OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: challenge/response whitelist system?

From: /dev/rob0 (rob0gmx.co.uk)
Date: Tue Nov 14 2006 - 10:43:37 CST


On Tuesday 14 November 2006 10:30, Sheldon T. Hall wrote:
> Louis-David Mitterrand says ...
>
> > I am looking for a solution involving postfix that would send a
> > challenge with a token to any message failing certain UCE
> > restrictions.
> > Upon valid response the sender would be added to a whitelist.
>
> Do not even consider this as a spam-reduction measure.

Agreed, but if the challenge comes in the form of rejection in SMTP,
there's no real abuse being committed. Real senders get the bounces
from their own server, not from the challenger.

Of course the other problems of C/R still apply. Whitelisting by
easily-forged sender addresses is weak.
--
    Offlist mail to this address is discarded unless
    "/dev/rob0" or "not-spam" is in Subject: header