On Mon, Jan 15, 2007 at 12:09:27PM +0100, Michael Menge wrote:
> If they resend the E-Mail like a real mailserver, or send a second
> mail with the same triple (sender , reciever, ip) then ther is no way
> to distinguish spam from ham. In near futute more spemmer will addapt
> to greylisting.
Sure they will, but with moderation. As I pointed some time ago,
maintaining the mail queue to manage resends costs resources. Of course
the resources are free for the spammer, since he uses someone else's
computer, but the free resources are finite.
The mail queue will grow with greylisting delays and with the amount of
sent spam. Once the spammer consumes all the available resources,
increasing the greylisting delay will lower the amount of spam sent.
Using very long delays is not possible, because users wants mail to go
be quickly delivered. This is where you can use variable delays
depending on the sender's reputation, using DNSRBL or other means.
--
Emmanuel Dreyfus
manu@...