In general, outbound rate limiting is the most important, but as to outbound scanning, it really depends on your size.

A smaller email system, might be able to depend strictly on outbound rate limiters, but larger ones need outbound scanning as well, because of piggyback spammers... the ones where the hacker only trickles out spam on top of a legitimate email account, to keep volumes low enough to be under the radar, but if you have 50 or 100 of those, you will get in trouble.

Of course, virus scanning outbound is a must, and you can start with outbound scanning but at a 'higher score' than inbound, to at least identify worst cases.

But once you get to a large size, it does become your responsibility to be a better netizen, and watch egress traffic more closely.. not that that happens in the real world often I am afraid, there are some well known 'too big to block' that seem to put emphasis on inbound, not outbound, often for purely commercial reasons..

And one thing you didn't mention, how is your use of RBL's? You should of course use good and sane RBL's BEFORE you pass it on to SA for scanning, as well as other best practices at the SMTP layer, if only to reduce loads on your servers. SpamRats, SpamCop, Spamhaus etc..

Once you have done all that, you will find that your filters, whether SpamAssassin, or other types, should be only catching levels of around 5% of the remaining volumes that reach that point..

You also might investigate custom SA Rule repositories, as the whole world isn't the same ;)



On 2020-12-16 12:03 a.m., Dr. Christopher Kunz via mailop wrote:
Hi all,

I'm wondering which software is currently the best practice in OSS (incoming) spam detection and filtering?

We are still using Spam Assassin on our main setup, but I feel that it's not aggressive enough to cope with current spam patterns, especially with regards to its rather conservative bayesian learning parameters.

Is it generally being superseded by other OSS solutions, or should I be looking into fine-tuning it? It's a shared cluster, so per-mailbox bayesian learning is an important feature for us.

Is it generally best practice to also scan all outgoing e-mail on a shared e-mail cluster for spamminess?

Best regards,

--ck


_______________________________________________
mailop mailing list
[email protected]
https://list.mailop.org/listinfo/mailop




--
"Catch the Magic of Linux..."
------------------------------------------------------------------------
Michael Peddemors, President/CEO LinuxMagic Inc.
Visit us at http://www.linuxmagic.com @linuxmagic
A Wizard IT Company - For More Info http://www.wizard.ca
"LinuxMagic" a Registered TradeMark of Wizard Tower TechnoServices Ltd.
------------------------------------------------------------------------
604-682-0300 Beautiful British Columbia, Canada

This email and any electronic data contained are confidential and intended
solely for the use of the individual or entity to which they are addressed.
Please note that any views or opinions presented in this email are solely
those of the author and are not intended to represent those of the company.
_______________________________________________
mailop mailing list
[email protected]
https://list.mailop.org/listinfo/mailop

Reply via email to