They can white list based on IP address (as bdragon pointed out). Currently there is a system by which a custom header is created. That's been used to identify spam by spamassassin. Of course, this is fairly easily spoofable but I bet using some kind of public/private key combination they can decrease the amount of spoofing. Maybe requiring a reverse connection to verify the source is not spoofed. There are a lot of ways to verify.
no subject
Date: 2006-02-08 02:07 am (UTC)