Re: [Asrg] [ASRG] SMTP pull anyone?

Rich Kulawiec <> Wed, 26 August 2009 22:21 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 0E8453A6AB3 for <>; Wed, 26 Aug 2009 15:21:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id CO+FeINI+7qt for <>; Wed, 26 Aug 2009 15:21:06 -0700 (PDT)
Received: from ( []) by (Postfix) with ESMTP id 777DD3A70EF for <>; Wed, 26 Aug 2009 15:21:06 -0700 (PDT)
Received: from ( []) by (8.14.1/8.14.1) with ESMTP id n7QMLBpu012679 for <>; Wed, 26 Aug 2009 18:21:12 -0400 (EDT)
Received: from ( []) by (8.14.1/8.14.1) with ESMTP id n7QMD7Am001415 for <>; Wed, 26 Aug 2009 18:13:07 -0400 (EDT)
Received: from (localhost []) by (8.14.3/8.14.3/Debian-4) with ESMTP id n7QML5Gd029344 for <>; Wed, 26 Aug 2009 18:21:06 -0400
Received: (from rsk@localhost) by (8.14.3/8.14.3/Submit) id n7QML57E029334 for; Wed, 26 Aug 2009 18:21:05 -0400
Date: Wed, 26 Aug 2009 18:21:05 -0400
From: Rich Kulawiec <>
To: Anti-Spam Research Group - IRTF <>
Message-ID: <>
References: <> <>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <>
User-Agent: Mutt/1.5.18 (2008-05-17)
Subject: Re: [Asrg] [ASRG] SMTP pull anyone?
X-Mailman-Version: 2.1.9
Precedence: list
Reply-To: Anti-Spam Research Group - IRTF <>
List-Id: Anti-Spam Research Group - IRTF <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Wed, 26 Aug 2009 22:21:11 -0000

On Wed, Aug 26, 2009 at 06:06:01PM -0000, John Levine wrote:
> >Rich, does ipv6 change any of this?
> I'm not Rich, but the open question at this point is how effective
> DNSBLs will be on IPv6.

What John said.

Point blocks already have their issues, for example (a) hosts using
dynamic addressing can hop around within a network allocation and
(b) spammers can try to use snowshoe techniques to tread lightly
enough to evade them.  And they can be unwieldly.  I think all of
this is likely to get worse with IPv6.  I rather suspect that this
will lead to mechanisms using entire network blocks -- some of which
we already have.  (For example, we have MTAs that understand blacklists
in CIDR format.)

At least some of the other measures should continue working, though,
as they're independent of IPv4-IPv6.  But I think while they may be
helpful, they're not going to be enough.

I don't see much help coming from SPF or DKIM or whatever: most of the
spam that makes it past my setup is correctly marked with one of these.
(<cough> Hotmail, Yahoo)  I expect this will get much worse as spammers
begin to leverage the full power of the botnets they're operating.