And what protocol would you use to verify this?
The envelope on an SMTP message is very similar to an envelope on a postal message. How do you know that Joe is actually the person who put his return address on the envelope and dropped it into the postbox. Jane could have just as easily addressed the envelope and posted it, and you could not tell the difference.
I can send a message that looks very much like it came from Joe, even if I am Jane. You cannot believe any header on an SMTP message unless you verify it with trusted logs. The only headers I believe in messages I receive are my own networks, and possibly moving back from there, depending on the level of trust I have.
This becomes even easier if the message is able to be injected along the same path that a legitimate message would take.
One last point - if Joe "automatically" generated 50K responses on my network, he would be severely LARTed.
In reply to Re: Re: Re: Re: (OT) Fighting spam
by MidLifeXis
in thread (OT) Fighting spam
by Aristotle
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |