Reverse DNS RFCs and Recommendations

Tony Hain alh-ietf at tndh.net
Thu Oct 31 22:49:56 UTC 2013


John Levine wrote:
> Right.  Spam filtering depends on heuristics.  Mail from hosts without
> matching forward/reverse DNS is overwhelmingly bot spam, so checking for
> it is a very effective heuristic.

Leading digit is clearly in widespread use beyond 3com & 1and1. One of the most effective heuristics in my acl list is:
\N^.*@\d{3,}\.(cn|com|net|org|us|asia)

In the last few hours it has picked off multiple messages from each of these:
Carol28 at 8447.com
Jeff17 at 3550.com
Ronald79 at 0785.com
Kevin57 at 2691.com
Deborah76 at 3585.com
Kimberly34 at 5864.com
Sarah94 at 0858.com
zavfdv at 131.com
qgmklyysyn at 163.com
pjpeng at 163.com
fahuyrw at 163.com
Daniel57 at 4704.com
Helen95 at 2620.com






More information about the NANOG mailing list