Zee Roe wrote:

>On Tue, 22 Mar 2005, Stephen D. Williams wrote:
>>Upon receipt of an email message from a new email address / IP address
>>combination, send four probe email messages, one to the real From:
>>address and one to the Reply-To: address, and one to each of those
>>addresses with a random string appended to the userid.  The original
>>email is only allowed "in" if the first two sends succeed and the second
>>two bounce.
>Maybe I'm missing something, but wouldn't this automatically invalidate
>anyone sending from domains with catch-all addresses? I think it's pretty
>common with vanity domains, certainly I do it, for example.  It seems like
>just not bouncing the from: and reply-to: addresses would filter out a lot
>of the crap I get (some of which is marked as spam anyway).
That would be a problem and would have to be handled in some other way, 
perhaps an auto-reply system (which has it's own issues) or one of the 
sender-verified systems.

The point would be to prevent all of the spoofing of both real and bogus 
addresses that is used in spam.


