RE: [Asrg] Some data on the validity of MAIL FROM addresses

"Eric D. Williams" <eric@infobro.com> Wed, 21 May 2003 04:29 UTC

Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id AAA11693 for <asrg-archive@odin.ietf.org>; Wed, 21 May 2003 00:29:22 -0400 (EDT)
Received: (from mailnull@localhost) by www1.ietf.org (8.11.6/8.11.6) id h4L3u0L32146 for asrg-archive@odin.ietf.org; Tue, 20 May 2003 23:56:00 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4L3u0B32141 for <asrg-web-archive@optimus.ietf.org>; Tue, 20 May 2003 23:56:00 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id AAA11670; Wed, 21 May 2003 00:28:51 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19ILCO-0002wx-00; Wed, 21 May 2003 00:27:32 -0400
Received: from ietf.org ([132.151.1.19] helo=www1.ietf.org) by ietf-mx with esmtp (Exim 4.12) id 19ILCN-0002wu-00; Wed, 21 May 2003 00:27:31 -0400
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4L3sMB32087; Tue, 20 May 2003 23:54:22 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4L3pgB31974 for <asrg@optimus.ietf.org>; Tue, 20 May 2003 23:51:42 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id AAA11396 for <asrg@ietf.org>; Wed, 21 May 2003 00:24:34 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19IL8E-0002vI-00 for asrg@ietf.org; Wed, 21 May 2003 00:23:14 -0400
Received: from black.infobro.com ([63.71.25.39] helo=infobro.com) by ietf-mx with smtp (Exim 4.12) id 19IL8A-0002v5-00 for asrg@ietf.org; Wed, 21 May 2003 00:23:12 -0400
Received: from red (unverified [207.199.136.153]) by infobro.com (EMWAC SMTPRS 0.83) with SMTP id <B0002554205@infobro.com>; Wed, 21 May 2003 00:22:46 -0400
Received: by localhost with Microsoft MAPI; Wed, 21 May 2003 00:23:03 -0400
Message-ID: <01C31F2F.24E92910.eric@infobro.com>
From: "Eric D. Williams" <eric@infobro.com>
To: 'Kee Hinckley' <nazgul@somewhere.com>, 'Scott Nelson' <scott@spamwolf.com>
Cc: "'asrg@ietf.org'" <asrg@ietf.org>
Subject: RE: [Asrg] Some data on the validity of MAIL FROM addresses
Organization: Information Brokers, Inc.
X-Mailer: Microsoft Internet E-mail/MAPI - 8.0.0.4211
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/pipermail/asrg/>
Date: Tue, 20 May 2003 22:25:58 -0400
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

I see major bounce back from spammer addresses - forgery? (this is anecdotal) 
To me this is not unusual.

-e

On Monday, May 19, 2003 9:55 AM, Kee Hinckley [SMTP:nazgul@somewhere.com] 
wrote:
> At 8:25 PM -0700 5/18/03, Scott Nelson wrote:
> >I would expect that /if/ the majority of return addresses are forged,
> >then the spammer would pick the domain at random from their collection
> >of lists.
>
> As I noted in my mail.  This appears to be happening now--although I
> had not seen symptoms of it before.  Is anyone else starting to see
> low-level occasional bounce back from spam?
>
> Prior to that, all of the bounce-back instances I had heard of or
> experienced (and I used to get one or two a week) were major--where
> the entire spam load got sent out with the same return address.
>
>
> --
> Kee Hinckley
> http://www.messagefire.com/          Junk-Free Email Filtering
> http://commons.somewhere.com/buzz/   Writings on Technology and Society
>
> I'm not sure which upsets me more: that people are so unwilling to accept
> responsibility for their own actions, or that they are so eager to regulate
> everyone else's.
> _______________________________________________
> Asrg mailing list
> Asrg@ietf.org
> https://www1.ietf.org/mailman/listinfo/asrg
_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg