Get the latest tech news

A SpamAssassin Surprise


[LWN subscriber-only content] Back in April, an important anniversary went mostly unremarked: it was a full 30 years since the sending of the still-famous "green-card spam". Those of us who were recipients of that missive were horrified at the time, but nowhere near as horrified as we would have been had we known what was coming.

Validity confusion A close look at the spam that got through revealed, along with numerous opportunities to get rich, deal with chronic health issues, or make improbable anatomical changes, that a couple of rules ( RCVD_IN_VALIDITY_CERTIFIED and RCVD_IN_VALIDITY_SAFE) were firing in all of them. The result is that a lot of email that would otherwise have been properly classified as spam now looks legitimate; you really did have an unknown rich uncle whose estate can be yours if you just pay a small advance fee. But we are essentially entrusting one of our important communication channels to unaccountable third parties with predictable results; anybody who has run an email server for a while knows the sinking feeling that comes with having to request removal from another blocklist — again.

Get the Android app

Or read this on Hacker News