In general, outbound rate limiting is the most important, but as to
outbound scanning, it really depends on your size.
A smaller email system, might be able to depend strictly on outbound
rate limiters, but larger ones need outbound scanning as well, because
of piggyback spammers... the ones where the hacker only trickles out
spam on top of a legitimate email account, to keep volumes low enough to
be under the radar, but if you have 50 or 100 of those, you will get in
trouble.
Of course, virus scanning outbound is a must, and you can start with
outbound scanning but at a 'higher score' than inbound, to at least
identify worst cases.
But once you get to a large size, it does become your responsibility to
be a better netizen, and watch egress traffic more closely.. not that
that happens in the real world often I am afraid, there are some well
known 'too big to block' that seem to put emphasis on inbound, not
outbound, often for purely commercial reasons..
And one thing you didn't mention, how is your use of RBL's? You should
of course use good and sane RBL's BEFORE you pass it on to SA for
scanning, as well as other best practices at the SMTP layer, if only to
reduce loads on your servers. SpamRats, SpamCop, Spamhaus etc..
Once you have done all that, you will find that your filters, whether
SpamAssassin, or other types, should be only catching levels of around
5% of the remaining volumes that reach that point..
You also might investigate custom SA Rule repositories, as the whole
world isn't the same ;)
On 2020-12-16 12:03 a.m., Dr. Christopher Kunz via mailop wrote:
Hi all,
I'm wondering which software is currently the best practice in OSS
(incoming) spam detection and filtering?
We are still using Spam Assassin on our main setup, but I feel that it's
not aggressive enough to cope with current spam patterns, especially
with regards to its rather conservative bayesian learning parameters.
Is it generally being superseded by other OSS solutions, or should I be
looking into fine-tuning it? It's a shared cluster, so per-mailbox
bayesian learning is an important feature for us.
Is it generally best practice to also scan all outgoing e-mail on a
shared e-mail cluster for spamminess?
Best regards,
--ck
_______________________________________________
mailop mailing list
[email protected]
https://list.mailop.org/listinfo/mailop
--
"Catch the Magic of Linux..."
------------------------------------------------------------------------
Michael Peddemors, President/CEO LinuxMagic Inc.
Visit us at http://www.linuxmagic.com @linuxmagic
A Wizard IT Company - For More Info http://www.wizard.ca
"LinuxMagic" a Registered TradeMark of Wizard Tower TechnoServices Ltd.
------------------------------------------------------------------------
604-682-0300 Beautiful British Columbia, Canada
This email and any electronic data contained are confidential and intended
solely for the use of the individual or entity to which they are addressed.
Please note that any views or opinions presented in this email are solely
those of the author and are not intended to represent those of the company.
_______________________________________________
mailop mailing list
[email protected]
https://list.mailop.org/listinfo/mailop