From: Brad Templeton <brad@templetons.com>
People are free to run C/R systems. A system designed for widescale use
should indeed follow a set of principles:
a) Properly handle mailing list mail
b) Never challenge a reply to an E-mail you sent, even if you sent
it from elsewhere and a different account which aliases over to
the real mailbox.
c) Include protections against loops, obviously and challenging other
challenges, autoresponses etc.
d) Provide a means to allow the user to review all their blocked mail
(sorted by spam score) to catch the people who did not respond
to the challenge. Yes, these happen regularly even with simple
challenges, and not because the other person is lazy.
e) If you don't do (d), provide some other means for anonymous mail
and yes, mail from people with broken mailers, to make it to you.
ok. here is my system. i posted one on my site, but i don't think anybody
read it, so i post the revised system here: