Spam

Martin Keegan mk270 at cam.ac.uk
Wed, 9 Oct 2002 13:15:41 +0100 (BST)


On Wed, 9 Oct 2002, Ken Brown wrote:

I presume the spammers "forge" (which I think is too strong a word) the
From: headers so as to reduce the efficacy of particular anti-spam
strategies by increasing the false positives?

> I suppose what we need to do is intercept mail coming in from outside
> that has a header that seems to be from within our system and append a
> "this message appears to be forged" disclaimer to it.  I wonder if spam
> assassin can do that?  I suppose I could write it myself but the chance
> of embarrassing failure is large.

This is a disaster - they do something like this at Cambridge University's
Engineering Department: if you have an @cam.ac.uk email address but aren't
mailing from within the University (e.g., from your cablemodem), then the
mail is bounced on entry to the eng.cam.ac.uk mailservers. I can see
exactly why they do it, though.

Mk