On 2019-12-19 17:45, Chip M. wrote:
Another interesting "tell" is its sloppy/ridiculous SPF: v=spf1 ip4:52.0.0.0/8 ip4:3.0.0.0/8 ip4:54.0.0.0/8 ip4:107.0.0.0/8 ip4:18.0.0.0/8 ip4:34.0.0.0/8 -all Perhaps they're anticipating Amazon gobbling up more IP space?!?
sadly spf supports 0.0.0.0/0, if spf was designed sane it would be max 256 ipv4 and one ipv6
if one create a perl module to calc ipv4 / ipv6 in that it can see if ips is under 256 to be accepted as pass, then it changes
time to block domains with over so many ips