D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] email

 

On Wed, 24 Jun 2009, Simon Waters wrote:

> Paul Hirst wrote:
>>
>> Has this actually happened to you? I've not seen this in several years
>> of using a 'catch all' domain for my email.
>
> As we provide website hosting at ZyNet, we often set up forwarding for
> the hosted domain.
>
> Until recently it was very common for domains with catch-alls to be
> sought out and spammed. I think this is less common, but it still
> happens with sufficient frequency I wouldn't rely on it. The main
> problem is once you use a catch-all people forget which addresses they
> have used, so when they are spammed they can't say "I only use x, y, z",
> and thus have to eat the backscatter.
>
> I don't know off hand how many domains we have left with a catch-all
> (I've been migrating folk away), but a significant proportion of domains
> with catch-alls get abused in a year.

More or less "Wot he said".

I host email for my customers, (and their customers), and I've been 
discouraging use of the catch-all for some time now. Mostly due to 
backscatter, but also due to the disk space it can suddenly load you with 
(and subsequent transfer time if you're sucking it via POP)

I have seen sites hit by dictionary attacks, and overnight, you've 
suddently got 15,000 emails waiting for you )-:

>> I find it rather useful as I can use a different email address for each
>> and every company I supply one to. Then if I start receiving spam on a
>> particular address I can just dump it to /dev/null using procmail.
>
> Typically you can also do this with either a "+" or "-" extension,
> depending on the mail server.
>
> i.e. simon+dcglug@xxxxxxxxxxxxxx delivers to simon@xxxxxxxxxxxxxx, but
> you can filter on the extension if and when needed.

And, er: gordon+dcglug@xxxxxxxxxx works for me :)

On a personal note, I more or less gave up caring if my email address was 
published or not, and just developed the tools and means to deal with it. 
I've had the same email address since 1995 now ... I use the + system for 
tracking, but the down-side of that is that 95% of all webshites have an 
email validation system written by some dick-head of a spotty nerd who 
thought he/she knew what email addresses look like and decided that plus 
signs were not valid. Probably the same one who decided that computers 
weren't designed to make our lives easy and insisted on credit cards being 
typed in as 16 consecutive digits without spaces. Jeez, it's one line of 
code to remove spaces. Fuckwits.

Right. I'll stop ranting now!

Gordon

-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/linux_adm/list-faq.html