[Greylist-users] Possible Enhancements

Jason 'XenoPhage' Frisvold friz at godshell.com
Mon Jan 24 18:46:09 PST 2005

James J Dempsey wrote:

>There are lots of spam where the from: field lists a valid user on a valid
>host with a valid MX record.  It just happens to be someone whose name has
>been hijacked for this purpose, not the actual spammer.  This is often
>called a Joe-job.

Yeah..  But the general rule of thumb is that you don't trust the From: 
address..  So..  The only way to accomplish this would be to use the IP 
address of the incoming connection.  Reverse lookup, MX, and callback..  
Might be a bit much, but theoretically it shouldn't be a frequent 
operation.  Once a mailserver has "proven" itself, there's no need to 
look it up again...

>In this case, or in cases where the spammer simply uses "From:
>fill-in-the-blank at yahoo.com", this technique would completely  eliminate the
>effectiveness of greylisting.  Unless I'm not understanding your proposal properly.
