Two related suggestions.
(1) LHS (left-hand-side) rules
Any incoming mail message whose putative sender matches:
do-not-reply@
do.not.reply@
donotreply@
no-reply@
no.reply@
noreply@
and which is directed to any of the Mailman standard aliases can
be rejected (not bounced [1]) with SMTP status 550 (extended status
5.7.1) since either:
(a) it's a forgery, therefore there's no point in letting
Mailman attempt to emit a reply -- or even in accepting
the message to begin with.
(a) it's not a forgery, therefore there's no point in trying
to reply to it. (Nor is there any point in permitting it
to subscribe to a list or send any traffic to one.)
Arguably, this could be done in some MTAs by configuring rejection
of those LHS patterns on a per-local-user basis; but I'll argue that
doing this in Mailman itself would be more useful, since many (perhaps
most) sites don't use per-local-user configuration (and perhaps don't
know how). Moreover, any site running multiple mailing lists would
need to set this up for every Mailman alias for every mailing list --
so it seems simpler to handle it inside Mailman itself.
My guess is that this should be a switchable feature, named something
like "reject-noreplies". (Not that I can envision a need to switch it
off, but I think it'd be more conversative to have that option.)
(2) sender rules
Any incoming mail message whose putative sender matches the list below
can also be rejected (SMTP status 550, extended status 5.7.1) because
these addresses will never send traffic to any mailing list nor
subscribe to any mailing list. There's thus no point in expending
the bandwidth/CPU necessary to process them, nor in forwarding them on
to list admins for possible approval -- any message from these addresses
to any Mailman-related address is invariably a phish attempt.
I'm sure this list is incomplete; I built it by looking at incoming
attempts received locally in 2007. It's not meant to be complete,
only illustrative.
Again, this could be done at the MTA level by blocking on a per-local-user
basis, but (as above) I think wiring it into Mailman would make it useful
to people who do not have their MTAs so configured.
And this should probably also be switchable feature, perhaps named
"reject-obvious-phishes".
More comments below this list.
acc-overview(a)paypal.com
account-update(a)amazon.com
account.issue(a)paypal.com
account.protection(a)ebay.com
account.support(a)chaseonline.com
account(a)amazon.com
account(a)bankofamerica.com
account(a)capitalone.com
account(a)chase.com
account(a)ebay.com
account(a)paypal.com
accounts(a)amazon.com
accounts(a)bscu.org
accounts(a)chaseonline.com
accounts(a)downeysavings.com
accounts(a)mybankfirstunited.com
accounts(a)paypal.com
accounts(a)regions.com
accounts(a)searscard.com
accounts(a)wellsfargo.com
accounts_support(a)paypal.com
accountservice(a)bankofamerica.us
accountupdate(a)chase.com
admin(a)bankofhanover.com
admin(a)paypal.com
administrator(a)paypal.com
ads(a)servicecu.org
alertingservice(a)searscard.com
alertsrobots(a)bankofamerica.com
assistance(a)paypal.com
auto-confirm(a)amazon.com
aw-confirm(a)ebay.com
aw-confirm(a)paypal.com
aw.confirm(a)paypal.com
aw.confirm(a)regions.com
banking(a)chase.com
bankofamericaalerts(a)alerts.bankofamerica.com
bankofamericaalerts(a)bankofamerica.com
billing(a)ebay.com
billing(a)paypal.com
boa(a)bankofamerica.com
cardpayments(a)citibank.com
cards(a)paypal.com
cgi-bin(a)paypal.com
chase(a)chase.com
chase(a)chaseonline.com
chase(a)notify.chase.com
chase(a)service.com
chasecardservices(a)notify.chase.com
chaseco(a)chase.com
chaseonline(a)chase.com
chaseonlinealerts(a)alerts.chase.com
chaseonlinealerts(a)chase.com
checkout(a)ebay.com
closed(a)paypal.com
confirm145(a)paypal.com
confirmer(a)paypals.com
contact(a)paypal.com
customcare(a)paypal.com
customecare(a)paypal.com
customer-service(a)westernunion.com
customer-services(a)bankofamerica.com
customer.service(a)capitalone.com
customer.service(a)chase.com
customer.support(a)capitalone.com
customer.support(a)chase.com
customer.support(a)paypal.com
customer(a)bankofamerica.com
customer(a)paypal.com
customer(a)redwood-bank.com
customercare(a)amazon.com
customercare(a)paypal.com
customers(a)amazon.com
customerservice(a)bankofamerica.com
customerservice(a)paypal.com
customerservice(a)wachovia.com
customersupport(a)citibank.co.uk
dncu(a)dncu.org
do-not-replay(a)azfcu.org
do-not-replay(a)chase.com
do-not-replay(a)xfcu.org
do-not-reply(a)azfcu.org
do-not-reply(a)bankofamerica.com
do-not-reply(a)chase.com
do-not-reply(a)customers.cacu.net
do-not-reply(a)germanamericanbancorp.com
do-not-reply(a)lacapfcu.org
do-not-reply(a)paypal.com
do-not-reply(a)regions.com
financial(a)regions.com
flafstar-bank(a)security.org
fraud(a)paypal.com
fraud_help(a)chase.com
info(a)azfcu.org
info(a)bankofamerica.com
info(a)ebay.com
info(a)paypal.com
info(a)westernunion.com
member(a)ebay.com
member(a)paypal.com
memsvc(a)vacu.org
mesage.center(a)chase.com
message.center(a)chase.com
message(a)ebay.com
message(a)northforkbank.com
messages(a)ebay.com
militarybankalerts(a)alerts.bankofamerica.com
militarybankalerts(a)bankofamerica.com
mychase(a)chase.com
no-reply(a)chase.com
no-reply(a)ebay.com
no-reply(a)maybank.org
no.reply(a)ebay.com
no.reply(a)paypal.com
noreply(a)bankofamerica.com
noreply(a)germanamericanbancorp.com
noreply(a)westernunion.com
notice.alert(a)bankofamerica.com
notice(a)azfcu.org
notice(a)bankofamerica.com
notice(a)chase.com
notice(a)chaseonline.com
notice(a)ebay.com
notice(a)paypal.com
notice(a)wellsfargo.com
notices.alert(a)bankofamerica.com
office(a)paypal.com
office(a)westernunion.com
online-banking(a)chase.com
online-support(a)online-bankofamerica.com
online-survey(a)chase.com
online.bank(a)regions.com
online.banking(a)regions.com
online.services(a)wachovia.com
online(a)bankofamerica.com
online(a)paypals.com
onlineaccount(a)capitalone.com
onlinebanking.alert(a)bankofamerica.com
onlinebanking(a)alert.bankofamerica.com
onlinebanking(a)bankofamerica.com
onlinebanking(a)wellsfargo.com
onlinesecurity(a)bankofamerica.com
onlinesecurity(a)wachovia.com
onlineservice(a)bankofamerica.com
onlineservice(a)capitalone.com
onlineservice(a)paypal.com
onlineservice(a)wachovia.com
onlineservice(a)wellsfargo.com
onlineservices(a)bankofamerica.com
onlineservices(a)wachovia.com
onlinesrvices(a)wachovia.com
onlinesupport(a)pafcu.org
onlineupdate(a)paypal.com
payment(a)paypal.com
paymentprotector(a)cuna.org
paypal-acc(a)paypal.com
paypal-account(a)paypal.com
paypal-service(a)paypal.com
paypal(a)onlinesecure.com
powersellersinfo(a)ebay.com
privacy(a)regions.com
pw-confirm(a)chase.com
renew(a)azfcu.org
renew(a)tscu.org
resolution-center(a)paypal.com
reward(a)chaseonline.com
reward(a)downeysavings.com
rewards(a)chase.com
rewards(a)westernunion.com
secure-acc(a)amazon.com
secure-acc(a)paypal.com
secure-bank(a)regions.com
secure-cc(a)capitalone.com
secure-cc(a)paypal.com
secure-login(a)chase.com
secure-login(a)regions.com
secure(a)boa.com
secure(a)paypal.com
secure(a)wachovia.com
secure(a)watermarkcu.org
secure(a)wellsfargo.com
security.alert(a)bankofamerica.com
security(a)amazon.com
security(a)baefcu.org
security(a)bankofamerica.com
security(a)bankofhanover.com
security(a)boa.com
security(a)capitalone.com
security(a)cefcu.net
security(a)chase.com
