[postfix-users] Postfix + SpamAssassin + Amavisd-New + ClamAV

2007-07-27 Thread Donny Christiaan

Guyz,

Mail server saya menggunakan Postfix+SpamAssassin+Amavisd-New+ClamAV
dan saya setting di amavisd.conf

$sa_spam_subject_tag = '[IS-SPAM] ';
$final_spam_destiny   = D_DISCARD;
$final_bad_header_destiny = D_DISCARD;

dan memang semua email yg bener2 SPAM tidak diteruskan ke user tetapi 
saya lempar ke mailbox [EMAIL PROTECTED]
tetapi yg jadi pertanyaan saya ada beberapa email spam yang tetep bisa 
lolos ke user padahal memang terdetect oleh SpamAss/Amavis dan di 
Subject diberi tag [IS-SPAM] . Kira-kira kenapa ya ?


Mohon pencerahannya ...


 Original Message 
Subject:SPAM FROM [202.71.103.211]
Date:   Thu, 26 Jul 2007 06:55:00 +0700 (WIT)
From:   Content-filter at mail.insera-sena.com [EMAIL PROTECTED]
To: [EMAIL PROTECTED]



Internal reference code for the message is 19701-05/qs7R7eSFclUM

First upstream SMTP client IP address: [202.71.103.211] mail211.wpdns.com
According to a 'Received:' trace, the message originated at: [200.88.203.16],
 tdev203-16.codetel.net.do [200.88.203.16]

Return-Path: [EMAIL PROTECTED]
X-Mailer: Microsoft Outlook Express %OE_VERSION%OE_SUBVERSION
Message-ID: [EMAIL PROTECTED]
Subject: SPAM LOW Unbelievable Quality
The message has been quarantined as: spam-qs7R7eSFclUM.gz

The message WAS NOT relayed to:
[EMAIL PROTECTED]:
  254 2.7.0 Ok, discarded, id=19701-05 - SPAM

SpamAssassin report:
Spam detection software, running on the system mail.domain.com, has
identified this incoming email as possible spam.  The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email.  If you have any questions, see
postmaster for details.

Content preview:  EXQUISITE REPLICA WATCHESROLEX, CARTIER, BREITLING AND
 MORE...VISIT OUR ONLINE SHOP! EXQUISITE REPLICA WATCHES ROLEX, CARTIER,
 BREITLING AND MORE... [...] 


Content analysis details:   (33.5 points, 5.0 required)

pts rule name  description
 -- --
1.3 UNRESOLVED_TEMPLATEHeaders contain an unresolved template
0.8 DATE_IN_PAST_06_12 Date: is 6 to 12 hours before Received: date
2.9 REPLICA_WATCH  BODY: Message talks about a replica watch
0.0 HTML_MESSAGE   BODY: HTML included in message
3.5 BAYES_99   BODY: Bayesian spam probability is 99 to 100%
   [score: 1.]
1.9 DNS_FROM_RFC_BOGUSMX   RBL: Envelope sender in
   bogusmx.rfc-ignorant.org
1.6 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
  [Blocked - see http://www.spamcop.net/bl.shtml?200.88.203.16]
1.6 URIBL_SBL  Contains an URL listed in the SBL blocklist
   [URIs: ouonfnewdiett.com]
3.0 URIBL_BLACKContains an URL listed in the URIBL blacklist
   [URIs: ouonfnewdiett.com]
4.5 URIBL_SC_SURBL Contains an URL listed in the SC SURBL blocklist
   [URIs: ouonfnewdiett.com]
3.8 URIBL_AB_SURBL Contains an URL listed in the AB SURBL blocklist
   [URIs: ouonfnewdiett.com]
4.1 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist
   [URIs: ouonfnewdiett.com]
3.0 URIBL_OB_SURBL Contains an URL listed in the OB SURBL blocklist
   [URIs: ouonfnewdiett.com]
1.4 UPPERCASE_75_100   message body is 75-100% uppercase



--
Best Regards,
Donny Christiaan.
[EMAIL PROTECTED]



Re: [postfix-users] Postfix + SpamAssassin + Amavisd-New + ClamAV

2007-07-27 Thread Tukang Internet

Dibawah ada info :
1.6 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
 [Blocked - see 
http://www.spamcop.net/bl.shtml?200.88.203.16]



Mungkin ada baiknya memperketat di MTA nya :
smtpd_recipient_restrictions = permit_mynetworks,
   reject_rbl_client relays.ordb.org,
   reject_rbl_client sbl-xbl.spamhaus.org,
   reject_rbl_client list.dsbl.org,
   reject_rbl_client relays.ordb.org,
   reject_rbl_client bl.spamcop.net,
   reject_rbl_client opm.blitzed.org,
   reject_rbl_client cbl.abuseat.org,
   reject_rbl_client dul.dnsbl.sorbs.net,

jadi kalo kedetek sama salah satu rbl_check di atas.
langsung reject, belum sampai tahap send DATA.

