upvote
> Most of the junk we've been getting passes DMARC and has an unsubscribe link.

You say that like its a problem.. its a formidable solution!

Has worked for me for many years now: Just fail2ban-style block (groups of) relays that attempt to send an unsubscribe-link destined for a mailbox that never ever subscribes to anything. Those malicious-compliance folks add these unsubscribe links everywhere because they determined that its a cheap method for reducing blocks. That makes them reliably stand out whenever they hit strictly human-to-human mailboxes that simply never have any reason to "unsubscribe". Its like a honeypot, and all it took was a strict policy about what a tiny fraction of mailboxes can and cannot be used for.

reply
I'll have to ponder the method you describe. I know I could implement that on my own mailboxes and some automated endpoints, but not sure how that would work for other users on our domain.
reply
DMARC doesn't really do much to prevent general spam. It prevents spoofing the from address, which provides some protection against phishing, but if the email is from the domain it claims to be, it can pass DMARC whether or not it is spam.
reply
Indeed. Ultimately we're still relying on blacklists, Bayesian filters, and hueristics to detect actual SPAM.
reply
[dead]
reply