Comment 2 for bug 266316

Revision history for this message
Mark Sapiro (msapiro) wrote :

I am closing this because mailman is doing what it should.
The users were unsubscribed by bounce processing. The
settings for this are list by list on the Bounce processing
page of the admin web interface.

Mailman registers the bounce notices that it receives in
response to post deliveries and handles them according to
bounce settings. The remote server has no direct involvement
with the unsubscribe. It just returns a notice to mailman
just like the notice returned to you when you mailed these
addresses directly. The process is described on the Bounce
processing page.

And yes, bounce notifications can be spoofed, but with
normal default settings, the spoofer would have to send 5
spoofed notices on different days, and then the member would
have list delivery disabled and be sent a warning, and be
sent two more warnings at one week intervals before being
unsubscribed. Also, you can select the option to notify the
list owner when the subscription is disabled, so
unsubscribing a user by spoofing bounces is not likely to be
successful if the user actually has any interest in the list.