OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Postfix Users] Re: Yahoo's DomainKeys

From: Bill Cole (postfixlists-070913billmail.scconsult.com)
Date: Sun Sep 16 2007 - 14:37:26 CDT


At 6:49 PM +0200 9/16/07, Tony Earnshaw imposed structure on a
stream of electrons, yielding:
>Bill Cole skrev, on 16-09-2007 18:07:
>
>[...]
>
>>>Nonsense.
>>
>>It is the truth based on the examination of tens of millions of
>>messages over the past 2 months comprising the post-DNSBL mail
>>stream of multiple corporate domains and some heavily-spammed
>>microdomains. Very little of that mail is signed at all, but the
>>fraction of definite spam that is signed is significantly higher
>>than that for definite non-spam.
>
>The point is, that mail that is signed with rfc4871-compliant DKIM
>*has* to come from the domain it claims it does.
>
>Your spam might have been signed, but it wouldn't have been signed
>such that verification would have confirmed the claimed domain.

No, the signatures verify. Please re-read the message you called
'nonsense' more carefully.

I have no problem believing that you never see spam from the various
spammers who have their own paid-for address space and use their own
registered domains (at least temporarily registered) with working DNS
and records for DKIM and SPF authenticating that mail. The mail is
still spam.

>>It is certainly possible that the mail you see follows a different
>>pattern. I will refrain from calling you a frothing lunatic or
>>navel-gazing imbecile for that difference.
>
>Why not? That's exactly what I am.
>
>Along with Wietse, Noel, Ralf, Yahoo!, Google, Sendmail Inc, Cisco
>and all others who are adopting DKIM to prove the authenticity of
>their mail.

Which is a use orthogonal to the question of whether mail is spam.
Most spam today is still forged, but being forged is not
intrinsically related to whether mail is spam. Spammers were faster
to adopt SPF than regular mail senders and from what I can see, they
are adopting DKIM faster as well.

--
Bill Cole
billscconsult.com