Skip to content
A scene from Ireland

Whitelisting email

I have been following SPF for a while and have been thinking through the whole junk-mail control issue.

I have come to the conclusion that the only viable long-term solution is agressive whitelisting.

I have been having thoughts about setting up a local service to support whitelisting.

Outline

The idea is that you would arrange for all your incoming mail to pass through a central whitelist service. This would maintain:

  • A current white list for you
  • A current black list
  • A collection of pending messages

If a message arrives that matches your white list, it is forwarded directly to you.

If a message arrives that matches your black list, it is stored in the pending collection. Message remain there for one month, and are then quitely destroyed.

If a message arrives that doesn't match either list, it is added to the pending collection, and a message if forwarded to you which contains the subject and other summary information about the message. This message would be formated so that if you reply to it, the message details are whitelisted and all pending messages that match are released and forwarded to you.

If you get a message that you think is junk, and you decide that you don't want to trust the source, you can forward it to a special address (thisisjunk) and it will be added to your blacklist.

List Matching

But what does it actually mean to match a list?

Entries on a list are either an email address, or a bare domain. Each entry is also marked as SPF compliant or not.

Bare domains are only allowed on the whitelist, and only while no entry on the black list with the same SPF compliance has the same domain. Thus you can whitelist a domain until it is abused.

When a message arrives, we extract a Perported Responsible Address, by checking Resent-sender, Resent-from, Sender, and From. We do an SPF check on the origin to see if it is reliable.

Then we check if the address or its domain is on either list with the same SPF status (which is either Pass or Fail).

List Maintenance

The white list grows by you adding addresses when you "reply" to messages about new mail. Once a particular domain appears more than once on the white list, and not at all on the blacklist, the domain is whitelisted.

The white list can be reduced by you forwarding mail to "thisisjunk".

The blacklist grows by you sending mail to "thisisjunk" and also by you ignoring multiple mails from the one address. Once 5 mail items from a given address have been reported, the address goes on the blacklist unless it is on the whitelist.

The blacklist shrinks when you reply to a message that has since been blacklisted.

Note that "thisisjunk" with either remove from the whitelist or add to the blacklist. It won't do both. Conversly, replying to an alert will both whitelist and de-blacklist an address.

Finally, it is possible to get a copy of your blacklist and to modify it. This is done by sending mail to "myblacklist" (or similar).

Authentication

Whenever a message is sent by the whitelist system that expects a reply, it embeds a crypto-secure cookie in the return address. When it gets such a message, it can be sure that if the cookie is secure, the owner of the address is the one who sent it.

Other Ideas

It would be nice to automatically catch outgoing mail and add all addresses in such to the whitelist. This would require trapping all outgoing mail though, which isn't very elegant.

It is important that the new-mail-alert messages are not too annoying. They should have lots of useful information in the subject. It should also be trivial to filter them into a separate mail box for looking at only occasionally.