whitelist advice

Martin Sapsed m.sapsed at BANGOR.AC.UK
Thu Aug 28 19:55:53 IST 2003


Alan Fiebig wrote:
 > In the never ending quest to balance stopping spam and keeping
 > customers happy with minimum false positives, I am considering adding
 > a whitelist rule of: "From   @*.org  no"
 >
 > to allow all mail sent from '.org' site.
 >
 > 1) How much risk do any of you think I'd be running? Have any of you
 > seen much spam sent from '.orgs'?

We thought it would be safe to whitelist *.ac.uk (the UK academic
community) until the spammers started forging the From: addresses to be
.ac.uk ones.... :-(

The first message in a folder of spam I started collecting with a view
to feeding a bayes database is addressed

From: XXX <XXX at YYYYY.org>

and a couple of others apparently come from .org addresses.

Sorry to deflate your balloon but the spammers don't play fair...!

Cheers,

Martin

--
Martin Sapsed
Information Services               "Who do you say I am?"
University of Wales, Bangor             Jesus of Nazareth



More information about the MailScanner mailing list