September 20, 2012

Still no False Positives

There simply haven't been any false positives to write about. A lot of people are requesting delisting and removal from Apews.org here but they are all email senders whereas this blog is aimed at receivers of email that use the apews.org data for filtering or blocking.

Anyone wanting a removal would do better to publish the email header from a receiver as we have done.

These days it's all about reputation and permission, even new allocations to existing ISPs that have a bad rep can expect to remain listed. Folks have had enough of snowshoe spamming out of newly acquired IP blocks.

IPv4 address space is nearly all allocated and most of it has been assessed by the apews.org team to great effect. Consistently trapping 95% or more of spam sent with less then 0.5% false positives is a great statistic so there can't be much wrong with the apews.org data. We encourage email receivers to publish errors here, prove the error with the full email headers, munge them for privacy if you want to. That way there is a public record of the error in your view, shame apews.org into fixing that error.

We can see that soon there will be no more IPv4 addresses for spammers to pollute, old existing allocations will have to be cleaned up in order to regain a good rep or stay listed. No residential IP address space needs to send email so outbound connections to port TCP 25 should be disallowed at the ISP firewall and it's so easy to do.

Right now there needs to be a 2 tier tariff for IP addresses, the price for apews.org listed IP address space should be dirt cheap to rent or even free since there is ad revenue from the http traffic. That is the usual business model, give free access with commercials which cover the costs incurred. ISPs are running all their user traffic through http proxy servers for ad tracking etc, try blocking their http server addresses at your firewall and you will lose your internet connection.

Clean IP address space that never gets listed by blacklists is obviously run professionally and volume email senders do so with the permission of the recipient. Their IP address space should command a premium in value and they deserve to earn more out of their email sending services e.g. providing smart hosts for clients. They won't take dirty email databases though :-) If you're really serious about inboxing then pay for a service from one of these guys.

Nice to see more email servers using the l2.apews.org for blocking as published on NANAE usenet newsgroup recently. Spam is no longer problem. We've had a lot of extra spare time for server maintenance and monitoring the whitelists, user complaints have stopped and the techs are up to date. In our server logs we've seen subscriptions to newsletter being honored, not bounced by using the apews dataset, what more can I say. Once we see the subscription process followed by an acceptance email we whitelist that enews server.

20 comments:

  1. Please delist the IP range 71.255.139.192/28; especially the IP address 71.255.139.194.
    The IP was blacklisted before the current user obtained this IP range; which occurred within the past month.
    The current user is now High Mowing Organic Seeds and the IP address 71.255.139.194 (which is used for SMTP traffic) now has a rDNS to mail.highmowingseeds.com
    -----
    Testresults
    Oooops 71.255.139.194 is currently listed in APEWS :-(
    --------------------
    Entry matching your Query: E-437649
    71.255.128.0/17
    -------------
    CASE: C-679
    AS19262 US, ISP permits abuse and/or ignores criminal activity
    --------
    History: Entry created 2010-12-20

    ReplyDelete
    Replies
    1. ISPs have an AS reference against which their IP allocation gets recorded. What Apews.org did a few years back was list the entire AS for the worst managed IP blocks i.e. those with a bad reputation. That case C-679 that you've found is one of those and if you have the dnsbl editor tool you can see all the listings. These guys are obviously wanting to recycle their IP allocations in spite of their bad rep, need to see what happens next if anything.

      Delete
  2. Please help me An entire IP block for our ISPs has been blacklisted by APEWS, including the IP's for our mailserver, which is not spamming anybody.

    Please delist the IPs:
    5.9.21.66
    5.9.95.205

    i try senderbase.org and i have a good reputation score

    How do I report a false positive and get our IP address removed?

    ReplyDelete
  3. please delist my ip
    Testresults
    Oooops 110.34.4.250 is currently listed in APEWS :-(
    Entry matching your Query: E-411987
    110.32.0.0/11CASE: C-1375
    Spambots/zombies within CIDRHistory:
    Entry created 2010-09-08

    ReplyDelete
  4. Given that there are still previously unallocated IPv4 address space being allocated. How do reputable ISP's get their new ranges de-listed?

    ReplyDelete
  5. Fuck Apews - fascist fuckin' douchebags

    ReplyDelete
    Replies
    1. Spanked spammer? Not looking good for Xmas is it...