Donny Christiaan wrote:

Guyz,

Mail server saya menggunakan Postfix+SpamAssassin+Amavisd-New+ClamAV
dan saya setting di amavisd.conf

$sa_spam_subject_tag = '[IS-SPAM] ';
$final_spam_destiny   = D_DISCARD;
$final_bad_header_destiny = D_DISCARD;

dan memang semua email yg bener2 SPAM tidak diteruskan ke user tetapi
saya lempar ke mailbox [EMAIL PROTECTED]
tetapi yg jadi pertanyaan saya ada beberapa email spam yang tetep bisa
lolos ke user padahal memang terdetect oleh SpamAss/Amavis dan di
Subject diberi tag [IS-SPAM] . Kira-kira kenapa ya ?

Mohon pencerahannya ...


 Original Message 
Subject: SPAM FROM [202.71.103.211]
Date: Thu, 26 Jul 2007 06:55:00 +0700 (WIT)
From: Content-filter at mail.insera-sena.com [EMAIL PROTECTED]
To: [EMAIL PROTECTED]



Internal reference code for the message is 19701-05/qs7R7eSFclUM

First upstream SMTP client IP address: [202.71.103.211] mail211.wpdns.com
According to a 'Received:' trace, the message originated at: 
[200.88.203.16],

 tdev203-16.codetel.net.do [200.88.203.16]

Return-Path: [EMAIL PROTECTED]
X-Mailer: Microsoft Outlook Express %OE_VERSION%OE_SUBVERSION
Message-ID: [EMAIL PROTECTED]
Subject: SPAM LOW Unbelievable Quality
The message has been quarantined as: spam-qs7R7eSFclUM.gz

The message WAS NOT relayed to:
[EMAIL PROTECTED]:
  254 2.7.0 Ok, discarded, id=19701-05 - SPAM

SpamAssassin report:
Spam detection software, running on the system mail.domain.com, has
identified this incoming email as possible spam.  The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email.  If you have any questions, see
postmaster for details.

Content preview:  EXQUISITE REPLICA WATCHESROLEX, CARTIER, BREITLING AND
 MORE...VISIT OUR ONLINE SHOP! EXQUISITE REPLICA WATCHES ROLEX, CARTIER,
 BREITLING AND MORE... [...]

Content analysis details:   (33.5 points, 5.0 required)

pts rule name  description
 -- 
--

1.3 UNRESOLVED_TEMPLATEHeaders contain an unresolved template
0.8 DATE_IN_PAST_06_12 Date: is 6 to 12 hours before Received: date
2.9 REPLICA_WATCH  BODY: Message talks about a replica watch
0.0 HTML_MESSAGE   BODY: HTML included in message
3.5 BAYES_99   BODY: Bayesian spam probability is 99 to 100%
   [score: 1.]
1.9 DNS_FROM_RFC_BOGUSMX   RBL: Envelope sender in
   bogusmx.rfc-ignorant.org
1.6 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
  [Blocked - see 
http://www.spamcop.net/bl.shtml?200.88.203.16]

1.6 URIBL_SBL  Contains an URL listed in the SBL blocklist
   [URIs: ouonfnewdiett.com]
3.0 URIBL_BLACKContains an URL listed in the URIBL blacklist
   [URIs: ouonfnewdiett.com]
4.5 URIBL_SC_SURBL Contains an URL listed in the SC SURBL 
blocklist

   [URIs: ouonfnewdiett.com]
3.8 URIBL_AB_SURBL Contains an URL listed in the AB SURBL 
blocklist

   [URIs: ouonfnewdiett.com]
4.1 URIBL_JP_SURBL Contains an URL listed in the JP SURBL 
blocklist

   [URIs: ouonfnewdiett.com]
3.0 URIBL_OB_SURBL Contains an URL listed in the OB SURBL 
blocklist

   [URIs: ouonfnewdiett.com]
1.4 UPPERCASE_75_100   message body is 75-100% uppercase






--
Regards,
Toni ST // Mandorkawat Dotnet
--
Migrasi mailserver ke opensource ?
Mudah, Aman  Hemat biaya.
Hubungi : [EMAIL PROTECTED]
http://www.pedezz.net
--