Port 25 will be blocked for South Korea from December
zombie-storage.com
zombie-storage.com
ISPs that block Port 25
This list contains some of the major ISPs that block port 25 on their servers:
AT&T (can be unblocked at the request)
MindSpring
BellSouth
MSN
CableOne
NetZero
Charter
People PC
Comcast ATTBI
Sprynet
Cox
Sympatico.ca
EarthLink
Verio
Flashnet
Verizon
MediaOne
I don't know how accurate or up to date this list is, but I know that loads of residential ISPs in countries all over the World block outgoing port 25.That breaks a few things like the sendmail command on a default *Nix setup. But you can often set it up to relay mail to the ISP server instead.
It's a bit sad that you can't run a mail server at home. But very few people really need to do that. If you have a legitimate need to run your own mail server get a cheap cloud instance or use one of the bulk mail delivery services instead.
Blocking port 25 is a sane measure to protect Internet users from the spam and phishing mail propagated by botnets. Just like how some ISPs block the Windows networking ports to protect users with mis-configured home networks.
If you've got a dynamic IP, please don't even attempt this. If somebody else gets assigned your IP before you have a chance to update the DNS, they could potentially pick up your email.
ISPs who implement blocks on port 25 and force everyone to use their mail server are able to take responsibility for the spam leaving their network.
Note, ISPs don't block ports 587 and 465, so they're not preventing you from using services like GMail etc.
Also, it is completely relevant as they have all done exactly what is being proposed in the article being discussed. ISPs in South Korea will also provide mail relays for their subscribers to use.
The port 25 block is designed to force compromised systems to route email via controlled boxes. The fact that you can route email via controlled boxes doesn't mean you've worked around the block, it means you've been forced to do exactly what the intention was.
I suppose that would be a form of non-net-neutral corporate censorship. But one could make a pretty good argument that it's a technical issue with a core protocol of the Internet. It's not really practical to send emails from your home anyway because so many servers will simply refuse to accept them from residential netblocks.
I hoped that our neighbors were in a better position to fight these attacks on liberty online. Is privacy on the web really under this much pressure in Finland?
I configured our mail server to only accept mail from our internal work IP address and from authorised users.
Obviously mass mail providers will only be able to impose a username and password restriction but I would say the best way is to stop people producing mail software that can be open.
Preventing them from making outgoing connections on port 25 means they have to connect to an intermediary server instead. Usually the ISPs. This makes it much easier to detect/block/rate limit them.
Most of the time however, they just give up when they can't make the outgoing port 25 connection. Or keep trying and failing.
So if one of your office PCs catches an e-flu, it will have no trouble using your mailserver to spread spam.
The way I see it, the only way is to make SMTP authentication mandatory _everywhere_ (except perhaps on your desktop localhost, which should accept mail from you, but should be required to authenticate when pushing your outgoing mail to your upstream mailserver).
OTOH, if smtp auth became mandatory, or at least widely used, malware would just adapt, and its ability to sniff out credentials would improve. Arms race and all that. So scratch my idea.
How does blocking 1 specific port stop the issue anyway? They can just change the port they connect on?
As stated in the actual article...
Do these government agencies actually think blocking port 25 will reduce spam? Most of the issues stem from open relays.
I was offering an opinion on how to resolve those issues. Changing which port accepts the mail is in my opinion pointless.
It's like saying that most burglars come in through the back door so the government blocks everyones back door, they will just come in the front.
From outside of your network yes. If one of the computers inside your network is infected your mail-server will happily deliver the spam mails.
> How does blocking 1 specific port stop the issue anyway? > They can just change the port they connect on?
I don't know of any SMTP-Server that accepts E-Mail on Ports other than 25. Port 587 requires authentification before sending an E-Mail.
I thought most poeple don't accept E-Mails sent from isp-networks with dynamic ip adresseses. Maybe that's not the case and they try to reduce spam this way.
> I was offering an opinion on how to resolve those issues. > Changing which port accepts the mail is in my opinion pointless.
Nobody changed any ports. E-Mail is still send to port 25 from mail-servers. But if you are a not a mail-server (e.g. a client in a network) you have to use the submission port and authentificate against your isp/comapany mail-server.
you can still use port 25 on your isp mail gateway but now they can filter and rate-limit your emails.
> It's like saying that most burglars come in through the back door so the government blocks everyones back door, they will just come in the front.
not really. it is good practive to only act as mailserver if you are on a static ip and mx records point to your server. none of this is fullfilled by dynamic isp ip adresses. So this just stops the unwanted practice for good.
I think the two properties which a comms method needs to have a spam problem are:
1) it is inexpensive to communicate with someone
2) it is has a fixed, human-memorable "address" which can be communicated out of band (business card, verbally etc)
Once you have these two things, such lists of fixed address can accumulate and be circulated - and they can be spammed.
(2) implies that your comms method accept comms from unknown people. (1) is necessary for spammers to bother to do to use that channel to communicate with you.
I think you have to give up one or the other of these things to avoid spam. Note that (1) is a sliding scale. Physical post is significantly more expensive than email to send, and suffers less spam - but it is not non-zero.
Basically if cost of "customer acquisition" < "cost to send spam" on that comms channel, then you'll get some (if (2) is met).
[*] I suppose some heuristics to decide if it is OK for "random unknown user X" to contact me can help. But false positives are the very devil here...
However, this isn't necessary for all communications. For instance, if a communication is signed by a reputable company (bank, for instance), then don't bother asking. ISPs should keep the list of reputable companies as short as possible and, regardless, it gets rid of phishing emails.
The problem comes when spammers forge From headers which leads to:
-1: Very many emails in the greylist everyday
-2: False positives if they use a From that you've previously accepted (ie that person gets infected)
-3: False negatives if you get a spam that you reject which was sent from an address that you really want whitelisted.
Some of the failure modes are similar to challenge-response systems.
Nothing stops you from doing greylisting today, and it can be a very effective means of stopping most spam. There are tons of software solutions for greylisting.
Some require manual approval first time. Some sends a message back to ask the sender to do something (anything from just clicking a link to entering a captcha) and relies on you to do manual approval now and again (to catch automated but valid messages).
Some just defers delivery and waits for a second delivery attempt (because most spammers practice "fire and forget" and just ignores errors). Our office mail server is in the latter category - first time someone e-mails us,a second delivery attempt needs to happen after 10 minutes for the message to get through (it's ok if there are attempts in between too, but the assumption is that most of even the few spammers that retry will go away too quickly to send another attempt after 10 minutes). It gets rid of the vast majority of our spam before our real spam filter even kicks in.
Also, considering how easy it would be to spoof "x", they could probably make people click "yes" a significant amount of the time.
- the spammer has just succeeded in putting their message in front of you. If you had 500 of those per day, it would constitute spam which would again need the same filtering.
How does this prevent me from getting a certificate for "Viagra Salesman" or even "Roger Smith" and sending spam selling viagra?
Whilst I don't generally believe governments should intervene in the internet, this is one area they could intervene in. They could act as a certificate authority.
Of course, CAs will make mistakes, but they can revoke certificates when things go wrong.
This is already how we manage to block most spam on the edge. What you're proposing is just a small iteration on the existing defences. An expensive one, which wouldn't work unless you managed to get everyone doing it at the same time.
I can't remember what it is called, but I hope somebody else can chime in with the name.
The smart thing about it is that you can use it as a filter in your baysian spam filtering systems. That way it can be implemented gradually, with no need to cut out everybody who doesn't yet use it.
(In the 90s Bill Gates touted the idea that the recipient of the email would receive the fee, and routinely refund it to the sender for legitimate messages.)
Mailing lists could even demand a lower hash target, requiring more energy to send messages to lists. This could rate-limit flame wars, for example.
What are you going to do to emails without the HashCash header when 95% of the World is still sending email without it? Does it matter to anyone else what you do to those emails if you're the only one doing it?
There are plenty of reasons why "Payment" anti-spam methods have been soundly debunked over the years. You're not the first one to think it's a good idea, and you probably won't be the last, but do the research yourself first into why they can't work.
If a spammer can't get a message through, they will keep tweaking it until they succeed.
If even 999 out of 1000 spams are blocked, they'll still keep firing.