Aunty Spam's
Slam a Spammer Blog

Home RSS Archives Aunty's CAN-SPAM eBook with FREE pdf! Spam & the Law Conference Add to My Yahoo! Subscribe with Bloglines
SEND A QUESTION OR COMPLIMENT TO AUNTY! BE SURE TO ADD THE .com AT THE END!

August 31, 2004

Who are the Earliest Adopters of SPF? Survey says: Spammers!

Posted 1 year, 1 month ago on August 31, 2004
A survey of nearly 2million pieces of email by security company CipherTrust revealed some interesting facts:

1. Only 5% of the email came from servers which had enabled either SPF or Sender I.D. authentication.
2. Of the email coming from servers with SPF or Sender I.D. enabled, more than half was spam.

Spammers are early-adopters. Who knew?

Well, only anybody who has ever observed how quickly spammers latch on to any new technology designed to ease delivery of email. It's no secret.

CipherTrust then went on to say that this demonstrates that sender authentication such as SPF will do nothing to stop spam.

No kidding!

It was never intended to stop spam. Nobody ever said that it would stop spam.

The purpose of SPF and Sender I.D., and Domain Keys, and on and on, is to be able to demonstrate that the domain from which the email is purportedly being sent is not being spoofed. That it's really who it says it is. SPF et al say nothing about what sort of email it is. Never has, never will.

And, Aunty would suggest that the fact that it's showing up in spam means, in fact, that it's working. How handy to be able to track a spam back to its true IP address and domain of origin!

Related link here.

The trackback url for this post is http://www.aunty-spam.com/bblog/trackback.php/88/

Re: Who are the Earliest Adopters of SPF? Survey says: Spammers!

Posted 1 year, 1 month ago by Justin • • wwwReply

Hi Anne -- got the link for that story?

Trackback URL : http://www.aunty-spam.com/bblog/trackback.php/88/305/

Re: Who are the Earliest Adopters of SPF? Survey says: Spammers!

Posted 1 year, 1 month ago by Aunty Spam • • • Reply

Oops, a thousand pardons. Here it is: http://www.infoworld.com/article/04/08/31/HNspammerstudy_1.html

Trackback URL : http://www.aunty-spam.com/bblog/trackback.php/88/306/

Re: Who are the Earliest Adopters of SPF? Survey says: Spammers!

Posted 1 year, 1 month ago by Kelson • • wwwReply

The article neglects to mention another set of early adopters: sites whose domain names have been repeatedly forged in spam. I handle the email abuse reports for my employer, and for the past year I've gotten several complaints a week. To date, not a single one has been over a message that actually came through our network or from our customers. We put up SPF records last December, but since hardly anyone checks them, it hasn't stemmed the tide of misdirected complaints. Another missing piece of information is the percentage of email that actually *fails* SPF checks. So they found that 3.8% of spam passes and 2.8% of legit mail passes. That's disheartening, but SPF is pass/fail/neutral, not just pass/fail. What if 10% of spam *fails* and only a tiny amount of legit mail does? If that's the case, then it's already proving useful. But without those numbers, there's no way to tell.

Trackback URL : http://www.aunty-spam.com/bblog/trackback.php/88/307/

Add Comment

( to reply to a comment, click the reply link next to the comment )

 
Comment Title
 
Your Name:
 
Email Address:
Make Public?
 
Website:
Make Public?
 
Comment:
 
 
 

Recently

Vote for Whomever You Want...
Gaping Security Hole a Pain...
Make Your C*ck a Hammer...
Nigerian 419 Spam: The Video
No More Free Outlook...

Aunty Spam Provided By ISIPP

CAN-SPAM Teleseminar 5/6/04
CAN-SPAM Teleseminar 5/13/04
Spam & the Law Conference 7/29/04
CAN-SPAM Compliance Pack

Other Blogs & Sites

Fun Anti-Spam Novelty Products
The Spam Blog
Spam Primer
Ask Leo
DadsRights.org




Slam a Spammer
Store!
Powered by bBlog