Announcement

Collapse
No announcement yet.

If You Don't Want to be Taken for a Spammer, Don't Behave Like a Spammer

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • If You Don't Want to be Taken for a Spammer, Don't Behave Like a Spammer

    Part of my job is moderating our customer email listserv. It is hosted at a third party non-for-profit free service. I'll call them Host.

    A few months ago one of my long-standing subscribers, Jane, who works at a school system in Ontario, had some trouble posting emails to the list, yet she was still receiving emails. I checked for the most common cause and sure enough, her school had changed everyone's email address by two letters, then their network admin set it up so messages sent to the old address were automatically forwarded to the new one.

    She was getting messages at the new address because they were bering forwarded. But couldn't post because our list is closed and the list software didn't recognize her new address. It's not a huge deal. I just unsubbed Jane's old address and subbed the new one for her.

    Then a few weeks ago Jane tried to post a message and couldn't. She asked me to check again to make sure the correct address was subbed. It was. She tried again, still no dice. She mentioned a bounce message so I asked her to expand the headers and send it to me.

    I'm not a network admin and I don't pretend to be. So took the bounce message down to our network admin so he could look at it. The bounce message came from Host and explained that her email was rejected because a mismatch was found between the server name and the IP address after a DNS lookup.

    In non-technical terms, the school's outgoing email is configured with a spoofed IP address. Since there's no LEGITIMATE reason to spoof where your email comes from, Host's filters are rejecting her email as spam.

    I assumed their network administrator wasn't aware they had that problem. So I was happy to pass along the diagnosis and tell her that the problem would be fixed once they had reconfigured their email server to stop acting like a spam server.

    Ha! She had been previously doing this by email, but that prompted a phone call. She wasn't nasty or anything but she filled me in on several things:

    1. Bob, her network admin, had set that up deliberately as security measure. He's hiding their real IP address as a security measure.

    2. Bob, her network admin, INSISTS that this is a normal setup for "big" organizations" like the school system and that everyone else does it the same way.

    3. Bob, her network admin, has heard complaints from his users about the fact that they can't send emails to half the planet. He solidly places responsibility for that failure on the recipients' shoulders. All they need to do is add his spoofed IP address to their white list.

    I'm not a network admin and I don't pretend to be one, but even I can see the obvious logic flaws.

    I didn't argue point 1. People are free to use whatever weird ass setup they want. It's not my job to tell them how to configure their mail server.

    I did argue point 2. We have many susbcribers to our list from instititutions of varying sizes. NONE of them spoof IP addresses. The only people who do, in my experience, are people who are up to no good: spammers and scammers. I didn't get anywhere because I was talking with the user not the network admin. She was choosing to take Bob's word as gospel, but otherwise she was just a frustrated person caught in the middle. It wasn't her fault and she had no control over the situation. I stated my arguments quickly in the hope that she might talk sense into her network admin, but I dropped it when she resisted.

    Point 3 was interesting. It technically would work provided that the recipient maintained an IP address white list AND was willing to add a deliberately spoofed IP address to their white list. I doubt very much that any organization, not to mention a free service, would want to expend resources adding spoofed IP adresses to their white list. It's completely asinine to expect the rest of the freaking world to do that just so they can have the "privilege" of getting emails from that one school system.

    Nevertheless, Jane had been trying to contact Host to ask them to do this, but, of course, her emails were bouncing back to her.

    So Jane begged me to ask Host to whitelist her spoofed IP address on her behalf. Since the request itself was harmless enough, I agreed.

    Of course I didn't want to look like an idiot, so I merely passed along her email and explained that it came from a subscriber who was having trouble emailing and asked me to pass it along for her. There was no further comment.

    I honestly didn't expect a response so quickly. As a FREE not-for-profit service, Host is staffed by volunteers and they respond only when absolutely necessary. Hey, if we don't like it, we can get a refund, right?

    Apparently they found it too ridiclous to let it go without a response. The stated point blank that the mail server would need to be reconfigured or they wouldn't accept emails from it. The best line was:

    "RFC requires proper DNS records on all internet-facing IPs, let alone those which claim to be legitimate mail servers." [Note: RFC refers to internet standards]

    I emailed Jane with slightly different wording and let her know that she would either have to convince Bob to follow internet standards or she could subscribe from another email address that followed them. I have not heard back from her.

