Anyone have opinions on the mail and anti-spam work that IronPort is doing with SenderBase and such?

I hadn't heard of them before, but someone recently pointed them out.

The info on their site is a little weak on details:

IronPort SenderBase is an information service that allows email administrators to rapidly and effectively identify high volume senders of email. SenderBase uses an extensive network of over 5000 ISPs, universities and corporations to give IT administrators a global view into the volume of email sent from every domain and network.

Now we all know that "high volume senders" aren't necessarily spammers. For instance, their top four right now are:

  1. yahoo.com
  2. attbi.com
  3. rr.com
  4. aol.com

But I do see beyondspecials.com and beyondoffers.net on the list. They're more of what I think of as spammers.

Anyway, I'm looking for more info. Anyone using their service? Bought their product?

Posted by jzawodn at March 15, 2003 08:47 PM

HiddenNetwork.com Banner

Reader Comments
# Cody Powell said:

The CTO from IronPort was on Tech TV the other day, talking about their service. I wasn't paying an extreme amount of attention, but it sounded like a good idea, although I was looking for more details. Tech TV is pretty good about archiving their stuff on their site, so you may want to go over there and take a look.

on March 15, 2003 09:34 PM
# chuqui said:

think of them as an anti-blackhole list. Effecitvely, using RBL technology to whitelist instead of blacklist.

At a basic level, they're a bonding house. The way these things tend to work is that if your complaint levels go above a certain level, you start paying fines out of your bond, so effectively, it's an agreement to whitelist a mail sender in return for keeping the complaints below a given level, with a financial incentive to do so.

it's an emerging, not necessarily widely used, setup. I think it has potential to help sort out the e-mail and figure out what needs to be evaluated. I have'nt specifically evaluated these folks, but they're on my list to take a closer look at. The underlying concepts and technology seem pretty reasonable, though. Anything that can help you narrow the field of things you aren't sure about is a good thing, and whitelists like this have a strong potential at helping larger sites manage their mail processing load, if they can scale, be trusted and e-mail senders convinced to sign up with them...

on March 16, 2003 12:04 AM
# Justin said:

We in the SpamAssassin (http://spamassassin.org/) dev team have been keeping an eye on this; it could be quite neat, purely as a measure of mail volume. Dan Quinlan in particular, seems to have been talking to them about it.

I personally would also like to see some correlation between spamtrap data and this data, to give a probability of spam from that IP address, similar to the spamcop DNSBL (http://spamcop.net/bl.shtml). But purely as a bulk-production measuring system, it's going to provide cool infrastructure for tests...

on March 16, 2003 11:03 AM
# Craig said:

Adding to what Justin said, I've actually had several meetings with the IronPort guys, including a bunch of discussion of their Bonded Sender, SenderBase and other stuff they're working on.

As I understand it, today the "product" they sell is a mail appliance for sending/receiving large volumes of mail. Super high-performance appliances based on some kind of BSD kernel (which I think they've heavily modified for SMTP performance, to reduce DNS bottlenecks, etc). They also "sell" Bonded Sender I think. Not sure that they have a for-money product around SenderBase, but it's certainly possible that they either do, or are planning one.

Certainly looking forward to getting the benefit of the SenderBase data to help in the fight against spammers. Combination of the SenderBase data with other tests on incoming email can certainly be used as a powerful determinant of spamminess.

Right now, there is a little bit of a bias in their mail volume data, where people who tend to send a lot of mail to people who use SpamAssassin with Bonded Sender checking turned on will have a disproportianately high ranking in SenderBase (since it gets its data by monitoring how frequently people lookup addresses in Bonded Sender). So since I correspond quite a bit with other SA users who have this turned on, SenderBase estimates that I send several hundred thousand emails per day, which is obviously a little off. Over time though, this should become less of a problem, assuming they spread their data gathering a little more.

on March 16, 2003 01:57 PM
# Justin Lundy said:

IronPort is grossly overpriced. Equally phenomenal, albeit slightly lower performance is available for about 1/10th to 1/15th the price, if you buy from competing vendors. One such vendor I hear is Tegatai Systems, who are scheduled to release their product and service line within three months. I have seen their benchmarks and they definately offer more value for the dollar. To note a correction, the IronPort device is only for outgoing mail, according to their documentation.

on March 19, 2003 02:30 PM
# Nir said:

IronPort are releasing a new product that will do Anti Spam, Anti Virus and Content-Filering
in one box.
It will have 3 1000/100/10 Ethernet nics,
with 4 hot swap Scsi drives.
I've checked them out for my network and it looks pretty good.

on May 5, 2003 06:02 AM
# Ken Simpson said:

SenderBase is a useful resource -- I particularly like the fact that they provide an efficient web service interface to make queries against it. See the Net::SenderBase module by Matt Sergeant of MessageLabs fame.

