Why so much Hotmail spam lately (was Re: [Mimedefang] Adding support for learning our addresses)

David F. Skoll dfs at roaringpenguin.com
Tue Jan 31 09:57:58 EST 2006


Replying to myself...

I think the reason lots of spammers are abusing Hotmail is this
note in our incident report:

     SPF query returned 'pass'

Hotmail publishes SPF records, and I guess spammers hope that a "pass"
will help their mail get through.  I've evolved my thinking on SPF so
I use it as follows:

- For domains that I do not control, I add 5 points for "fail" and 2
  for "softfail".  I never subtract points; I think it's highly dangerous
  to subtract points unless you control the domain.

- For domains that I do control, I subtract 2 points for "pass".  I don't
  add points for fail or softfail, though I guess that wouldn't be dangerous.

Regards,

David.



More information about the MIMEDefang mailing list