Re: [Asrg] seeking comments on new RMX article

Steven F Siirila <sfs@tc.umn.edu> Tue, 06 May 2003 17:07 UTC

Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA29627 for <asrg-archive@odin.ietf.org>; Tue, 6 May 2003 13:07:11 -0400 (EDT)
Received: (from mailnull@localhost) by www1.ietf.org (8.11.6/8.11.6) id h46HFk809721 for asrg-archive@odin.ietf.org; Tue, 6 May 2003 13:15:46 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h46HFk809718 for <asrg-web-archive@optimus.ietf.org>; Tue, 6 May 2003 13:15:46 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA29609; Tue, 6 May 2003 13:06:41 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19D5vq-0000dv-00; Tue, 06 May 2003 13:08:46 -0400
Received: from ietf.org ([132.151.1.19] helo=www1.ietf.org) by ietf-mx with esmtp (Exim 4.12) id 19D5vq-0000ds-00; Tue, 06 May 2003 13:08:46 -0400
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h46HBD809378; Tue, 6 May 2003 13:11:13 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h46H8h809255 for <asrg@optimus.ietf.org>; Tue, 6 May 2003 13:08:43 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id MAA29318 for <asrg@ietf.org>; Tue, 6 May 2003 12:59:39 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19D5p2-0000aX-00 for asrg@ietf.org; Tue, 06 May 2003 13:01:44 -0400
Received: from earth.tc.umn.edu ([160.94.5.5]) by ietf-mx with esmtp (Exim 4.12) id 19D5p1-0000aQ-00 for asrg@ietf.org; Tue, 06 May 2003 13:01:43 -0400
Received: by earth.tc.umn.edu; Tue, 6 May 2003 12:02:33 -0500
From: Steven F Siirila <sfs@tc.umn.edu>
To: Scott Nelson <scott@spamwolf.com>
Cc: asrg@ietf.org
Subject: Re: [Asrg] seeking comments on new RMX article
Message-ID: <20030506170232.GD10345@earth.tc.umn.edu>
References: <aT5vaIe86J8qbrFBE02@x>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <aT5vaIe86J8qbrFBE02@x>
User-Agent: Mutt/1.4.1i
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/pipermail/asrg/>
Date: Tue, 06 May 2003 12:02:32 -0500

On Tue, May 06, 2003 at 12:18:40AM -0700, Scott Nelson wrote:
> 
> >(Yes, reverse DNS can be faked, but that can be reasonably reliably 
> > detected by doing an extra forward lookup of the reverse name.)
> >(Yes, in some
> >cases you must do a little more than just comparing the PTR and A RRs,
> >such as fetching all PTR RRs or all A RRs for the PTR name.)
> 
> Reverse DNS is controlled by the IP.
> If they have an rDNS, you would do about as well by skipping
> the rDNS and using the HELO to do a forward look up.

As mentioned previously on this list, a spammer has control over the EHLO
parameter for open proxies, but has no control over the originating IP
address.  So there is a difference.

> Of course, having rDNS is also a sign of clue, 
> and many spammers are lacking in that which makes the mere presence
> of rDNS a good test.

We are finding rDNS checks to be more and more useful over the past 9 months
as more and more real MTAs are getting "proper" rDNS RRs.  What makes these
checks useful is that the spammer using open proxies and the like has no
control over rDNS configuration, only over the SMTP sessions they create.
We are finding that a lot of sites do not bother setting up rDNS for the
many client workstations they are responsible for.  This makes those very
workstations unable to be abused by spammers (at least for sending to sites
who check rDNS, such as ours).
_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg