I'm using trap address with great results, checking ASSP logs shows bad addresses being dropped. So, I was quite confused when my mail server daily report showed:
Recipient address rejected: drdos.info (total: 1) 1 428f8ae6.6010...@drdos.info Looking though ASSP's logs, I find the entry. It identified it as a trap address, but appears to have let it though. Can someone tell me why? 09-03-2013 04:32:53 m1-21573-11823 [Worker_1] [TLS-out] [Trap] 12.173.72.50 <mcpos...@mdp.edu.ar> penalty trap address: 428f8ae6.6010...@drdos.info 09-03-2013 04:32:53 m1-21573-11823 [Worker_1] [TLS-out] 12.173.72.50 <mcpos...@mdp.edu.ar> Message-Score: added 50 (stValencePB) for penalty trap address: 428f8ae6.6010...@drdos.info, total score for this message is now 50 09-03-2013 04:32:53 m1-21573-11823 [Worker_1] [TLS-out] 12.173.72.50 <mcpos...@mdp.edu.ar> [SMTP Error] 550 5.1.1 User unknown: 428f8ae6.6010...@drdos.info Thanks! Doug -- Ben Franklin quote: "Those who would give up Essential Liberty to purchase a little Temporary Safety, deserve neither Liberty nor Safety." ------------------------------------------------------------------------------ Symantec Endpoint Protection 12 positioned as A LEADER in The Forrester Wave(TM): Endpoint Security, Q1 2013 and "remains a good choice" in the endpoint security space. For insight on selecting the right partner to tackle endpoint security challenges, access the full report. http://p.sf.net/sfu/symantec-dev2dev _______________________________________________ Assp-test mailing list Assp-test@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/assp-test