The basic assumption for outbound mail is that the people sending it are sending legitimate content. The problem is that this is not a valid assumption. If one customer, among hundreds or thousands, starts sending outbound spam, FOSE outbound IP addresses can get blacklisted. When that happens, recipients who use that 3rd party blacklist block the mail of our outbound IP. The net result is that customers can get blocked by receivers through no fault of their own. The actions of a couple of customers can affect everyone.
There are any number of ways that users computers can get infected with a virus that flips it into a botnet, but the net result is the same – it starts to emit spam.
To the outside world, the IP that is used to send out the mail looks like a spam source. However, it is not a singular source of spam because there are so many IPs hidden behind that single IP. Only a small subset of them, usually one or two, are responsible for sending out the spam. It doesn’t matter, however, because once a source IP is identified as sending out spam, it poses problems for everyone who shares that IP space.
FOSE’s situation is different than a service like Hotmail or Gmail, but the problem is still the same – our outbound reputation is compromised because in a shared environment with many users, the spammer hides amongst hundreds of others.
When one customer starts sending out spam, it often sends out spam to 3rd party operators of blocklists. When it does, that blocklist labels that outbound IP as abusive; unfortunately, other customers are also using that IP but are not using it to send out spam.
The net result in Figure 6 is following: It severely degrades our reputation and we have to embark on many steps to reclaim it.
Our outbound IP reputation has now been severely degraded. Many customers have the potential to see their mail rejected because of the actions of a few.
We now shift our perspective in another direction: having acknowledged that outbound spam is a serious issue, what do we do? How do we handle outbound mail that we detect as spam?
[1] Sometimes this assumption is true, sometimes not. Spam traps are a good way of harvesting spam but cannot always be used with 100% reliability. They are prone to false positives.
[2] Frank also may be rather obstinate and unreasonable. Sometimes he is very difficult to get a hold of, complicating the delisting process.