Somehow, yesterday I experienced a new form of email nonsense.
-
Ryan Castellucci :nonbinary_flag:replied to Ryan Castellucci :nonbinary_flag: last edited by
@tychotithonus @Sempf if they can't be bothered to decide whether they're going to accept it at that time
-
Ryan Castellucci :nonbinary_flag:replied to Royce Williams last edited by
@tychotithonus @Sempf hold the connection while validating at the next hop
(this is a bit ideological)
-
Ryan Castellucci :nonbinary_flag:replied to Ryan Castellucci :nonbinary_flag: last edited by
@tychotithonus @Sempf being less extreme, it's pretty safe to send a bounce if SPF and DKIM validate
-
Royce Williamsreplied to Ryan Castellucci :nonbinary_flag: last edited by
@ryanc @Sempf I mean, I get that, but in the meantime the blowback still hits the innocent non-sender. As a troubleshooter, I 100% hated silent discard, but as a spam fighter from back in the day, never doing that produced a whole bunch of busy work and harm that was impossible to work around otherwise. (Rejecting early in the connection was of course ideal!). But I've been out of this game for more than a decade ...
-
Royce Williamsreplied to Ryan Castellucci :nonbinary_flag: last edited by
-
@tychotithonus @ryanc I have learned more about SMTP in this conversation then I have in 25 years of fucking with it.
-
Ryan Castellucci :nonbinary_flag:replied to Royce Williams last edited by
@tychotithonus @Sempf the cursed thing here is that the sending side is silently discarding it
-
Ryan Castellucci :nonbinary_flag:replied to Bill last edited by
@Sempf @tychotithonus do you need a hug?
-
Billreplied to Ryan Castellucci :nonbinary_flag: last edited by
@ryanc @tychotithonus No, just a brain.
-
@Sempf @tychotithonus @ryanc is that what happens when you hit the age of the port number? Remind me to die before I hit 80 years old...
-
Ryan Castellucci :nonbinary_flag:replied to Erik Ableson last edited by
@erik @Sempf @tychotithonus I've forgotten more about HTTP than most people will ever know...
-
Billreplied to Ryan Castellucci :nonbinary_flag: last edited by
@ryanc @erik @tychotithonus I was gonna say, I spend most of my time at 443 so I'm probably ok there.
-
DrScripttreplied to Ryan Castellucci :nonbinary_flag: last edited by
@ryanc @tychotithonus @Sempf well it might, but it won’t be your server sending the back scatter.
The server you refused to accept the message from us coulpable for the backscatter. Maybe it shouldn’t have accepted the message in the first place.
-
DrScripttreplied to Ryan Castellucci :nonbinary_flag: last edited by
@ryanc ask them for a PCAP.
If they successfully sent and you never got as much as a SYN, then someone’s got a monkey in the middle.
Are any ISPs intercepting outbound port 25 instead of filtering it?
-
I'm interested in minimizing ecosystem harm / impact, even if I'm not the direct / attributable source. In the worst case, if I know that an upstream hop is going to generate backscatter if I reject in my DATA phase, and I know with high confidence that the content is spam, and I know that that upstream hop is not likely to change their ways any time soon ... it's a net lessening of ecosystem harm if I silently discard, rather than indirectly "trigger" predictable backscatter.
Yes, I know this is idealistic.
-
Ryan Castellucci :nonbinary_flag:replied to Royce Williams last edited by
@tychotithonus @drscriptt @Sempf I think we can agree this is a case of choosing amongst bad options, but don't think either of us are going to change our mind about which is worse.
Besides, I'm the one who patched their mail server to allow for customized fake rejects.
-
Ryan Castellucci :nonbinary_flag:replied to DrScriptt last edited by
@drscriptt they're not going to have a pcap, and I have mine as I said
-
cR0w :cascadia:replied to Ryan Castellucci :nonbinary_flag: last edited by
@ryanc @tychotithonus @drscriptt @Sempf
Me: I run my own mail server. I know what I'm doing.
Me later: reads this thread
Me now: Okay, y'all are awesome and I'm a noob again. And that's so cool.
-
@cR0w @ryanc @tychotithonus @drscriptt Exactly this.
-
Royce Williamsreplied to Ryan Castellucci :nonbinary_flag: last edited by [email protected]
@ryanc
I think we agree more than we disagree! Especially when it it is probably better for the ecosystem for the systems causing harm to be the explicit source of that harm, so that the ecosystem will start to respond to it appropriately. So I'm basically arguing myself out of silent discard even in my idealistic case!
@drscriptt @Sempf