Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


November 17, 2004

Blacklists: Readers Respond


RSS
View this exclusive article with VIP access -- click here to join |
See More Security Articles Here | Reprints | Or sign up for our VIP Monthly Pass!

Last week, I wrote about how blacklists can help an email filter detect junk mail and thus reduce the amount of junk that reaches your inbox. Several readers responded, and this week I'll share some of their perspectives because they make good points that everyone should be aware of.

Small-business owner Evan Ross wrote that he thinks blacklists are a bad idea. He said, "We had an issue last year where Spamhaus blacklisted my ISP due to . . . another one of their customers sending spam. We were prevented from sending mail to some of our customers for up to four weeks. In direct conversations with Spamhaus, I did not find them at all responsive. I felt that they were vigilantes that held me hostage."

Stephen Canale, from the mail-filtering outsourcing company OnlyMyEmail, expresses similar sentiments, writing that blacklist providers "are not particularly responsive to correcting listing errors and generally don't mind creating collateral damage. Some even encourage this as a way to put pressure on ISPs and other hosts. Spamcop is pretty straightforward about this, saying 'The SCBL is aggressive and often errs on the side of blocking mail.' The only way to accurately stop spam without significant false positives is to use out-sourced services such as ours." OnlyMyEmail filters out junk mail and malware for individual users or entire domains.

I think these services work well--otherwise they'd go out of business relatively quickly. But I don't agree that filtering services are the "only way to accurately stop spam." My desktop-based email filter that supports the use of blacklist services works well, and I'm sure most of you have similar results. A third reader, Joe Wein, wrote: "I wholeheartedly back your recommendation of the Spamhaus.org blacklists (SBL and XBL), with which we've had excellent results so far. Spamhaus is probably the single most valuable source of IP blacklist information available today."

Joe went on to say, "I would add some reservations concerning the SpamCop list though. While it catches a lot of spam, it has a much higher false positive rate than Spamhaus and even other services. SpamCop.net itself does not recommend using it for outright blocking: 'SpamCop encourages use of the SCBL in concert with an actively maintained whitelist of wanted email senders. SpamCop encourages SCBL users to tag and divert email, rather than block it outright.' http://www.spamcop.net/bl.shtml "

Joe had more to say about SpamCop: "SpamCop users frequently submit reports involving servers of their own mail accounts that are configured to forward mail to another account of theirs at a different provider, where mail is read. Because SpamCop does not follow the Received lines through [to] the real culprit, the servers of the auto-forwarding ISP end up getting listed instead of the spam source that hit the initial forwarding ISP."

Joe's next point was one that I probably didn't stress enough last week. "Because of its high [false positive] rate, the SpamCop list can only be used as one part of a scoring system, with a hit on the list weighted low enough so that false positives do not cause the loss of valid email." I think this principle should be employed when using any blacklist service.

Joe continued, "A good anti-spam solution should involve multiple strategies and combine the results, rather than relying on a single make-or-break test. A combination of IP blacklists, domain blacklists and content-based scoring (such as detecting known bulk email software and/or Bayesian filters) offers the best results overall. This multi-pronged approach has been used by SpamAssassin and also by our own desktop solution, jwSpamSpy. http://www.joewein.de/sw/jwSpamSpy/ "

Joe also informed me about another type of blacklist service, Spam Uniform Resource Identifier Realtime Blocklists (SURBLs), in which, according to the http://www.surbl.org/ Web site, "SURBLs are not used to block spam senders. Instead they allow you to block messages that have spam domains which occur in message bodies." Joe said that because of the way SURBLs work, "Spammers can switch Trojaned boxes and open proxies as much as they want. As long as they still advertise the same Web sites, they will get caught in the filter."

Joe continued, "My main advice for people running Web sites and mail servers who want to avoid ending up in IP blacklists (other than not spamming, of course) is to pick their [ISP and hosting service] well. Make sure [the provider has] a strong acceptable use policy (AUP) and [that they] enforce it. [Perform] some due diligence and don't just go for the cheapest offer. Otherwise your business could end up paying for the [mistakes] of others [in the event that] your [ISP and hosting service] get blacklisted. If you run any mailing lists, do make sure to use confirmed opt-in for all subscriptions. Sometimes people end up getting their domains listed on URL blacklists because they paid shady online marketing companies for sending bulk email. Just because someone claims to have an opt-in mailing list doesn't mean it actually is one. Check out how long they've been around and what kind of references to them you can find on the Web. Emails from a known spam source advertising a freshly registered domain are a big red flag for us. Therefore, do some research before you pay someone to do marketing for you, or you could harm your reputation."

The same holds true for your junk-mail-filtering solutions, whether you use one in-house or an outsourced service. Check them for functionality, accuracy, reputation, support, responsibility, then choose one wisely.

End of Article



Reader Comments
I use Spamhaus and a few others, quite successfully. My spam load is way down because of them. Spamhaus doesn't have a contract with Evan Ross. It has a contract with me, to provide me with a list of servers owned by companies hosting spammers.

What struck me as odd was that Mr Ross was contacting Spamhaus and expecting them to be responsive to him when he isn't their customer. Why wasn't he instead contacting his own ISP? Their decision to host a spammer directly resulted in the Spamhaus listing. Had Evan Ross contacted his ISP, the ISP could have very easily and quickly contacted Spamhaus to be delisted. They merely needed to confirm to Spamhaus that the spammer was no longer their customer. Evan Ross would have seen his mail delivered and been happy with his ISP's responsiveness, or he could have been complaining to you and others quite legitimately that his ISP is non responsive. And since he's spending money with them, his gripe would have been far more worthy of consideration. Mr Ross was in no position to tell Spamhaus that his ISP had terminated the spammer, so it isn't clear to me what response he could possibly have expected from Spamhaus, or what basis he has for complaining when that response failed to materialize.

I'll keep using Spamhaus, Spamcop, SORBS, SPEWS, and all the others that are currently protecting my servers.



Anonymous User November 17, 2004 (Article Rating: )


For anyone running MS Exchange 2000 or 2003 they would be remiss in their duties for not running a tiny, inexpensive ($99) little program called Open Relay Filter (ORF). It easily allows you to configure multiple BL servers and the reporting features are awesome. It goes far above and beyond what is built into EX2003 or most other filters I have seen.

The results of installing ORF was immediate and dramatic.

You can find ORF at www.vamsoft.com

It was the best $99 I've ever spent on ANY software product.

Ron


Anonymous User November 18, 2004 (Article Rating: )


Not sure what sort of small business Mr. Ross owns, but we'd recommend the Spamhaus blacklist to anyone in small business, it stops 90% of our incoming email - all of which seems to be spam! But then I guess he was not using it, but was hosting on an ISP that allowed spammers on for FOUR WEEKS?! It's ISPs like that which cause 90% of our email to be spam I supposed. Don't blame the food critic Mr. Ross, blame the restaurant serving you the spoiled fish.

Anonymous User November 20, 2004


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
CES 2009: Ballmer Announces Windows 7, Windows Live, Live Search Milestones

During his first-ever Consumer Electronics Show (CES) 2009 keynote address last night in Las Vegas, Microsoft CEO Steve Ballmer announced the pending public availability of a feature-complete Windows 7, the final version of Windows Live Essentials, and ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

Where is Microsoft NetMeeting in Windows XP?

...


Security Whitepapers The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Protecting (You and) Your Data with Exchange Server 2007

Related Events Security Summit

How IE7 & The New Extended Validation SSL Certificates Impact Your Site

Top 10 Email Security Challenges and Solutions

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2009 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing