« SpamSentinel Now Blocks Spam at the SMTP Level | Main| No Backscatter for Lotus Domino Project »

SpamSentinel Stops Backscatter

Tags:
7.25

Although backscatter is not spam, many of our Lotus Notes customers complain about it to us, as they know we can be pretty creative when stopping unwanted email.  I'll admit that this one had us stumped for a few weeks.  We tried to find a way to distinguish between a backscatter email and good mail.  Backscatter is a common issue at the moment. What happens is that the spam sender forges the return address so that it points to you. When the receiving server rejects the message, due to an invalid user name or mail box full error (for example), the server creates a non-delivery failure and sends it back to the user who it thinks the mail came from - i.e. you or one of your users.

Some customers report hundreds of these each day for a single user, and one customer had so many it amounted to a Denial of Service attack (see Case Study of DoS Attack ).  Customers were begging us for a solution to this problem.

Well, we finally figured out how to stop baskscatter that your server receives.

We accomplish this using unique properties of Domino messages that help distinguish real NDRs from backscatter.  The trick was that some senders send back a non-delivery report (NDR) and some send back only a "Memo", which complicates the problem.  These Memos are simple mail messages from a legitimate email server to your email server.  If they include the body of the message, SpamSentinel is able to stop the message as spam.  If they simply say "We are unable to deliver the message" then it is almost impossible to stop.  But we have found a way!

So, if you upgrade to version 7.5.3.1 of SpamSentinel, your problem is solved.  This version has two new options:

- Block NDRs that are not from Emails generated from one of your Domino SMTP servers
- Block Memos that are effectively NDRs

Here is a sample email backscatter message that SpamSentinel 7.5.3.1 catches:

A picture named M2



This version is available by request.  Email me Frank Paolino and I will get you the software.  This is a "no charge" upgrade, and includes the ability to block spam at the SMTP gateway (see the blog posting SpamSentinel Now Blocks Spam at the SMTP Level)




Comments

Gravatar Image7 - @6 Claus Thanks for the heads up. I will check it out for possible inclusion into the product! Anything we can do to help stop backscatter is a big win.

Gravatar Image6 - If SpamSentinel supports doing DNSBL-Queries if envelope-from is a nullsender only, then there is a riskless solution to stop receiving backscatter.

ips.backscatterer.org is a blocklist which covers backscatterer and sender callout abuser only.

BIG FAT WARNING:
Please be sure you don't use it like a regular DNSBL, because almost all listees are real (but poorly configured) mailservers.

Doing requests just if sender claims to be a bounce is the only real safe usage of this blocklist.

Gravatar Image5 - @4 Peter We have released v 7.5.3.5 which has more aggressive settings and allows messages to (optionally) be put in the JunkMail folder for review, or left in the Quarantine.nsf for the daily report. I will send it to you.
Frank

Gravatar Image4 - Is there any way how to tune these settings? We have upgreaded the SS to the 7.5.3.1 version, but we are "backscatterred" still... thanks

Gravatar Image3 - @1 Dag These settings are ON by default, so there is no configuration necessary.
Frank

Gravatar Image2 - I think this is a smashing good idea!Emoticon

Gravatar Image1 - So, where exactly in 7.5.3.1 do You enable these two settings ?
I have searched High and Low and not found it.

Post A Comment

:-D:-o:-p:-x:-(:-):-\:angry::cool::cry::emb::grin::huh::laugh::lips::rolleyes:;-)

Lotusphere 2008

Tags

Frank Paolino