Mailing List SIMS@mail.stalker.com Message #14381
From: Alex von Thorn <avt@worldhouse.com>
Subject: Re: rbl troubles
Date: Sun, 28 Mar 2004 22:26:03 -0500
To: SIMS Discussions <SIMS@mail.stalker.com>
From their FAQs, SORBS appears to be one of the RBLs which block innocent third parties. As such, they will generate false positives. So you can't assume the ISP has any control over what SORBS puts in its database.

As for your own mail server, false positives should be a strong indication of an RBL that you should avoid using.




At 11:50 AM -0500 28 3 04, Charles Mangin wrote:
one of my clients is on a sketchy rural ISP that has managed to get itself - its entire /32 netblock - listed on sorbs (http://www.dnsbl.us.sorbs.net/)

normally not a problem for someone using my server for smtp, but it means my clients couldn't send me email from their home account. so i took sorbs off my rbl list for a week and sent the ISPs tech support and admin addresses a note about getting de-listed.

now i appreciate sorbs even more than before. my personal account, with a normally low spam load, got slammed for a week. i have a half dozen other rbls in my list, and they're doing their part, but sorbs seems to be blocking the lion's share.

after the week, sorbs still had the netblock listed, so i put it into my "client host addresses" list. yay, they can send me mail again.

but, doesn't this also mean that anybody in that netblock can use my server to relay? according to sorbs, the only offense these guys are guilty of (so far) is sending to a spamtrap somewhere - no open relays, zombies, etc. but the last thing i want to do is get *my* server listed because someone discovers this hole and starts spewing indiscriminately. normally, i think i'd list only the IPs from the MX records of the ISP, but none of the email i've gotten from these guys has come directly from the MX, but from some other ips in the same netblock.

any suggestions on how to lock this down better?



             charles mangin | Alpha Geek and Chief Mental Hygienist
        option8@option8.com | What's that watermelon doing there?
     http://niftee-tron.com | http://mentalhygiene.com


#############################################################
This message is sent to you because you are subscribed to
 the mailing list <SIMS@mail.stalker.com>.
To unsubscribe, E-mail to: <SIMS-off@mail.stalker.com>
To switch to the DIGEST mode, E-mail to <SIMS-digest@mail.stalker.com>
To switch to the INDEX mode, E-mail to <SIMS-index@mail.stalker.com>
Send administrative queries to  <SIMS-request@mail.stalker.com>


--
Alex von Thorn http://worldhouse.com/alex
Ad Astra Program Operations http://www.ad-astra.org
Cascadia Con Programming http://www.cascadiacon.org
journal http://blog.worldhouse.com/

Note: my main computer is temporarily offline as of 19 Mar 04.
Call me or email me again if you need something from me.
Subscribe (FEED) Subscribe (DIGEST) Subscribe (INDEX) Unsubscribe Mail to Listmaster