I asked this yesterday right before the Hotmail issue came to light...so
I'll ask again to see if there are any thoughts:
Setting up a 'bad users/stalker' filter (BOUNCEONLYIFYOUMUST) in Declude
in which I have my Yahoo address in the external file as a test address.
The bounced email
SMTP-(0254) MAIL FROM:[EMAIL PROTECTED] 04:29 14:42
s missing the preceeding to wrap the address
That's the issue...the fact/problem is Declude or Imail is the one who
wrote that command to Yahoo's server that way. According to specs, we
do not put around emails in bounce messages.
Setting up a 'bad users/stalker' filter (BOUNCEONLYIFYOUMUST) in Declude
in which I have my Yahoo address in the external file as a test address.
The bounced email (VIEWERABUSE.EML) looks like an 'unknown user' bounce
with a copy to me, so the sender thinks the person is no longer here.
In my
I have this in my $default$.junkmail file:
WHITELISTFILE c:\IMail\Declude\whitelistfile.txt
The whitelistfile.txt has a format of:
FROM [EMAIL PROTECTED]
FROM @katz-media.com
FROM @NielsenMedia.com
FROM @sellstufflocal.com
FROM @evertz.com
FROM @continentaltvsales.com
FROM
The whitelistfile.txt has a format of:
FROM [EMAIL PROTECTED]
So, whitelists for IP's and REVDNS should remain in the GLOBAL.CFG?
Does a single address get handled as both TO and FROM? I used both in
the global.
Robert
---
[This E-mail was scanned for viruses by Declude Virus
So, whitelists for IP's and REVDNS should remain in the GLOBAL.CFG?
Correct.
Does a single address get handled as both TO and FROM? I used both in
the global.
The WHITELISTFILE option only works on the sender's address.
-Scott
Thanks
I have about 15...why?
Robert
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Jason (by way
of R. Scott Perry [EMAIL PROTECTED])
Sent: Thursday, November 06, 2003 4:43 PM
To: [EMAIL PROTECTED]
Subject: [Declude.JunkMail] OT: Do you use ColdFusion?
I
---begin snip
Mail Server: 218.253.238.146 for wjla.com [wjla.com]
DNS Pointer: cm218-253-238-146.hkcable.com.hk
Host Name: wjla.com
Triggers: SPAMCHK, MYHELOTEST, SPAMCOP, IPNOTINMX, WEIGHT10,
WEIGHT20, WEIGHT70, WEIGHT130, FIVETEN-SPAM (Blocked - see
Can someone give me the order(IMAIL/DECLUDE JM/DECLUDE VIRUS) in which an
email is processed?
I have Imail rules which 'I think' are setup properly:
B~(name=.*\.pif\s|name=.*\.exe\s|name=.*\.lnk\s):NUL
B~(begin 6.*\.pif\s|begin 6.*\.exe\s|begin 6.*\.lnk\s):NUL
but I still see these emails in
So, your internal users are sending out spam with a score of over
150?
I use Imail to store and forward email for another domain we use to
provide email for some of our clients.
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-mail came from the
I'm getting complaints about bounce messages from spammers that are using
internal emails as the FROM person. The bounce messages go back to the
original recipient who never sent the email in the first place.
Is this a valid command at the top of the bounce message that declude would
send out if
07/22/2003 15:01:57 Q8a220d1a00b4cc34 Msg failed WEIGHT150 (Weight of 169
reaches or exceeds the limit of 150.). Action=IGNORE.
WEIGHT 150 ACTION SHOULD BOUNCE...WHY DID IT IGNORE?
TWO SECONDS LATER:
07/22/2003 15:01:59 Q8a2314af00a2d099 Msg failed WEIGHT150 (Weight of 193
reaches or exceeds
That's because Declude JunkMail is very flexible, and has per-user,
per-domain, incoming, outgoing, and now even sender actions. So a single
test may have many different actions.
In this case, you have a configuration file with WEIGHT150 BOUNCE, and
another that either has WEIGHT150 IGNORE or no
I would recommend using LOGLEVEL HIGH in the \IMail\Declude\global.cfg
file. When doing so, Declude JunkMail will record in the log file which
configuration file it is using. That will make it easier to see which
config file has WEIGHT150 IGNORE (or no action listed for
WEIGHT150). My
I'm having an issue with some domains that are supposed to be
whitelisted, but still failing a test:
I Hold on SPAMDOMAINS
In my Global:
WHITELIST FROM .paypal.com
Log snippet:
07/19/2003 01:26:43 Qd69101bd009c5c65 Msg failed SPAMCHK (Message failed
SPAMCHK: 60.). Action=WARN.
07/19/2003
I got one too...wierd.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] Behalf Of Dan Geiser
Sent: Friday, June 06, 2003 2:16 PM
To: Declude JunkMail
Subject: [Declude.JunkMail] Recent Message From
[EMAIL PROTECTED]
Hello, All,
A little less than 1/2 hour I
??? :)
Robert Forsyth
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-mail came from the Declude.JunkMail mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type unsubscribe Declude.JunkMail. The archives can be found
To send an alert email to multiple recipients, the syntax is:
To: %MAILFROM%, [EMAIL PROTECTED]
Actually, the IMail1.exe program that Declude uses to send the
E-mail won't
accept that, because of the space in there (it is very picky!). If you
change it to:
To: %MAILFROM%,[EMAIL
I'm see an on-again off-again occurrence of emails getting through that
should of failed.
Below are the headers...can anyone shed some light?
Thanks
Robert
Received: from relay04.valueweb.net [216.219.253.238] by wjla.com with ESMTP
(SMTPD32-7.06) id A72D1CA50104; Tue, 25 Mar 2003 12:51:41
I would love it too. [EMAIL PROTECTED]
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Darrell L.
Sent: Friday, February 28, 2003 9:15 AM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.JunkMail] Log Analyzer - Comments Needed
Keith,
I have a beta
24 hours with declude and 2900 emails stopped! Awesome product!
Robert Forsyth
Director of Internet Operations
ABC 7/Newschannel 8
703-236-9580 (direct)
703-236-9259 (fax)
---
[This E-mail scanned for viruses by Declude Virus]
---
[This E-mail was scanned for viruses by Declude Virus (http
21 matches
Mail list logo