We have been working on integrating SenderBase data with our spam throttling product and have found some success with it. It's not a panacaea, however, and I understand that IronPort has a proprietary database which they do not expose through the SenderBase public interface, which contains a much more valuable "reputation" score.

But nonetheless they are doing a good thing for the community IMHO by making this database available.

on October 22, 2005 03:06 PM
# Tony Harbon said:

We re-sell Ironport and it does a good job. Effectively, Ironport Senderbase is a database of the "reputation" of IP addresses of mailservers that exist out on the Internet. It uses about 60 factors to determine reputation including; when the IP address was first seen sending mail, how much mail it is sending on a daily basis, can an email be sent to the IP address, pattern of mail volume growth; can you do a lookup on the IP address, is it on any of the 12 black lists that it has access to etc.

Based on the reputation of the IP address, the administrator can block, limit or apply other rules to email coming from that IP address. In addition, Ironport provides heuristic spam filtering and AV.

Our customers tell us that it can reduce incoming mail volumes by up to 50% by refusing connection from "obvious" rogue mail servers.

on September 22, 2006 10:26 AM
# Daniel Katz said:

Avoid this product. They're "throwing the baby out with the bath water." A properly configured email server which doesn't send any spam will be rejected and even if the IP is changed will be tracked. There is no legitimate way to contact the company and when you contact Ironport tech support, they OUTRIGHT LIE AND TELL YOU senderbase is not them!

Anybody who knows how to use WHOIS can discover that it's the same company.

Avoid!

on December 7, 2007 10:23 AM
# UCE Crusader said:

As an extremely experienced Mail Admin for a large company (and longtime Spam-Fighter), I have to say Iron Port is ridiculously FLAWED and a huge ANNOYANCE.

My network had a single workstation infected for all of about 15 minutes. I had this cleared up with SPAMCOP in an hour.

But it is taking well over a week to cleanup the aftermath from Senderbase.

Without any RBL listing or spam history, Ironport continues to list our Server's IP as "POOR" causing Hundreds of domains to refuse our email (even though the message didn't even come from our server).

The lack of a formal de-listing service is BOGUS and ARROGANT.

Ironport's "support" email is a blackhole of its own. Enquiries go in, nothing comes out.

To say "we don't block your email" is nonsense.

Ironport sells appliances and services to block email using subscriptions to a reputation database they maintain.

Even should I know the identities of the untold masses of Senderbase users, is it practical for me to contact the multitude of Mail Admins to request delisting?

Ironport and Senderbase get a double bird-flip!

on July 31, 2008 12:32 PM
# Victim of Ironport/SenderBase said:

I have to agree with UCE Crusader. Ironport/SenderBase really fails big time on providing a way to get removed from their "blacklist".

I agree with the assessment, BOGUS and ARROGANT.

Cisco owns this company - so let them know how you feel. IF you happen to own cisco stock, share your opinion at the next stockholder's meeting.

Getting listed on a site that is so unfriendly is like getting a second mugging - first you get hit with user error leading to a virus infection... then after that is all cleared up, no-one in your company can get e-mail out to critical clients.

The folks at Cisco/Ironport/Senderbase NEED to have a way to de-list *rapidly* companies that have been temporarily infected by a spam generating virus or Trojan horse.

"Bogus" and "arrogant" are excellent adjectives. If they fix this, it could be a great service. But right now, their own "reputation" sure needs it's own special 'blacklist'.

on September 11, 2008 10:32 AM
Leave a Comment
Your Name (optional)


Your Email Address (required but won't be displayed on the site)


Your Weblog URL (no weblog? leave it blank)


Type "Jeremy" below (required)


Comment here. Stay on topic (policy). No HTML tags, sorry.


Remember Me



Disclaimer: The opinions expressed here are mine and mine alone. My future, past, or previous employers are not responsible for what I write here, the comments left by others, or the photos I may share. If you have questions, please contact me. Also, I am not a journalist or reporter. Don't "pitch" me.

 

Privacy: I do not share or publish the email addresses or IP addresses of anyone posting a comment here without consent. However, I do reserve the right to remove comments that are spammy, off-topic, or otherwise unsuitable based on my comment policy. In a few cases, I may leave spammy comments but remove any URLs they contain.