hacking security forum

Re: [Full-Disclosure] Implications of outsourcing email

From: <Valdis.Kletnieks@vt.edu>
Date: Mon Dec 08 2003 - 15:08:36 CST

On Mon, 08 Dec 2003 15:01:59 EST, MaxPageant@aol.com said:

> Question: Why don't more companies do this to authenticate their commercial
> opt-in email????

Chicken. Egg.

Not enough companies do that to make it worth checking for. For that matter,
even at this site our outbound mail doesn't emit from anything that our MX
points at (for a good reason - our MX's point at stuff optimized for catching
inbound mail, the outbound gate is set up to do outbound).

In any case, if I was outsourcing a mailing to 500K or 1M people (and companies
like Microsoft could easily have *legitimate* customer lists of 50M or more),
the *LAST* thing I'd want is for the outsourcing company to funnel all 1-50M
pieces of mail through my outbound gateway - that leaves *ME* sitting on all
the stuff that gets queued up rather than leaving it sitting on the outsourcing
company's server.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

Received on Mon Dec 08 15:42:30 2003

This archive was generated by hypermail 2.1.8 : Mon Dec 08 2003 - 16:01:02 CST