Are spam 'blocklists' going too far?

Like a growing number of Web surfers, Audrie Krause faces a new uncertainty when she hits the send button on her e-mail these days: Will the message get through?

As the head of a political action group, Krause uses members-only e-mail lists to help educate and organise fellow activists. So she was jarred recently when one message bounced back with a note accusing her of spreading unsolicited junk e-mail, or spam.

Without warning, Krause's NetAction site had been blacklisted--an increasingly common occurrence as companies seek to block crushing loads of unwanted e-mail by any means necessary.

"It's ironic because the work we do as an organisation includes helping get the message out to other activists and nonprofits about how to use e-mail and the Net for outreach...without spamming," Krause said. "I'm sure it was a mistake."

The incident, which was fixed within a day, highlights a growing problem for ordinary e-mail users now that sometimes-indiscriminate blacklists have become a key weapon in the war against unsolicited bulk e-mail.

Blacklists--also known as blocklists--keep tabs on sites and numeric IP (Internet Protocol) addresses suspected of sending spam. Internet service providers, companies and individual Web site operators subscribe to the lists, bouncing any traffic directed to their servers that originates from those addresses. The result is that all blacklisted e-mail--legitimate or not--is returned to the sender.

Blacklists are as old as the Internet, but their number has multiplied in recent years. Many on the receiving end are now adopting tougher policies as spam has grown to epidemic proportions. At the same time, more companies and Web site operators are using blocklists as a mainline defence against vast volumes of spam that can cripple their systems if left unchecked. The need is so great that some companies now are turning a blind eye toward militant tactics that may do too little to sort legitimate from illegitimate sites.

"Almost every company now is looking at using blocklists because there's no choice--there's too much spam coming in," said Steve Linford, who maintains a London-based blacklist of mass e-mailers called the Spamhaus Block List. "The blocklists need to be run with an amount of responsibility and ensure that if any innocent user is caught on a blocklist there's a means to get off quickly."

Spam invasion
Most people are enraged by the exponential growth of spam in the past year but baffled when it comes to looking for answers. Worldwide spam attacks have grown by nearly five times in the last year, from about 1 million last June to just under 5 million this year, ISP filtering company Brightmail noted in a report published this week.

Part of the problem stems from the economics of e-mail, which provides no incentive for marketers to cap the volume of messages they attempt to deliver.

Blocklists such as Spamhaus, the Realtime Blackhole List, SPEWS and SpamCop.net have grown as a response to the resulting flood. But they are increasingly coming under fire for high incidents of "false positives," in which non-spammers are added to the lists.

Recent complaints about blocklists have come from companies and organizations, including British Telecom, the Libertarian Party and ZDNet News publisher CNET Networks, among others.

In general, blocklists are simple databases of spam-generating IP addresses. Most use the DNS (domain name system) protocol to block a IP address in real time so that if a number is added it will have an immediate effect on spam delivery.

The blocklists rely heavily on each other to locate spammers and create their lists. Many lists go to SpamCop to see if a piece of e-mail has been reported and to determine the offending IP address. Others use a Usenet newsgroup called news.admin.net-abuse.sightings (NANA) to root out sources. Once the mail is verified as spam, the blocklist will add its originating IP address and, typically, that of any Web site advertised in the message.

While the blocklists target spammers, legitimate sites such as NetAction.org can easily be caught in the net.

Sites may find themselves on blocklists because of e-mail viruses or other tricks that spammers use to "spoof" or mimic addresses. The Klez virus, for example, caused at least one site to be listed by mistake on Relays.osirusoft.com, according to Joe Jared, who runs that list.

Jared operates a blocklist database that carries SPEWS and other spam listings.

Organisations running the blocklists have different policies for adding an IP address to the list. But many are now adopting an attitude of list-first-ask-questions-later, capturing an ever-widening circle of suspected offenders, guilty or not.

Jared, for one, downplayed concerns about catching legitimate e-mail, saying that if an e-mail "looks like spam and it smells like spam, then it will get listed."

Room for mistakesSpamCop, which started in the last year, this week incorrectly listed the main e-mail hub for British Telecom, ruffling a few feathers. Because the system is automatic and doesn't use a person to flesh out whether an IP address belongs on the list, it can mistakenly add a company, according to operator Julian Haight. In British Telecom's case, its mail hub had an inconsistency in its DNS information, which caused the listing. Haight corrected the mistake by listing the individual spammers on the telecommunications company's network.

"Every form of filtering has false positives. As soon as you start to use filtering, you accept that you're going to block some legitimate e-mail; it's just a question of how much," Haight said, who advises site operators to give their users a choice about blocking.

"People in the past were opposed to filtering at all, but more and more system administrators have to be aggressive because they have no choice."

He said that if innocents are listed, it takes a week to become automatically de-listed.

