Re: [Asrg] Some data on the validity of MAIL FROM addresses

Scott Nelson <scott@spamwolf.com> Mon, 19 May 2003 02:03 UTC

Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA23012 for <asrg-archive@odin.ietf.org>; Sun, 18 May 2003 22:03:37 -0400 (EDT)
Received: (from mailnull@localhost) by www1.ietf.org (8.11.6/8.11.6) id h4J1WL622203 for asrg-archive@odin.ietf.org; Sun, 18 May 2003 21:32:21 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4J1WLB22200 for <asrg-web-archive@optimus.ietf.org>; Sun, 18 May 2003 21:32:21 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id WAA23001; Sun, 18 May 2003 22:03:06 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19Ha1J-0006dB-00; Sun, 18 May 2003 22:04:57 -0400
Received: from ietf.org ([132.151.1.19] helo=www1.ietf.org) by ietf-mx with esmtp (Exim 4.12) id 19Ha1I-0006d5-00; Sun, 18 May 2003 22:04:56 -0400
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4J1S3B21998; Sun, 18 May 2003 21:28:03 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h4J1RXB21971 for <asrg@optimus.ietf.org>; Sun, 18 May 2003 21:27:33 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id VAA22933 for <asrg@ietf.org>; Sun, 18 May 2003 21:58:18 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19HZwe-0006cS-00 for asrg@ietf.org; Sun, 18 May 2003 22:00:08 -0400
Received: from adsl-66-120-64-133.dsl.snfc21.pacbell.net ([66.120.64.133] helo=magic1.org) by ietf-mx with smtp (Exim 4.12) id 19HZwe-0006cP-00 for asrg@ietf.org; Sun, 18 May 2003 22:00:08 -0400
Message-Id: <aT5vaIe86J8qbrFfG02@x>
To: asrg@ietf.org
From: Scott Nelson <scott@spamwolf.com>
Subject: Re: [Asrg] Some data on the validity of MAIL FROM addresses
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/pipermail/asrg/>
Date: Sun, 18 May 2003 19:01:24 -0700

At 08:58 PM 5/18/03 -0400, Kee Hinckley wrote:
>At 10:53 AM +0100 5/18/03, Jon Kyme wrote:
>>  >
>>>  Interesting that the results vary so much by ISP.  Yahoo accounts are
>>>  pretty valid.  Hotmail accounts are pretty bad.  AOL is quite good.
>>>  Earthlink has a problem.  MSN's slightly better, but still negative.
>>
>>
>>Of course yahoo will say 250 to pretty much anything.
>>So these addresses are "valid" in what sense exactly?
>
>They said "no" to 16% of the messages I queried them on.  The 
>specific message they used was:
>
>553 VS10-RT Possible forgery or deactivated due to abuse (#5.1.1)
>
>Can you show instances in which they say yes to messages they cannot deliver?
>

I tried this:

% head /dev/urandom | md5sum
ce4c096d881440fffebbde3b64291d92  -

% telnet mx1.mail.yahoo.com 25
Trying 64.156.215.5...
Connected to mx1.mail.yahoo.com.
Escape character is '^]'.
220 YSmtp mta124.mail.scd.yahoo.com ESMTP service ready
helo spamwolf.com
250 mta124.mail.scd.yahoo.com
mail from:<>
250 null sender <> ok
rcpt to:<ce4c096d881440fffebbde3b64291d92@yahoo.com>
250 recipient <ce4c096d881440fffebbde3b64291d92@yahoo.com> ok
quit
221 mta124.mail.scd.yahoo.com
Connection closed by foreign host.


Saying that <ce4c096d881440fffebbde3b64291d92@yahoo.com> is 
unlikely to be a valid address is an understatement.

Scott Nelson <scott@spamwolf.com>
_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg