With, like, 80+% of inbound SMTP traffic coming from Google, Microsoft, Amazon and assorted non-malicious transactional/list-based SaaSes, a simple 'I either like or dislike the sending IP' approach has been infeasible for many years.
With, like, 80+% of inbound SMTP traffic coming from Google, Microsoft, Amazon and assorted non-malicious transactional/list-based SaaSes, a simple 'I either like or dislike the sending IP' approach has been infeasible for many years.
I see a few spam a week, have never seen a false positive. I think greylisting made the biggest difference after sane-sender checks.
Just do a challenge-response on incoming mail from new addresses on Gmail and Outlook. Send an auto-reply telling them they can get their mail through if they copy a code in the reply. That will kill most spams from those sources.
It'd be nice if Google did something about this. Until they do, I tell everyone that uses Google for email that they have to accept that they're hosting with one of the biggest sources of spam on the Internet that, as far as I'm aware, does absolutely nothing when spam from them is forwarded to their abuse addresses.
Never auto-reply to any email ever. You're only making the spam problem worse.
(Plus, if you think there are not actual persons behind most Outlook/Gmail spam, I've got news for you. They will reply, and beg you for another chance, sometimes in highly emotional terms).
"550 5.7.1 The recipient has set a policy that prohibits email from this sender" at the SMTP level is the only way forward here.
Looking at just a random spam I have here, I see it passed both SPF and DKIM happily. But it was marked as spam in HostKarma, Spamhaus, Truncate and flagged as Bulk by Razor.
So I dropped it. Looking at heaps of my attempted Spam emails I see the same. It seems most spammers setup SPF before attempting, or are hijacking legit sites/mailservers to send the spam.
Pretty much the only Spam I find I reject based on DMARC as well is just the "I hacked your webcam" blackmail spam that tries to "prove" they hacked you by spoofing my email domain.
I think if I disabled all RBLs the other huristics rspam gives me would still catch 90% of the Spam, but the RBLs certainly help me still catch 99.9% of the Spam attempts I recieve.
Factually untrue. You are a teenager spouting self-important garbage.
And in 2009, filtering inbound SMTP traffic using a popular DNSBL or two was definitely effective (as was greylisting). Alas, no more.
But I probably misunderstand what you're saying?