Email challenge-response

From Citizendium
Revision as of 09:37, 21 September 2009 by imported>David MacQuigg (stub article)
Jump to navigation Jump to search
Due to technical limitations, this article uses an unusual title. It should be called  Email challenge/response.

Challenge/Response (C/R) is a method of filtering spam email.

The sender is asked to respond to a challenge, on the theory that only legitimate senders with important messages will respond.

C/R is controversial due to its potential for generating unwanted challenges to forged sender addresses.

The sender address may be:

1) A fictitious or invalid address.
2) An address of a real person, either
  a) the actual sender's address, or
  b) a forged address.

C/R is 100% effective in eliminating category 1. Category 2a is less than 100% effective identifying legitimate senders, because some will not respond to the challenge.

Category 2b is almost always an annoyance to the person whose address was forged. Many will report these challenges as "backscatter spam". Few will take action to avoid such backscatter.

Backscatter spam may be reduced by publishing an SPF record. Spammers generally avoid using return addresses that are protected by SPF.

A properly-designed C/R system will not send a challenge to an SPF-protected sender's address, unless that address passes the SPF check. In that case, a challenge to a forged address should be a welcome alert to its recipient, leading to correction of a problem on the recipient's side.