One thing your mail-sending system should doIf you are for some reason absolutely forced to have a system that will
send email to user-entered addresses (given the principles of modern
email this is not a good idea,
but let's imagine that your management forces you), one of the things
that you should absolutely do is make your system so that it won't send
mail to certain user names. Spamming people is one thing; spamming
(You may be able to guess what our postmaster alias got today, although it was probably actual spam faking the 'someone requested you be sent information' bit.) The case for vacation autoreplies is somewhat weaker, but I think that
they should definitely not auto-reply to at least (These days, And on a side note, putting the IP address that submitted the web form
into your auto-sent-out email message does not make your email any less
spammy or abusive, or cause people to react any better to it. That
particular well has been thoroughly poisoned by spammers (who forge this
information in the hopes of distracting people). However, if you are
going to do this please insert the same information into the message
headers in some relatively standard format, like (As a tip to would-be spammers, try to make your forged IP addresses come from actual allocated IP address space.) (2 comments.)
|
These are my WanderingThoughts GettingAround This is part of CSpace, and is written by ChrisSiebenmann. * * * Atom feeds are available; see the bottom of most pages. Categories: links, linux, programming, python, snark, solaris, spam, sysadmin, tech, unix, web |