Who are the Earliest Adopters of SPF? Survey says: Spammers!   - 1,374 Views, 3 Comments

Summary: A survey of nearly 2million pieces of email by security company CipherTrust revealed some interesting facts: 1. Only 5% of the email came from servers which had enabled either SPF or Sender I.D. authentication. 2. Of the email coming from servers with SPF ...

Previous Article « War Driver Gets Whacked by CAN-SPAM
Read Next Article » For Sale: Your Email Address. Serious offers only. Inquire at Advocacy, Inc.

  Follow Anne on Twitter     Friend Anne on Facebook

A survey of nearly 2million pieces of email by security company CipherTrust revealed some interesting facts:

1. Only 5% of the email came from servers which had enabled either SPF or Sender I.D. authentication.
2. Of the email coming from servers with SPF or Sender I.D. enabled, more than half was spam.

Spammers are early-adopters. Who knew?

Well, only anybody who has ever observed how quickly spammers latch on to any new technology designed to ease delivery of email. It’s no secret.

CipherTrust then went on to say that this demonstrates that sender authentication such as SPF will do nothing to stop spam.

No kidding!

It was never intended to stop spam. Nobody ever said that it would stop spam.

The purpose of SPF and Sender I.D., and Domain Keys, and on and on, is to be able to demonstrate that the domain from which the email is purportedly being sent is not being spoofed. That it’s really who it says it is. SPF et al say nothing about what sort of email it is. Never has, never will.

And, Aunty would suggest that the fact that it’s showing up in spam means, in fact, that it’s working. How handy to be able to track a spam back to its true IP address and domain of origin!

Related link here.

Who are the Earliest Adopters of SPF? Survey says: Spammers!

 Follow Anne on Twitter

 Twitter Explained in Plain English

 Friend Anne on Facebook

Previous Article « War Driver Gets Whacked by CAN-SPAM
Read Next Article » For Sale: Your Email Address. Serious offers only. Inquire at Advocacy, Inc.

Read more:

»  Please Help Aunty by Taking This Reader Survey

»  Survey Says…!

»  Anti Spammers are Lamers, Says Spammer

»  Have Sex or Search the ‘Net? The Choice is Clear

For additional similar stories check out our archives on Everything Else

NOTE: We never, ever, ever will recommend any product or service on this site that we have not regularly used ourselves and do not wholeheartedly believe in. That said, in some cases after being very pleased with a product or service, we may enter into a relationship with the provider of that product or service such that if someone purchases that product or service based on our recommendation, we may get a small payment. Such payments go towards the upkeep of the Internet Patrol.

 

3 Comments »

  1. Hi Anne — got the link for that story?

    Comment by Justin — 8/31/2004 @ 4:26 pm

  2. Oops, a thousand pardons. Here it is:

    http://www.infoworld.com/article/04/08/31/HNspammerstudy_1.html

    Comment by Aunty Spam — 9/1/2004 @ 8:41 am

  3. The article neglects to mention another set of early adopters: sites whose domain names have been repeatedly forged in spam.

    I handle the email abuse reports for my employer, and for the past year I’ve gotten several complaints a week. To date, not a single one has been over a message that actually came through our network or from our customers. We put up SPF records last December, but since hardly anyone checks them, it hasn’t stemmed the tide of misdirected complaints.

    Another missing piece of information is the percentage of email that actually *fails* SPF checks. So they found that 3.8% of spam passes and 2.8% of legit mail passes. That’s disheartening, but SPF is pass/fail/neutral, not just pass/fail. What if 10% of spam *fails* and only a tiny amount of legit mail does? If that’s the case, then it’s already proving useful. But without those numbers, there’s no way to tell.

    Comment by Kelson — 9/1/2004 @ 9:15 am

RSS feed for comments on this post. TrackBack URI

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


If you have not posted a comment here before, we apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day! You only need to do this once; once you have successfuly posted a comment here you will not be asked to do this again. Thank you for your understanding!

 
 This article first appeared on 8/31/2004
The Internet Patrol
Patrolling the Internet for You!