|
|||||||||||
|
Re: [Asrg] Re: Receiver Initiated Authentication
From: Michael Kaplan <michaelkaplanasrg(at)gmail.com>
Date: Mon Sep 17 2007 - 11:52:35 EDT
Yes, in section 9 I summarize the Ironport data on the bounce problem, and
it is a real problem.
Indiscriminate bounces are the real problem with bounces. In section 9 I demonstrate what would happen if 50% of the global email population used RIA and 4% of incoming spam was bounced. The conclusion is that the average user will receive a 0.2% increase in 'spam' volume. Some individuals/entities will suffer a DDoS attack as their domains are heavily spoofed by spammers. In this worse case scenario RIA will increase their email volume by only 5% despite having 50% global participation in RIA. Again the real problem with bounces is indiscriminate bouncing, highly selective bouncing is relatively inconsequential. 50% of the global population would have near perfect protection from spam in exchange for only a slight increase in erroneous bounces.
If whatever
Any email that gets an SPF FAIL will never be bounced. You never send spammy email, and all of your email is already authenticated. You will never even be aware of the existence of RIA as your emails will never be bounced. You need never use a sub-address, or you can use a deactivated sub-address - it really doesn't matter since your emails are unambiguously ham so they will always directly reach the inbox. Almost all email sent by individuals is unambiguously ham; most individual senders will remain completely unaffected by RIA.
But I'm far from confident that that's the case, there are dubious
This is good; RIA will never block authenticated email from reputable senders. RIA will almost exclusively impact the less responsible senders who do not authenticate and also get a poor rating via a statistical filter. > Existing SPF cannot authenticate forwarded email. > [RIA] Bounces will not be sent to an SPF FAIL. See section 9 as to the impact on innocent third parties.
If innocent third parties without BATV or without SPF PASS/FAIL
If you (and 50% of the global email population) instituted RIA and subsequently became almost completely spam free, could you then live with the fact that non-participants in RIA and non-participants in BATV will suffer an average of a 0.2% increase in spam volume? Yes, a very small number of individuals will suffer a 5% increase in erroneous bounce traffic. 50% of the email population living spam free would be an extraordinary thing; I for one would be willing to live with the guilt.
Thank you for you input,
Asrg mailing list Asrg@ietf.org https://www1.ietf.org/mailman/listinfo/asrg Received on Mon Sep 17 11:53:26 2007 This archive was generated by hypermail 2.1.8 : Mon Oct 29 2007 - 14:15:56 EDT |
||||||||||
|
|||||||||||