security(a)comchoicecu.org
security(a)dncu.org
security(a)ebay.com
security(a)ncua.gov
security(a)paypal.com
security(a)regions.com
security(a)security.com
security(a)transwestcu.com
security(a)visa.com
security(a)wellsfargo.com
security_alert(a)citizensbank.com
service-account(a)paypal.com
service-bank(a)regions.com
service.account(a)capitalone.com
service.customer(a)paypal.com
service(a)amazon.com
service(a)azfcu.org
service(a)bankofamerica.com
service(a)bankofamerlca.com
service(a)bankofhanover.com
service(a)capitalone.com
service(a)chase.com
service(a)chaseonline.chase.com
service(a)chaseonline.com
service(a)chesterfieldfcu.net
service(a)cscu.org
service(a)downeysavings.com
service(a)ebay.com
service(a)mandtbank.com
service(a)midamericabank.com
service(a)mybankfirstunited.com
service(a)ncua.gov
service(a)paypal.com
service(a)paypal.it
service(a)paypals.com
service(a)regions.com
service(a)secure.regions.com
service(a)visa.com
service(a)wachovia.com
service(a)wamu.com
service(a)warrenfcu.com
service(a)wellsfargo.com
service(a)westernunion.com
service_banking(a)chase.com
servicecenter(a)bankofamerica.us
servicecenter(a)firstinterstatebank.com
services(a)bankofamerica.com
services(a)chesterfieldfcu.net
services(a)downeysavings.com
services(a)ebay.com
services(a)paypal.com
services(a)watermarkcu.org
sitesecurity(a)citibank.com
store-news(a)amazon.com
support(a)amazon.com
support(a)capitalone.com
support(a)chase.com
support(a)ebay.com
support(a)flagstar.com
support(a)online-bankofamerica.com
support(a)paypal.com
support(a)wamu.com
support(a)wellsfargo.com
support(a)yahoo.com
survery(a)twcu.org
survey(a)arizonafederal.org
survey(a)azfcu.org
survey(a)bankofhanover.com
survey(a)cuna.org
survey(a)downeysavings.com
survey(a)tyndallcreditunion.com
suspension(a)ebay.com
unsuspend(a)paypal.com
update-accounts(a)paypal.com
update.profile(a)amazon.com
update(a)boa.com
update(a)paypal.com
update(a)wellsfargo.com
updating(a)capitalone.com
web-info(a)cuna.org
web-service(a)mybankfirstunited.com
webmaster(a)paypal.com
westernunionalerts(a)westernunion.com
westernunionresponse(a)westernunion.com
In both these cases, the check can be carried out by doing some
simple string-matching. The second list will need ongoing (and
careful) maintenance -- and one way to achieve that might be to
enlist the cooperation of the domains in question. However,
note that (a) under-inclusion is no worse than the current
situation and (b) over-inclusion is unlikely given even a modicum
of scrutiny applied to prospective list entries.
---Rsk
[1] The difference between a reject and a bounce: a reject is performed
by emitting the appropriate SMTP status code and closing the connection;
that is, the message is refused while the SMTP connection is open from
the sending side. A bounce is performed by accepting the message
(again, emitting the appropriate SMTP status code), then performing
further processing, deciding not to accept the message, and attemping
to "return" the message to the putative sender. The simplest way
of putting this is "reject good, bounce bad", since bounces invariably
result in outscatter (aka "backscatter"), which is a form of spam,
which in turn will cause sufficiently egregious emitters to be
(correctly) blacklisted. Note as well that various mitigating
strategies designed to blunt the effects of bounce-instead-of-reject
policies lose entirely due to rampant forgery, DNS redirection,
an estimated 100M+ fully-compromised systems, and widespread failure
of end-user ISPs to control outbound SMTP abuse. So saying that it's
immensely preferable to reject rather than bounce is an understatement.