[Esd-l] Spam Filtering

John D. Hardin jhardin at impsec.org
Wed Jul 31 06:56:01 PDT 2002

On Wed, 31 Jul 2002, Peter Hanecak wrote:

> 	# some SPAM hase "To" filed set to addresses like
> 	# Undisclosed.Recipients at our.gateway.com so I know for 
> 	# sure that this is some "To" faking in progress and 
> 	# message is SPAM, scum or something along that line

Another 100% rule is a blank or missing To: header.

> 4) notorious junk senders are placed in sendmail's access file
> with "ERROR:550 Spammers are banned from our site" and (if that
> control is effective) messages from then are not delivered to me
> (and colegues) anymore

I've been thinking about this for a while: there are open relay lists
(ORBS), does anybody do a similar known-bulk-mailer-ipaddress service?
SPABS maybe?