One of the most controversial tactics involves adding entire ranges of IP addresses to a databases, even when it's clear that some legitimate Web sites may be affected--an outcome dismissed as "collateral damage" in the trade.

Some militant blocklists have been accused of actively using collateral damage as a tool to spur legitimate sites into the battle against spam.

Magdalena Donea, a system administrator at Web hosting company KIA Internet Solutions, found a set of her company's IP addresses blacklisted recently on SPEWS. She successfully lobbied to get the listing removed, but it was re-listed a second time with additional IP addresses, a move that also affected a company client, the Libertarian Party.

"The SPEWS system is unapologetic about false positives and even regards them as a plus. They've taken the 'ends justify the means' argument way farther than I've seen anyone else take it," Donea said.

"Their philosophy appears to be that if innocent businesses and individuals on the periphery of spam-house blocklists are affected, then those innocents will have no other choice but to pressure their upstream provider to remove the spammers from their blocks, thereby solving the spam problem bit by a bit. Draconian, yes. Effective? Sure."

The people who run SPEWS are anonymous and could not be reached for comment. Many blocklist operators seek the shadows because they are constantly slammed with complaints and requests for addresses to be removed.

"We get harassed all the time," said Relays' Jared. But he added that blocklists are winning more converts every day.

"There are lists that are very hard core and lists that are very liberal," he said. "But basically the tolerance for spam is decreasing in direct proportion to the increase in spam."

Advertisement

Talkback 2 comments

    Oh come on. Every anti spam w ...Anonymous -- 15/07/02

    Oh come on. Every anti spam web site tells you what to do. Firstly try and contact the sender if it is a guniune organisation. Secondly try and contact the ISP that has the mail server. Then contact the ISP that is hosting the web page. If all of that fails after repeated attempts THEN and ONLY THEN do you try and add the ISP's IP address to a black list.

    Get real. Get a life. Get rid of spam at ALMOST ANY COST!!!!

    20Gb+ and counting... Spam Blo ...Anonymous -- 16/07/02

    20Gb+ and counting...

    Spam Blocks are indeed going to proliferate. One thing that was not mentioned by the author when tagging a blocklist site at 'militant' was that EACH AND EVERY network admin that implements a blocklist has the CHOICE to use or not use one of the many blocking databases. If that admin feels that the database is run by a so-called 'militant' then its up to them to choose not to use their database.

    Its that simple.

    Spam causes MASSIVE problems. I can say this with experience as we are still (a month into it) receiving undeliverable mail from a forged From: address claiming to be from a site we host. Im talking about well over 20Gb of data. From an average of 7kb spam email. Someone has to pay for this. Us. Is that fair? Someone has to implement strategies to deal with this spam. Us. Is THAT fair?

    We have had to reengineer our network, implement products (at a cost to us, and requiring fast learning) that can properly handle unwanted connections (Reject) and move the hosted customer to another link so as to not affect our other customers.

    We have had to work till beyond 3am a number of times specifically to deal with the deluge of data coming down our (quite large) internet link. I personally worked most of the recently passed long-weekend dealing with the 'collateral damage' that we were (and still are) sustaining from a spammer forging the From: address.

    We have to weather hundreds of criticising emails suggesting that we are spammers.

    As an administrator, I am TRULY angry at spam.
    Further, it angers me to read articles that attempt to paint blocklists as 'militant', its wildly unnecessary, but i guess authors love to emphasise their point of view...

    The fact is, these blocklists (militant or otherwise) are necessary. Until admins secure their networks, and until the people who write Email server and Proxy server software secure their code, and until ISP's stand up and take notice 'draconian' action is going to be fully necessary. Spammers will not stop. Their selfish morals are in the gutter with other vermin.

    I understand the pain that an unfairly blocked site feels, ive been involved in their removal. But I can garuntee that you will change your mind if you become 'Joe Jobbed'.

    (Joe Jobbed is a term used to describe a spammer forging your domain/email address as the From: address on spam emails. Used to make you look bad etc)

    So take a second to consider the bigger picture. Do you want to complain about missing a few 'important' emails, and give the spammers more time to devise new and better methods of sending you the latest email about dangerous drugs, sexual abuse and other JUNK?

    Its either accept spam, or do not. The blocklists arent 100% effective, but thats all youve got. Noone currently has any better idea's. And LOTS of people are trying.

    Support them, support your administrators in their use. And hope that spammers take the hint.

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • Array Can complaints on mobile content be cut?
    On 1 July this year the new Mobile Premium Services Code was introduced. It sounds like it's had a good impact, but is it enough?
  • Array NZ farmers: Bleating about broadband
    As we know, farmers are such bleaters. They bleat as much as the four-legged woolly things in their paddocks. If it's not the weather, it's the strength of the dollar! Nothing is ever right. Likewise with rural broadband.
  • More blogs »

Tags

Back to top

Featured