I'm in the process of setting up a new server and I'm planning on
implementing both a 2-second greetdelay (to catch those bots that just
connect and spew) and greylisting (to catch those bots that send the
message only once) as methods of reducing deliverable spam accepted (I'm
already doing other things like user validation, so undeliverable spam is
already being rejected). I know that there are certain domains out there
that either don't play nice with greylisting because of round-robing
sending servers, send time-sensitive email (such as ebay), or
(occasionally) are not RFC compliant in waiting for the SMTP greeting
before issuing the HELO/EHLO. I also have a method of getting sender
lists from senderbase.org for individual domains, which can then be used
to populate the tcpserver file to disable the greetdelay and/or
greylisting features.
The question is, who do I need to exclude, and from which features? I
know that ebay should probably be excluded from greylisting, and IIRC ebay
and/or paypal need to not have a greetdelay, though I'm not positive on
that. And I think I've heard someone mention yahoo among others for the
multi-outbound-server problem. So, who do people suggest I exclude, and
from which feature should I exclude them (greetdelay, greylisting or
both)?
Once I get a list put together, I'll probably start hosting it an updating
it as more info comes in...
Josh
--
Joshua Megerman
SJGames MIB #5273 - OGRE AI Testing Division
You can't win; You can't break even; You can't even quit the game.
- Layman's translation of the Laws of Thermodynamics
qmail@honorablemenschen.com
|