Skip to content

Instantly share code, notes, and snippets.

@DeviaVir
Created January 8, 2015 08:39
Show Gist options
  • Save DeviaVir/0c975a2c6bb8bd956312 to your computer and use it in GitHub Desktop.
Save DeviaVir/0c975a2c6bb8bd956312 to your computer and use it in GitHub Desktop.
Formal complaint to Spamhaus
Dear Spamhaus,
We would like to submit a formal complaint regarding one of your divisions, the CBL (CBL.abuseat.org), and hope you will swiftly take action regarding these practices.
Two days ago, our customers started to notify us that we were blacklisted.
The CBL had picked this up using a sinkhole, and had banned our IP's. Upon investigation we found several hacked wordpress and joomla websites, that were being abused, we cleaned these up and forced the customers to upgrade.
This seemed to not please the CBL, however, as they already enforced a 48 hour ban on all of our IP's. One IP address which was not even active the last month. Imagine our surprise when we tried to switch one out to use it. I think it's outrageous to immediately enforce a 48 hour ban on any IP connecting to the sinkhole, these IP's are used to send legitimate e-mail (usually), and all of our customers are impacted by this practice.
We would like to suggest to you to use a different practice, please do not ban IP's for 48 (!) hours by default when detecting connections, at the very least you could first inform the host and/or enforce a smaller timespan (think 3/6/12 hours).
Thanks to further human errors at the CBL, still some of our IP's have now been banned for more than four days, causing outrage amongst our customers, as we have been unable to quickly replace these IP addresses due to the way it is set up at Amazon, and using these IP addresses for multiple reasons.
We look forward to your response. Thanks in advance.
@DeviaVir
Copy link
Author

DeviaVir commented Jan 8, 2015

Dear Spamhaus,

Building on the previous complaint, please change this practice (see picture attached), as well.

You are already using (the old version of) Google's ReCaptcha, stop punishing me for looking up to check if my IP has finally (!) been delisted. This is ridiculous.

screen shot 2015-01-08 at 09 46 04

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment