Client wants to whitelist entire country, consequences? Got a ticket this morning that made in a bad way. Client on our OVHcloud shared plan claims 40% of their "legitimate business mail" from a certain country is hitting spam filters. Their proposed fix: whitelist every IP geo-located to that country in SpamAssassin. I checked our aggregate delivery data. That country represents 12% of global spam volume but only 3% of ham. The false positive rate on geo-IP is what worries me. MaxMind updates weekly, stale allocations everywhere, VPN exit nodes mis-tagged. My status page shows three incidents this quarter from over-aggressive country blocks at other providers. Alert fatigue is real for recipients too. Anyone measured collateral damage on country-level whitelists? But geo-IP databases sure do sometimes.
Spam filtering: Client wants to whitelist entire country, consequences?
Country level whitelist is asking for a fire sale of your deliverability!
MaxMind stale? Try RIPE stale! Try APNIC stale! The whole system is held together with zip ties and prayer! — https://www.ripe.net
VPN exit nodes live in those ranges! Your client will whitelist a compromised host in malaysia and wonder why cryptolocker hits their inbox!
I saw a shop whitelist "United states" once! Once! Spam rate went from 2% to 47% in 72 hours!
PacketpunkUma raises a valid concern about stale data, though the mechanism deserves precision. Geo-IP databases rely on RIR delegation records, not BGP advertisements directly. The mismatch between IRR objects and actual routing announcements is precisely where false positives originate.
For context: a /22 allocated to LACNIC might be announced by a HostHatch peer in Amsterdam via a Contabo transit session, carrying a NO_EXPORT community. The geo-IP database still tags it South American. RPKI validation does not solve this; ROAs specify origin AS, not geography.
I measured this last year on a RackNerd mail relay. Approximately 8% of IPs with "country-X" MaxMind tags were physically routed through other regions, and 3% were anycast nodes with no fixed geography at all. Whitelisting by country code implicitly trusts a database with known inaccuracy rates.
The client should identify the sending domain and authenticate via SPF/DKIM alignment. Country-level policy is the wrong abstraction layer.