nanog mailing list archives

Re: Senderbase is offbase, need some help


From: Jon Lewis <jlewis () lewis org>
Date: Sun, 18 Apr 2010 21:19:28 -0400 (EDT)

On Sun, 18 Apr 2010, Larry Sheldon wrote:

Have you checked cyclops and other BGP announcement tracking systems
to see if it might have been a short-lived whack-a-mole short prefix hijack
(pop up, announce block, send burst of spam, remove announcement, disappear
again)?


Maybe I'm just tired and cranky or too old to understand.....if the
addresses in question never send traffic, who cares?

He's suggesting that maybe mail came from those IPs while someone else was using them without your knowledge. Given the available info, I think its far more likely senderbase has some glich causing bogus 0.48 scores for IPs that really haven't sent anything in recent history.

----------------------------------------------------------------------
 Jon Lewis                   |  I route
 Senior Network Engineer     |  therefore you are
 Atlantic Net                |
_________ http://www.lewis.org/~jlewis/pgp for PGP public key_________


Current thread: