7. Mail from/to the Internet
Since October 2004 a group of I2P users and postman operate a proxy system for email messages from and to the Internet. Original and retired contributors to the proxy services are: sugadude,jrandom, duck, pipi, mule. Special thanks to cervantes and welterde for providing MX relay facilities and helping to keep this service available on the Internet.
The following chapters aim to explain how sending mails to the Internet and receiving mails from the Internet is implemented, considering security and privacy concerns of I2P’s users as well as the administrative aspects of such a system. If you think we missed some very important issue in this concept, send a mail to postman@mail.i2p or join #mail.i2p on the I2PNet IRC Network.
1. Working with a pseudo-mailidentity
A pseudo-mailidentity is a system that tries to render any form of sender address forgery impossible. If a recipient receives a mail from a certain
address, he can be sure that it was sent by the user behind the mailaddress set in the Return-Path header line. Within the postman.i2p system the identity is created by simple measures:
Every user can only use his OWN address as the Return-Path for an email. The postman.i2p system requires you to authenticate yourself for every mail sent, it does not make a difference whether the recipient is a @mail.i2p user or an Internet destination. smtp.postman.i2p supports the PLAIN and LOGIN mechanism for authentication – all modern mail clients are capable of SMTP authentication.
While a sender can still forge the From: header address, he cannot change the Return-Path: line in the mail, since it’s inserted by the MTA.
2. Basics on forwarding mail to the Internet
Out-proxies and gateways to I2P services must be handled with care. Under all circumstances the anonymity of I2P service users must be
guaranteed. Interacting with Internet communication partners has to be kept strictly separated from I2P internal communication.
Content from the Internet needs to be sanitized before being offered to I2P users or clients. Content that is being sent to the Internet
needs to be sanitized to protect I2P users/clients.
At the moment we’re using a number of relays acting as official MX servers for the domain i2pmail.org.
Those servers both work as incoming and outgoing servers. smtp.postman.i2p and the out-proxy systems communicate solely by using I2P.
The following happens when your mail is sent to the Internet:
I2P mail to the Internet: (assuming sender is jondoe@mail.i2p)
Note:Please note that user@mail.i2p is always used as the sender address. When mail is forwarded to the Internet it will be mangled to: user@i2pmail.org. If you intend to receive mails from the Internet for your postman account, you should always give the
“official” address and not the internal one.
3. Forwarding mail from the Internet
The official in/out-proxies do not carry any important data about I2P mail users at all. Mail is sanitized and forwarded to the smtp.postman.i2p system via I2P. If the machines are raided and confiscated no trace leading to the postman.i2p system can be found (No IPs, no account data). The queue file system for the mailer might contain a few still unsent mails. To protect those the complete queue file system, the I2P installation and all MTA related data reside on a crypto file system. In a nutshell:
Internet mail back to I2P (assuming recipient is jondoe@i2pmail.org)
4. Configuration of delay for outgoing mails
While the smtp.postman.i2p mailer protects users by applying one last level of header sanitisation, the fact that an e-mail is being sent to the Internet alone carries some kind of information that can be used to lower the level of anonymity: an email sent to the Internet means that the sender is connected to I2P at this very moment. For this reason, a delay is being applied to outgoing mails. You can chose between the following:
The Date: header line is always rewritten when mail is being delayed. Users can configure the delay in the [ Manage Account ] area.
Default is a defer-delay for all outgoing mail.
5. Quota … What Quota?
As much as mail communication to and from the Internet is appreciated among fellow I2P users – “fellow” spammers always looking for new and anonymous ways to spam effectively. To be honest, without any security measures the whole postman.i2p system would allow spammers to send large amounts of messages to the Internet – protected by the level of anonymity I2P offers all its users (and not only to those who aren’t spammers).
Since the out-proxy is not supposed to be listed on every blacklist and the operator of the out-proxy certainly does not want to be sued for
allowing spam to be sent using this system, a quota system has been created.
of recipients does not exceed 20 a day.
The quota can be managed in the new
[ Manage Quota ] Area.
Go there to acquire extra accounts via hashcash as well.
6. How to prevent spamming from the Internet?
For now the following model is implemented: