At 13:56 2004-09-27 +0530, Suresh Ramasubramanian wrote:
Jeff Chan wrote:
Thanks for your feedback on this. Have you guys looked into ways to prevent these from getting on your lists? For example, is the corpus of new additions small enough to be hand-checked?
It is a few hundred a day and does have to be blocked in real time :(
Seems to me it's better to check first and block second. It's better to let a few spams in than to block legitimate mail, IMO.
For most of what we spot (typically pharmacy spam domains) checking first will mean several thousand more emails coming in.
How many of those that currently get listed have name servers listed in SBL at the time they get listed? If a substantial part do have their name server listed in SBL, have you considered using that type of data as an aid to filter out FPs in real time?
Patrik