Home  › Email › Email Marketing

MAP is Spam’s Simple Answer

  |  November 21, 2003   |  Comments

Steven Trupp says that current spam propogation measures are so primitive that a simple piece of software can solve most of the problem.

Steven Trupp, president of Bohemia, NY-based ICS Network Systems, has been observing the spam problem for some time. The company’s Mail Sentry Gateway service, which provides anti-spam, anti-virus, and anti-relay protection for corporate networks, processes a great deal of email traffic. Of necessity, it built its own spam fighting solution.

The company’s Mail Authentication Protocol (MAP) simply checks to see whether an email received at a server with the MAP milter plugin has a valid sender address. MAP validates the complete sender address at the MX host for the sender’s domain (or the domain’s A record host if no MX record is published).

On November 13, 2003, for a typical client, MAP rejected about 50 percent of the company’s mail (presumably letting some spam through). Of that, 31 percent was rejected because the MX host for the sender’s domain confirmed the sender’s address was false. 26 percent of rejected mail was forged as coming from Hotmail, Yahoo, MSN, or AOL. Another 26 percent was rejected because MAP could not connect to an SMTP server at the sender’s domain. 11 percent of rejected mail was blacklisted. The remaining 6 percent was on hold due to various errors, possibly benign, returned by the MX host.

Trupp says the mail catches the vast majority of spammers, who are not willing to include a valid sender address in their spam. "You cannot just use any fake email address appended to a valid domain to get around MAP," he says. He adds that spammers find that faking email addresses gets around a surprising number of filters.

Trupp says that traditional anti-spam measures are being foiled by proxy spam. Whether individuals are actually being paid to spam from their home accounts, or whether their home accounts and PCs have been taken over, he does not know, but he suspects the former. He is certain that a significant amount of spam now comes from home PCs running their own SMTP engine. The source IPs are clearly those assigned dynamically to individual subscribers by the large broadband providers, especially cable ISPs. This new source of spam is increasing at an alarming rate.

Because spam has changed from being a high-volume, single source problem to being a small-volume, multi-source problem, traditional blacklists don’t work anymore. Spammers no longer send from their own domain. "Spammers are soliciting people to work from home for money," he says. And in the current economy, he believes many would accept the offer.

MAP includes whitelist and blacklist features. Trupp says whitelists are useful, but users sometimes get frustrated with the blacklists. He says that spam coming off the cable networks has a valid, dynamic IP address. Blacklisting that IP address has little or no effect on spam. "Some customers get frustrated because there’s stuff they don’t want to see, so they add 800 IP addresses to the blacklist in the first week, and it doesn’t change much."

Nevertheless, some high-volume spammers still exist, and they will be frustrated by MAP. "Some spammers will send 1,000 emails in a single connection and use multiple connections. If the spammer has not provisioned an MX host that can actually receive a return email, each time he connects and I connect back to the MX host to verify an address, he waits 20 seconds for MAP to time out. Spammers face the same penalty that I’m incurring by checking them."

After implementation, Trupp advises customers to wait for several days collecting statistics on how the MAP engine handles the customer’s traffic. The MAP engine will probably be blocking some mail it shouldn’t.

Customers need to learn which mail types need special treatment. "If someone’s using Monster.com for recruiting, they may need to whitelist the address that receives the mail about monster.com because a lot of it will come from domains other than Monster, such as AOL."

MAP’s future seems to lie in becoming a component of another anti-spam solution, or a complement to several. Blocking forged mail pretending to come from large, known ISPs could be a business by itself, and is a useful idea.

Pricing and availability
MAP is available now directly from ICS as a milter plugin (pricing not public at press time) or as a component of the company’s Mail Sentry Gateway service.

The price for Mail Sentry Gateway is $250 for up to 50,000 messages per month. Trupp says that since the software relies on his servers, he has to charge based on his costs. "We’ve had no pushback from customers since we switched from per-user to per-message pricing, even from customers whose invoice amounts tripled."

ClickZ Live Chicago Join the Industry's Leading eCommerce & Direct Marketing Experts in Chicago
ClickZ Live Chicago (Nov 3-6) will deliver over 50 sessions across 4 days and 10 individual tracks, including Data-Driven Marketing, Social, Mobile, Display, Search and Email. Check out the full agenda and register by Friday, August 29 to take advantage of Super Saver Rates!

ABOUT THE AUTHOR

David Daniels

For more than 20 years, David has been an industry proponent. Direct Magazine said David is "one of the most influential experts in email marketing, if not the most influential." Co-author of "Email Marketing An Hour A Day," David has held senior level positions at Forrester and JupiterResearch, Apple, Anthropologie, MacWarehouse, Proteam, and retailers that dotted the early days of CompuServe. David advises many industry organizations including the OTA, DMA, eec, and has been a contributor to the Weekend Today Show on NBC. Learn more about connected marketing and download free research with registration here. Follow David on Twitter @emaildaniels and learn more at www.relevancygroup.com.

COMMENTSCommenting policy

comments powered by Disqus

Get ClickZ Email newsletters delivered right to your inbox. Subscribe today!

COMMENTS

UPCOMING EVENTS

Featured White Papers

IBM: Social Analytics - The Science Behind Social Media Marketing

IBM Social Analytics: The Science Behind Social Media Marketing
80% of internet users say they prefer to connect with brands via Facebook. 65% of social media users say they use it to learn more about brands, products and services. Learn about how to find more about customers' attitudes, preferences and buying habits from what they say on social media channels.

Marin Software: The Multiplier Effect of Integrating Search & Social Advertising

The Multiplier Effect of Integrating Search & Social Advertising
Latest research reveals 68% higher revenue per conversion for marketers who integrate their search & social advertising. In addition to the research results, this whitepaper also outlines 5 strategies and 15 tactics you can use to better integrate your search and social campaigns.

Resources

Jobs

    • Marketing Technology Analyst
      Marketing Technology Analyst (Alfred Music) - Van NuysMarketing Technology Analyst DEFINITION Under the general/direct supervision of the head of...
    • Chinese Speaking Copywriter
      Chinese Speaking Copywriter (Agora Financial) - BaltimoreDo you speak Chinese? Are you interested in economics and finance or want to learn more...
    • Video/Digital Media Designer
      Video/Digital Media Designer (Confidential) - Delray BeachFull service corporate video production studio looking to hire a creative, and highly...