ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Plug pulled on anti-spam project

Richard Thurston ZDNet

Published: 22 Dec 2006 11:14 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A popular anti-spam service is shutting itself down, saying it is no longer effective at protecting organisations from junk email.

The Open Relay Database (ORDB) was set up by volunteers five years ago, shortly after the dot-com boom ended. It aimed to stop spammers using SMTP proxy servers — also known as open mail relays — to flood the internet with junk mail.

These proxy servers were initially used as 'middlemen' to move email from source to destination rather than sending them directly over the internet. As a consequence, they could be used to send large amounts of junk mail with little chance of detection.

ORDB distributed a blacklist of servers that operated as open relays, so that administrators could block email from these sources.

But the ORDB has recently stopped growing, and its volunteers' interest waned. While five years ago, around 90 percent of spam was sent through open relays, now the figure is less than 1 percent. Much of today's spam is propogated using botnets, which are networks of compromised computers.

The announcement that it had decided to close came on Monday.

"We regret to inform you that ORDB.org is shutting down," said the ORDB in a statement. "The general consensus within the team is that open relay RBLs [relay blocking lists] are no longer the most effective way of preventing spam from entering your network as spammers have changed tactics in recent years, as have the anti-spam community."

The ORDB said organisations should remove its checks from their mailers immediately and consider other methods of spam filtering. It recommended a combination of greylisting and content-based analysis, such as the dspam project, bmf or Spam Assassin.

Another organisation that creates blacklists of spammers has also been in the limelight recently.

Spamhaus, a UK firm with a global customer base, was ordered to pay over $11m in damages to a company it blacklisted, which claimed the move was illegal. 

But it is not just the ORDB and Spamhaus which have found it difficult in their quest to tackle spam.

The Information Commissioner's Office (ICO), the privacy watchdog, admitted to ZDNet UK earlier this month that it had not successfully prosecuted any UK spammers, despite regulations designed to curb spam being brought in three years ago. The ICO says it lacks powers to combat spam, and blames its lack of power on the UK Government.

In the meantime, spam levels are still soaring. According to email security vendor IronPort systems, 63 billion spam messages were sent each day in October 2006, compared to 31 billion per day in October 2005. November saw two surges that averaged 85 billion messages a day, one from 13 November to 22 November, the other from 26 November to 28 November.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
356 out of 463 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Java/Analyst Developer - Global Investment Bank - 500 per day

Position in a team working with one of the key systems in the firm, responsible for calculating the official profit-and-loss and reporting it to a ...

Core Java - Global Investment Bank 550+ per day

This role is within a team, which improves the information management and scalability using the Client Dashboard. This client is looking for a Java ...

Quant Dev - Quant Team - Financial Institution - 700 per day

Role for a C++ Quant Developer at Global Financial Institution. The role will involve developing a new pricing server for exotic commodities linking ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation