[SURBL-Discuss] SURBL and listing abuse address

Nick Askew Nick at Askew.nl
Mon Dec 20 20:45:48 CET 2004


I have MDaemon installed and lately it has been working wonders to
reject spam. However I've noticed that all it does is bounces the mail
back to the person who supposedly sent it. Now we all know that it is
almost always some innocent address or a fake address and so best case
the bounce is pointless and worst case some innocent person is being
bombarded with mails.

I'm relatively new to all this so please forgive me if this has been
suggested before or indeed if it is simply possible with other mail
servers. It occurs to me that we could list the various abuse addresses
of the ISP hosting the black listed site and this could be returned when
a match is found. If the server software then bounced the mail not to
the sender but to the abuse address we would seriously start to affect
these ISP's.

It seems to me this is not like the lycos solution because we are only
sending a mail when we receive a mail that mentions a spam url. The
result is that the more spam they send the more mails they receive from
us, the less spam they send the less mail they will receive and no
innocent addresses are affected.

There is a drawback to SURBL and that is that someone could end up black
listed wrongly. This mechanism would add insult to injury but lets face
it if I wanted to get at xyz.com I'd send out a bunch of spam as if it
came from jdoe at xyz.com advertising xyz.com and wait for the them to
appear on the black list and then send out more spam and now watch their
ISP get really upset with them as the bounced messages end up with them.


More information about the Discuss mailing list