November 3, 2011

Antispam whitelist

There is always plenty of talk about how good or bad a blacklist, or blocklist, is with comments about the false positives generated by that list. These days, with spam at approx 96% of the total daily volume of email sent, no sane email Administrator would operate email servers without first using a whitelist and thereafter possibly filters in addition.

I have had excellent results from these guys;
http://www.whitelisted.org/
You may want to get your own email server listed on their database so that your emails have a better chance of successful delivery, see their website for instructions. The whitelist service seems to be associated with, or run by, http://wwwUCEProtect.net/ , a German blacklist operator.

UCEProtect actually have 3 main blacklists each with it's own listing criteria. Using all 3 blacklists together on your email server will require 3 blacklist entries for DNS lookups but the combined results are very close with those of L2.APEWS.ORG. UCEProtect.net may provide better results for European language based senders and receivers, results here suggest that APEWS.ORG data is particularly good for English.

The use of a whitelist is to exempt the need for blacklist checking, i.e. it is a list of trusted IP addresses. Any sender of an email from a whitelisted IP address can be trusted to connect and deliver their email without any further checking. There can not be any error due to a blacklist since one has not been consulted!

Any connecting IP address that is not whitelisted probably can not be trusted and therefore warrants further checking. Things like PTR records can be useful indicators but as mentioned previously, we see email service providers to governments using badly configured email servers where the reverse DNS does not match. Results here suggest to ignore PTR record checking and just do a blacklist DNS lookup, creating X-Headers for those connecting IP addresses that are blacklisted.

False positives can be seen to be a reflection of the quality of the whitelist being used. If the whitelist maintainer has their data accurate, it would not matter whether trusted email servers were listed in the blacklist or not. Fine tuning of data for both whitelists and blacklists is a coninuous job though once the bulk of the entries are in it is just a matter of adding the odd one at local level.

7 comments:

  1. An entire IP block for our ISP has been blacklisted by APEWS, including the IP's for our mailserver, which is not spamming anybody.

    208.15.230.230

    How do I report a false positive and get our IP address removed?

    ReplyDelete
  2. Checked your IP address in senderbase.org and there are other IPs close to yours that are blacklisted elsewhere. Your own IP address isn't listed in APEWS now.

    ReplyDelete
  3. i have the same situation,
    An entire IP block for our ISPs has been blacklisted by APEWS, including the IP's for our mailserver, which is not spamming anybody.

    5.9.21.66
    5.9.95.205

    i try senderbase.org and i have a good reputation score

    How do I report a false positive and get our IP address removed?

    ReplyDelete
  4. Hello, our ,mail-server-IP has been blacklisted by APEWS.

    82.147.32.162

    We tried senderbase.org the reputation score was good.

    How can we then get our IP adress removed?

    Best regards, Roar at Siwu.no

    ReplyDelete
  5. hello our IP 83.229.43.140 and 83.229.43.142 has been blacklisted in your data base we have email security service in place activated, can you please whitelist our ip , we are unable to send email.

    Thanks
    Suhasini

    ReplyDelete
  6. hello our IP 83.229.43.140 and 83.229.43.142 has been blacklisted in your data base we have email security service in place activated, can you please whitelist our ip , we are unable to send email.

    Thanks

    Shady

    ReplyDelete
  7. These days, with spam at approx 96% how to stop spam of the total daily volume of email sent, no sane email Administrator would operate email servers without first using a whitelist and thereafter possibly filters in addition.

    ReplyDelete