Skip to content

Spam filtering: Client wants to whitelist entire country, consequences?

Web Hosting by uma 2 replies 167 views
#1

Client wants to whitelist entire country, consequences? Got a ticket this morning that made in a bad way. Client on our OVHcloud shared plan claims 40% of their "legitimate business mail" from a certain country is hitting spam filters. Their proposed fix: whitelist every IP geo-located to that country in SpamAssassin. I checked our aggregate delivery data. That country represents 12% of global spam volume but only 3% of ham. The false positive rate on geo-IP is what worries me. MaxMind updates weekly, stale allocations everywhere, VPN exit nodes mis-tagged. My status page shows three incidents this quarter from over-aggressive country blocks at other providers. Alert fatigue is real for recipients too. Anyone measured collateral damage on country-level whitelists? But geo-IP databases sure do sometimes.

436 days. reboot is surrender.
#2

Country level whitelist is asking for a fire sale of your deliverability!

MaxMind stale? Try RIPE stale! Try APNIC stale! The whole system is held together with zip ties and prayer! — https://www.ripe.net

VPN exit nodes live in those ranges! Your client will whitelist a compromised host in malaysia and wonder why cryptolocker hits their inbox!

I saw a shop whitelist "United states" once! Once! Spam rate went from 2% to 47% in 72 hours!

4 #3

PacketpunkUma raises a valid concern about stale data, though the mechanism deserves precision. Geo-IP databases rely on RIR delegation records, not BGP advertisements directly. The mismatch between IRR objects and actual routing announcements is precisely where false positives originate.

For context: a /22 allocated to LACNIC might be announced by a HostHatch peer in Amsterdam via a Contabo transit session, carrying a NO_EXPORT community. The geo-IP database still tags it South American. RPKI validation does not solve this; ROAs specify origin AS, not geography.

I measured this last year on a RackNerd mail relay. Approximately 8% of IPs with "country-X" MaxMind tags were physically routed through other regions, and 3% were anycast nodes with no fixed geography at all. Whitelisting by country code implicitly trusts a database with known inaccuracy rates.

The client should identify the sending domain and authenticate via SPF/DKIM alignment. Country-level policy is the wrong abstraction layer.

iBGP, eBGP, don't care, just peer

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft