Re: False positives (was Re: [Asrg] Re: RMX Records)

"Chris Lewis" <clewis@nortelnetworks.com> Fri, 07 March 2003 05:44 UTC

Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id AAA00356 for <asrg-archive@odin.ietf.org>; Fri, 7 Mar 2003 00:44:12 -0500 (EST)
Received: (from mailnull@localhost) by www1.ietf.org (8.11.6/8.11.6) id h275tXf05606 for asrg-archive@odin.ietf.org; Fri, 7 Mar 2003 00:55:33 -0500
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h275tXO05603 for <asrg-web-archive@optimus.ietf.org>; Fri, 7 Mar 2003 00:55:33 -0500
Received: from www1.ietf.org (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id AAA00352 for <asrg-web-archive@ietf.org>; Fri, 7 Mar 2003 00:43:41 -0500 (EST)
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h275o4O05254; Fri, 7 Mar 2003 00:50:04 -0500
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h275n6O05023 for <asrg@optimus.ietf.org>; Fri, 7 Mar 2003 00:49:06 -0500
Received: from zcars04e.nortelnetworks.com (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id AAA00221 for <asrg@ietf.org>; Fri, 7 Mar 2003 00:37:14 -0500 (EST)
Received: from zcard307.ca.nortel.com (zcard307.ca.nortel.com [47.129.242.67]) by zcars04e.nortelnetworks.com (Switch-2.2.5/Switch-2.2.0) with ESMTP id h275dG418006 for <asrg@ietf.org>; Fri, 7 Mar 2003 00:39:17 -0500 (EST)
Received: from zcard031.ca.nortel.com ([47.129.242.121]) by zcard307.ca.nortel.com with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.2653.13) id GDFBHRFW; Fri, 7 Mar 2003 00:39:17 -0500
Received: from americasm01.nt.com (acart4yn.ca.nortel.com [47.129.10.124]) by zcard031.ca.nortel.com with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.2653.13) id G3JBF829; Fri, 7 Mar 2003 00:39:15 -0500
Message-ID: <3E683148.10306@americasm01.nt.com>
X-Sybari-Space: 00000000 00000000 00000000
From: Chris Lewis <clewis@nortelnetworks.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.0.2) Gecko/20021120 Netscape/7.01
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: asrg@ietf.org
Subject: Re: False positives (was Re: [Asrg] Re: RMX Records)
References: <E18qJqx-0003Lt-00@mail.nitros9.org> <Pine.LNX.4.53.0303042143080.2979@shishi.roaringpenguin.com> <p06000911ba8b17e3e0a8@[192.168.1.104]> <Pine.LNX.4.53.0303050847550.2048@shishi.roaringpenguin.com>
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/pipermail/asrg/>
Date: Fri, 07 Mar 2003 00:42:32 -0500
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

David F. Skoll wrote:
> On Tue, 4 Mar 2003, Kee Hinckley wrote:
> 
> 
>>Companies may find it necessary to hire a human to filter
>>borderline messages that an automatic filter is unsure of, but in the
>>ISP context, false positives do not have a simple
>>solution--

> Oh, clearly this is not an appropriate solution for an ISP.  I was intending
> it only for a corporate setting.

Eeek!  I don't want to read 50,000 spams per day!

False positives have a very simple solution.  Treat it as the first step 
in a "do something else to get this thru".  Just like confirming a 
mailing list subscription with per-transaction keywords.  Or, "click 
here" to get it through.

In our case, we simply arrange to have the bounces say "if you think 
this was in error, forward this bounce to <x@x>".  Where <x@x> is a 
whitelisted address with people who'll forward/fix mistunings.  It's 
relatively safe - spammers tend not to do that.  And I'm a suspicious 
SOB ;-)

If your filters are good, the FP rate is low.  Our false positive 
handling address averages less than 5 per day.

_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg