Hi all,
One very effective but rarely implemented trick is to put in a 1 second delay before the SMTP greeting.
Botnets do not wait for 1 second, they post their whole spam in one shot. Then the mail server says its ready and they've already gone. 1 second is not much of a delay, so no real risk of timeouts.
It's a nice alternative to greylisting. It gets rid of the botnets, which is what greylisting is really for. Greylisting is no use if the spam is coming from a real mail server.
We do use greylisting at Manukau Institute of Technology and it's great. No complaints from the users in almost 6 years.
We do it based on /24 ranges which is less of a problem that unique IPs and we have built up a large database.
We don't bounce based on SPF (unless specified in DMARC policy) as so many people have their SPF records set up incorrectly. We just mark as spam for that.
Best Regards,
Stephan Hughson | Technical Architect
Private Bag 94006, Manukau, Auckland 2241
p: 09 968 7611 | m: 027 568 7611 | w: manukau.ac.nz
________________________________
From: nznog-bounces(a)list.waikato.ac.nz [nznog-bounces(a)list.waikato.ac.nz] on behalf of Glen Eustace [geustace(a)godzone.net.nz]
Sent: Wednesday, 5 April 2017 3:08 p.m.
To: Damian Kissick
Cc: nznog(a)list.waikato.ac.nz
Subject: Re: [nznog] Xtra and SPF
On 5/04/2017, at 2:21 PM, Damian Kissick