I'm using trap address with great results, checking ASSP logs shows bad 
addresses being dropped.  So, I was quite confused when my mail server 
daily report showed:

Recipient address rejected: drdos.info (total: 1)
            1   428f8ae6.6010...@drdos.info


Looking though ASSP's logs, I find the entry.  It identified it as a 
trap address, but appears to have let it though.  Can someone tell me why?



09-03-2013 04:32:53 m1-21573-11823 [Worker_1] [TLS-out] [Trap] 
12.173.72.50 <mcpos...@mdp.edu.ar> penalty trap address: 
428f8ae6.6010...@drdos.info

09-03-2013 04:32:53 m1-21573-11823 [Worker_1] [TLS-out] 12.173.72.50 
<mcpos...@mdp.edu.ar> Message-Score: added 50 (stValencePB) for penalty 
trap address: 428f8ae6.6010...@drdos.info, total score for this message 
is now 50

09-03-2013 04:32:53 m1-21573-11823 [Worker_1] [TLS-out] 12.173.72.50 
<mcpos...@mdp.edu.ar> [SMTP Error] 550 5.1.1 User unknown: 
428f8ae6.6010...@drdos.info

Thanks!

Doug

-- 
Ben Franklin quote:

"Those who would give up Essential Liberty to purchase a little Temporary 
Safety, deserve neither Liberty nor Safety."


------------------------------------------------------------------------------
Symantec Endpoint Protection 12 positioned as A LEADER in The Forrester  
Wave(TM): Endpoint Security, Q1 2013 and "remains a good choice" in the  
endpoint security space. For insight on selecting the right partner to 
tackle endpoint security challenges, access the full report. 
http://p.sf.net/sfu/symantec-dev2dev
_______________________________________________
Assp-test mailing list
Assp-test@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/assp-test

Reply via email to