|
|
 |
RE: FN-FORUM: email spoofing best practice
date posted 19th January 2007 12:33
Thanks all, and Dave and Alain: my host can set up SPF apparently so I'm
going to request that. Thanks
-----Original Message-----
From: [EMAIL REMOVED] [EMAIL REMOVED] On Behalf Of Dave Cross
Sent: 19 January 2007 12:42
To: FN-FORUM / [EMAIL REMOVED]
Subject: Re: FN-FORUM: email spoofing best practice
Quoting [EMAIL REMOVED] [EMAIL REMOVED] [EMAIL REMOVED]
[EMAIL REMOVED]
> Someone's spoofing my domain to send spam - my question is, what's the
best
> policy to try and avoid being blacklisted or whatever? The two things I'm
> considering are setting unknown recipients to 'black hole' or ':fail: no
> such address here' in cPanel.
It's definitely worth publishing SPF[1] records for your domain. It
won't do anything practical for most people (as most people don't
check SPF records before accepting mail) but for the few who do it
will mean they don't see the spam. And, more importantly, if you get
complaints from people who get the spam then you can point at the SPF
records as evidence that it didn't come from you.
This kind of spam is known as a Joe Job[2]. Last weekend the address
of a mailing list I run was Joe-jobbed. Over a period of 36 hours we
got about 50,000 bounce messages sent to the list. I can only hope
that the phishers responsible for the mail get a refund from whoever
sold them such a rubbish list of mail addresses :-)
Dave...
[1] http://en.wikipedia.org/wiki/Sender_Policy_Framework
[2] http://en.wikipedia.org/wiki/Joe_job
--
Magnum Solutions Ltd
Open Source Consultancy, Development and Training
http://mag-sol.com/
--
Freelancers, contractors earn more with Prosperity4
Call 0870 870 4414 or visit www.prosperity4.com
and benefit from Inland Revenue approved expenses today.
To advertise here: http://www.freelancers.net/advertising.html
|
 |
|