Sam Varshavchik wrote:
K.R. (Randy) Lewis writes:Yes, apologies about that. On the front-end 'smarthost' (ahead of courier) we are using OpenBSD's 'spamd' spam deferral daemon via 'pf' (packet filter). It's somewhat astounding to watch the 1,000's of bogus attempts to send mail into our servers through this system. Almost all (I mean 99% +) of the trapped smtp attempts are from what seem to be compromised machines. They just never come back for a legitimate 2nd attempt to send a message since they don't do a retry after they 'Temporary Failure' thrown by 'spamd' when it GREYLISTs such machines. Anyway, that part works great, and certainly lowers the load on the courier smarthost relay. On the other hand, if he sending system is a legitimate / properly configured estmp host - and knows all the rules - and complies - and retries a message after the GREYLIST hold off period imposed by 'spamd'; it will get relayed to the user account host(s) via the submission port (587) protected on each side by OpenBSD's 'pf' from outside intrusion. This too works great. OK, I read and re-read you comments (above), then re-visited what I'm doing on the user accounts host(s) machines. Yes, I have been filtering via a long-standing 'maildroprc' file that has served quite well, especially BEFORE we went exclusively with the really 'smart' smarthost relay system combination of OpenBSD +'spamd' + courier relay. I can now see that some of the filter rules I had in place were possibly causing a non 'ZERO' exit code due to delivery refusal into a users Maildir. Because (now) most of the offenders are being fended off on the front-end system BEFORE being relayed to the user account hosts, I have decided to remove the maildroprc processing on the end user host(s) from the equation. The only thing 'maildrop' that's happening is running message deliveries through 'spamprobe' (via $HOME/.mailfilter) and deciding which user sub-maildir gets the message. A message will go into either 'Maildir/new' or 'Maildir/.spam/new' based on its score - but it WILL get delivered. There is no non-ZERO exit code that can find its way back upstream. Hopefully this change from the previous configuration will settle things out for my trusted users. Thanks for your great work. Randy
-- ![]() |
begin:vcard fn:K. Randy Lewis n:Lewis;K. Randy org:RTMX Networking, LLC adr;dom:;;PO Box 1030;Hillsborough;NC;27278 email;internet:[email protected] title:Save Gas -- Telecommute with RTMX ! tel;work:919 644 7869 tel;fax:919 724 4439 x-mozilla-html:TRUE url:http://www.rtmx.net version:2.1 end:vcard
------------------------------------------------------------------------------ SF.Net email is Sponsored by MIX09, March 18-20, 2009 in Las Vegas, Nevada. The future of the web can't happen without you. Join us at MIX09 to help pave the way to the Next Web now. Learn more and register at http://ad.doubleclick.net/clk;208669438;13503038;i?http://2009.visitmix.com/
_______________________________________________ courier-users mailing list [email protected] Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users

