atom feed77 messages in net.sourceforge.lists.courier-usersRe: Alternative concepts to SPF vs. Y...
FromSent OnAttachments
Mitch (WebCob)Jan 5, 2004 11:31 am 
Jeff PotterJan 5, 2004 12:58 pm 
Mitch (WebCob)Jan 5, 2004 1:26 pm 
Gerardo GregoryJan 5, 2004 1:34 pm 
Sam VarshavchikJan 5, 2004 1:56 pm 
Andrew NewtonJan 5, 2004 3:02 pm 
Sam VarshavchikJan 5, 2004 3:23 pm 
Mitch (WebCob)Jan 5, 2004 3:38 pm 
Andrew NewtonJan 5, 2004 5:49 pm 
Sam VarshavchikJan 5, 2004 5:57 pm 
Andrew NewtonJan 5, 2004 7:06 pm 
Mitch (WebCob)Jan 5, 2004 8:19 pm 
Gordon MessmerJan 5, 2004 11:58 pm 
Sam VarshavchikJan 6, 2004 4:10 am 
Sam VarshavchikJan 6, 2004 4:11 am 
Sam VarshavchikJan 6, 2004 4:12 am 
Gordon MessmerJan 6, 2004 10:20 am 
Mitch (WebCob)Jan 6, 2004 10:50 am 
Malcolm WeirJan 6, 2004 2:10 pm 
Julian MehnleJan 6, 2004 3:07 pm 
Phillip HutchingsJan 6, 2004 3:28 pm 
Sam VarshavchikJan 6, 2004 3:44 pm 
Sam VarshavchikJan 6, 2004 3:46 pm 
Mitch (WebCob)Jan 6, 2004 3:56 pm 
Julian MehnleJan 6, 2004 4:17 pm 
Sam VarshavchikJan 6, 2004 4:31 pm 
Julian MehnleJan 6, 2004 4:45 pm 
Roger B.A. KloreseJan 6, 2004 5:17 pm 
Roger B.A. KloreseJan 6, 2004 5:20 pm 
Julian MehnleJan 6, 2004 5:33 pm 
Roger B.A. KloreseJan 6, 2004 5:51 pm 
Julian MehnleJan 6, 2004 6:12 pm 
Malcolm WeirJan 6, 2004 6:17 pm 
Roger B.A. KloreseJan 6, 2004 6:22 pm 
Sam VarshavchikJan 6, 2004 6:34 pm 
Sam VarshavchikJan 6, 2004 6:47 pm 
Julian MehnleJan 6, 2004 7:10 pm 
Julian MehnleJan 6, 2004 7:42 pm 
Julian MehnleJan 6, 2004 7:53 pm 
Roger B.A. KloreseJan 6, 2004 7:54 pm 
Roger B.A. KloreseJan 6, 2004 7:56 pm 
Roger B.A. KloreseJan 6, 2004 8:13 pm 
Sam VarshavchikJan 6, 2004 8:16 pm 
Sam VarshavchikJan 6, 2004 8:19 pm 
Sam VarshavchikJan 6, 2004 8:22 pm 
Roger B.A. KloreseJan 6, 2004 8:22 pm 
Roger B.A. KloreseJan 6, 2004 8:29 pm 
Mitch (WebCob)Jan 6, 2004 11:19 pm 
RolandJan 7, 2004 3:56 am 
Sam VarshavchikJan 7, 2004 4:14 am 
Julian MehnleJan 7, 2004 10:47 am 
Julian MehnleJan 7, 2004 10:59 am 
Roger B.A. KloreseJan 7, 2004 11:37 am 
Malcolm WeirJan 7, 2004 12:18 pm 
Julian MehnleJan 7, 2004 1:09 pm 
Julian MehnleJan 7, 2004 1:40 pm 
Gordon MessmerJan 7, 2004 3:08 pm 
Malcolm WeirJan 7, 2004 3:14 pm 
Sam VarshavchikJan 7, 2004 3:32 pm 
Mitch (WebCob)Jan 7, 2004 3:46 pm 
Sam VarshavchikJan 7, 2004 3:50 pm 
Julian MehnleJan 7, 2004 3:52 pm 
Bill MichellJan 7, 2004 3:54 pm 
Mitch (WebCob)Jan 7, 2004 3:56 pm 
Julian MehnleJan 7, 2004 4:03 pm 
Julian MehnleJan 7, 2004 4:06 pm 
Roger B.A. KloreseJan 7, 2004 4:12 pm 
Phillip HutchingsJan 7, 2004 4:16 pm 
Mitch (WebCob)Jan 7, 2004 4:27 pm 
Julian MehnleJan 7, 2004 4:29 pm 
Mitch (WebCob)Jan 7, 2004 4:32 pm 
Julian MehnleJan 7, 2004 4:33 pm 
Gordon MessmerJan 7, 2004 4:58 pm 
Malcolm WeirJan 7, 2004 5:07 pm 
Julian MehnleJan 7, 2004 5:27 pm 
Phillip HutchingsJan 7, 2004 6:33 pm 
Gordon MessmerJan 7, 2004 7:00 pm 
Subject:Re: Alternative concepts to SPF vs. YASAF WAS RE: [courier-users] RE: freemail list and questions about yahoo...
From:Phillip Hutchings (me@sitharus.com)
Date:Jan 7, 2004 4:16:42 pm
List:net.sourceforge.lists.courier-users

All messages from unknown senders are bounced. The bounce contains a link to a robot-unfriendly "prove you are a human with a real email address page" that consists of one of those "enter the letters you see in this picture" forms. Doing that validates the sender as a real person, not a spammer, and eliminates the need to run something like spamassassin.

I considered such a scheme, but then thought about it and decided against it. Why? Because I'm reluctant to take the extra step to authorise myself. It's irritating when I reply to a mailing list post, CCing the person, and get one of those requests. 99% of the time I ignore it. If I wanted to contact someone then I'd probably do it though.

I am quite fortunate, as I rarely get spam. I used to get quite a lot, then analysed it and noticed that 95% was from two servers, where some asshole was using my email address as a spam hole. I firewalled those hosts after checking who they were, and confirming that no valid correspondence had come from them.

I like the idea of SPF, as Courier esmptd is sensible and allows authenticated relaying by default. Also, as I use webmail mostly outside of my network it works fine.

The real aim of Yahoo!s system is not to authenticate the server though, it's to authenticate the email as being from a valid user. I can see this catching on in corporations, as it'll add a layer of knowledge to the receiver.

As Sam says, msa is rarely blocked as it is an authenticated port. It's also rarely used, so awareness of its existence isn't that high. Configure roaming clients to use this, or get people to use webmail if it's blocked. The problem would be a high-quality webmail system. Sure, squirrelmail works, but it isn't exactly pretty...

Anyway, I'm a bit tired now, I'll think more when I'm awake ;)