    I emailed Host back to let them know I agreed with them and thank them for their response. I couldn't, however, resist letting them know their Jane's network admin had set it up that way on purpose and wouldn't change it.

    I got another awesome response:

    It started with, "Wow" and ended with "This guy sounds like someone who sets up Exchange and thinks he knows what a mail server is. "
    Last edited by Dips; 02-20-2009, 09:05 PM.
    The best karma is letting a jerk bash himself senseless on the wall of your polite indifference.

    The stupid is strong with this one.

  • #2
    Ow. My brain. What kind of network admin wants to make their network look line a SPAM group on purpose?

    Comment


    • #3
      Quoth mattm04 View Post
      Ow. My brain. What kind of network admin wants to make their network look line a SPAM group on purpose?
      One who shouldn't be in charge of anything more technologically advanced than an Etch-A-Sketch.
      Knowledge is power. Power corrupts. Study hard. Be evil.

      "I never said I wasn't a horrible person."--Me, almost daily

      Comment


      • #4
        Quoth Irving Patrick Freleigh View Post
        One who shouldn't be in charge of anything more technologically advanced than an Etch-A-Sketch with broken knobs.
        edited for my amusement
        This is a drama-free zone; violators will be slapped. -Irving Patrick Freleigh
        my blog:http://steeledragon.wordpress.com/

        Comment


        • #5
          Quoth Irving Patrick Freleigh View Post
          One who shouldn't be in charge of anything more technologically advanced than an Etch-A-Sketch with broken knobs and a fucked-up screen.
          You still didn't go quite far enough.
          Knowledge is power. Power corrupts. Study hard. Be evil.

          "I never said I wasn't a horrible person."--Me, almost daily

          Comment


          • #6
            Quoth Irving Patrick Freleigh View Post
            One who shouldn't be in charge of anything more technologically advanced than an Etch-A-Sketch with broken knobs, no eraser sand, and a fucked-up screen.
            And for the hat trick.
            I AM the evil bastard!
            A+ Certified IT Technician

            Comment


            • #7
              Quoth lordlundar View Post
              And for the hat trick.
              One who shouldn't be in charge of anything more technologically advanced than an Etch-A-Sketch with broken knobs, no eraser sand, a fucked-up screen and that is invisible.
              Otaku

              Comment


              • #8
                I can go one better, than all of you.

                He shouldn't be in charge of anything more technologically advanced than a pencil and paper. Also the pencil has no lead
                Under The Moon Paranormal Research
                San Joaquin Valley Paranormal Research

                Comment


                • #9
                  Pfft. You're all losers. "Blah blah blah advanced than grass and spit."
                  Ba'al: I'm a god. Gods are all-knowing.

                  http://unrelatedcaptions.com/45147

                  Comment


                  • #10
                    You're just jealous that you didn't get in it earlier.
                    I AM the evil bastard!
                    A+ Certified IT Technician

                    Comment


                    • #11
                      wow just wow. I really need to update my resume and get a job like that. How is it so many incompetent net admins have decent jobs?

                      Comment


                      • #12
                        Quoth cawaker View Post
                        wow just wow. I really need to update my resume and get a job like that. How is it so many incompetent net admins have decent jobs?
                        MCSE mills
                        Lady, people aren't chocolates. D'you know what they are mostly? Bastards. Bastard-coated bastards with bastard filling. Dr Cox - Scrubs

                        Comment


                        • #13
                          CCNA Boot camps.
                          Fixing problems... one broken customer at a time.

                          Comment


                          • #14
                            Any further word back from Jane or the all-knowledgable Bob & His Spoofing Circus.
                            Regards,
                            The Exiled, V.2.0

                            "The world is indeed comic, but the joke is on mankind."
                            - H. P. Lovecraft

                            Comment


                            • #15
                              As someone who is frequently in your position in this odd triangle/rhombus of sorts, and sometimes even in the position of Host, my only thoughts on this can be summed up as:
                              LOL
                              Ne auderis delere orbem rigidum meum! - Don't you dare erase my hard disk!

                              This is Tech Support, not Customer Service.
                              What's the difference?
                              We're allowed to tell you "no".

                              Comment

                              Working...
                              X