLY71KD4UThhSMc=
VBR-Info: md=iecc.com; mc=all; mv=dwl.spamhaus.org
Date: 20 Oct 2012 21:42:57 -0000
Message-ID: <20121020214257.3127.qmail@joyce.lan>
From: "John Levine" <johnl@taugh.com>
To: asrg@irtf.org
In-Reply-To: <121020072504.ZM5005@torch.brasslantern.com>
Organization:
X-Headerized: yes
Mime-Version: 1.0
Content-type: text/plain; charset=utf-8
Content-transfer-encoding: 7bit
Subject: Re: [Asrg] DNSBL and IPv6
X-BeenThere: asrg@irtf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: Anti-Spam Research Group - IRTF <asrg@irtf.org>
List-Id: Anti-Spam Research Group - IRTF <asrg.irtf.org>
List-Unsubscribe: <http://www.irtf.org/mailman/options/asrg>, <mailto:asrg-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/asrg>
List-Post: <mailto:asrg@irtf.org>
List-Help: <mailto:asrg-request@irtf.org?subject=help>
List-Subscribe: <http://www.irtf.org/mailman/listinfo/asrg>, <mailto:asrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Sat, 20 Oct 2012 21:43:27 -0000

>} Is there a reason why a legitimate MTA (talking to MXs, not submission
>} servers) would want to hop around in its net?

Probably not, although I'm waiting for ESPs to figure out that if they
send every message from a different IP, it'll be much easier to
process bounces and complaints since all they'll need is the IP to
figure out what the list and address was.

Bad guys could use it to listwash, of course, but it's not totally
ridiculous.

R's,
John