      Delete
  6. good afternoon:


    I am the IT manager of the company (Chilean), and 3 months ago unable to use my mail server with subdomain IP# 200.111.174.20 because we appear in this list black. Please help me, I need to unlock the sub-domain, because my job depends on this situation.


    I'll be waiting for your reply.
    Thank you!

    ReplyDelete
  7. Sir
    Please deliste our Ip adress, you listed it before it was ours is the Ip 69.50.194.44 and we dont send any spam or publicy.
    kind regards
    Adela from vilmupa.com

    ReplyDelete
  8. Please help me An entire IP block for our ISPs has been blacklisted by APEWS, including the IP's for our mailserver, which is not spamming anybody.

    Please delist the IPs:
    93.116.195.115
    =============================
    Entry matching your Query: E-520789
    93.116.192.0/18

    ReplyDelete
  9. Please Delist 207.144.220.190, It's a K12 School Exchange server, fully secured, Static IP, RDNS, behind a Lightspeed SPAM gateway, it doesn't get more secure.

    This is a false positive, NOT a Spammer, It's a school.

    I hate spam as much as the next guy, but this method of blocking entire subnets without regard is questionable to say the least. I am the consultant who handles their Exchange. Please contact me directly via the listed website if their are further questions.

    Thank you.

    ReplyDelete
  10. Hello:

    We need to be remove the IP 200.71.17.226 (E-573781) because it was solved 2 problems:
    1) Open Relay: Now fixed.
    2) rDNS: Now fixed.
    Is this the correct way to request the IP Removal?
    I publish request of removal in several forums that APEWS inform and I have no response and was not de-list our IP.

    Regards

    ReplyDelete
  11. Please delist my Ip address

    174.92.253.91



    ReplyDelete
  12. Please help me; An IP for our email has been blacklisted by APEWS, including the IP's for our mailserver, which is not spamming anybody.

    IP address - 110.232.248.10 and 182.18.130.25
    Domain:- feedbackinfra.com

    ---Please delist the IPs:
    Oooops 110.232.248.10 is currently listed in APEWS :-(
    Entry matching your Query: E-412003
    110.192.0.0/10
    CASE: C-1375
    Spambots/zombies within CIDR
    History:
    Entry created 2010-09-08


    ----Please delist the IPs:
    Oooops 182.18.130.25 is currently listed in APEWS :-(
    Entry matching your Query: E-599459
    182.18.128.0/20
    CASE: C-131
    Unallocated CIDR, no traffic until allocated,
    or allocated to bad reputation provider
    or allocated but dynamic / generically named IPs,
    or bogons, see www.cidr-report.org,
    or orphaned IP / CIDR in routing table
    History:
    Entry created 2012-08-25

    ReplyDelete
  13. Please help me for our IP has been blacklisted by APEWS, including the IP's for our mailserver, which is not spamming anybody.

    Please delist the IPs:
    75.125.11.93

    Thanks In Advance.
    Regards,
    Khan.......

    ReplyDelete
  14. Please remove:
    Entry matching your Query: E-211479
    62.209.192.0/18
    from 2007-06-09!!

    Thanks
    Milan S.

    ReplyDelete
  15. No false positives? When you snag a small group of rich, middle aged, bible bearing, woman discussing their purebred cats, then you have a problem.

    ReplyDelete
  16. Please remove:
    Entry matching your Query: E-613289
    41.198.0.0/16
    CASE: C-258
    Spambots, zombies, contaminated CIDR, bad reputation provider
    History:
    Entry created 2012-11-21

    APEWS.ORG Databasetest

    Testresults
    Oooops 41.198.1.196 is currently listed in APEWS :-(

    41.198.1.196 used internally and under own administration.

    Spam are dealt with on a per case basis, but dynamically assigned ip addresses are hard to deal with.
    The /16 prefix in question are used in a couple of countries.
    From which prefix in specific did you receive the complaint to decide to block the entire /16 prefix?
    Can it be cleared from your list and be made more specific so we can narrow down the process to a specific country and network?
    Thank you
    Freddie S

    ReplyDelete
  17. waw mérci mes amis article top mérci
    merci merci merci jeux voiture merci merci
    jeux voiture games cars jeux flash gratuit free jeux flash 2015
    http://jeuxjeux99.blogspot.com

    ReplyDelete