Report ID Version 1.02b Detailed Report for: 09/23/2002 17:29:55
Log file examined: x:\DEC0923.LOG
Kill file examined: x:\FROMFILE.TXT
Kill file copied to: x:\APPS\DELOG\FROMFILE.TXT
Merge file examined: x:\KILL.TXT
Merge file
We can look into doing a match at the end (ENDSWITH, as the
filter would use).
Ok, so I made up a filter file.
Here is an example if any is curious:
-
MAILFROM1 ENDSWITH.ar
MAILFROM1 ENDSWITH.at
MAILFROM
Hi my name is kevin; I just bought declude a few months back but really
haven't had a chance to fine tune it.
Tom - I'm curious about this country code file. I filter allot of these in
the local mail application and it would be nice if junk mail would just
delete these when they come through,
Good morning :)
One of my users is receiving some really disgusting porn email.
The logs show that the sender is actually using HER address as the
return address. Here is a snip from the IMAIL log:
09:23 23:13 SMTPD(29B2013E) [200.231.59.131] HELO aleph.inbrac.com.br
09:23 23:13
Why is this IP failing Spamcop?
http://spamcop.net/bl.shtml?162.42.150.35
The link says it falls below the threshold and shouldn't be listed.
Note that the spam-to-legitimate-mail ratio is 1.1%, and the cutoff is
2.0%. Also, the most recent spam was 2.7 days ago (newer spam is weighted
I'm not sure if you realized that this list contains great part of
european countries. (Germany, Italy, Austria, France, Finnland,
Netherlands...)
Do you realy want to stamp all messages from this countries as spam?
Or said in other words: Are you sure that in a report of recieved spams
this
One way is to use myfilter.txt. Include some of the obvious wordings in
it such as :
SUBJECTCONTAINS 10 disgusting words
BODYCONTAINS 10 disgusting verbage
MAILFROM 10 sorry individual
Jim Rooth
Klotron, Inc.
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On
Tom,
Your kill file is worth its weight in gold!
Thanks!
Sharyn
We are the worldwide producer and marketer of the award winning Cruzan
Single Barrel Rum, judged Best in the World at the annual
San Francisco Wine and Spirits Championships. For
more information, please click (go to) htmla
Right, but isn't that the power of the filter tests? I use a complete list
of ccTLD codes that I downloaded from IANA and I jiggled the individual
weights based on the kind of mail I process here, but I wouldn't imagine
that my weight choices would be appropriate for anyone else anywhere else.
One of our client's got locked out by HiJack (hold2), but it appears to be
because of inbound mail, not outgoing mail.
Declude Hijack only checks outgoing E-mail, not incoming E-mail. Any
incoming E-mail is automatically exempt.
This client has an email account at another provider which
Scott: What about the country-test (IP2Country-lookup)? - I believe you
has talked about this some months ago.
This is something we are still working on -- we have finished the code to
look up the country from the IP, we just need to get it hooked into Declude
JunkMail.
The mail in question wasn't being forwarded from our mail server. It was
being forwarded FROM another mail server TO an account on our mail server.
That shouldn't still be considered outgoing should it?
That definitely should not.
What do the Declude Hijack log files say? Do they show it
Do you have the PRO Version of Junkmail? You can use filters to deal
with IP's, MAILFROM, etc if you do.
Yep, thanks, working on it now!
Sharyn
We are the worldwide producer and marketer of the award winning Cruzan
Single Barrel Rum, judged Best in the World at the annual
San Francisco
The HiJack log shows it as outgoing. Below is the log entry of the first
one that was held. I'll send the Q* and D* files for this email directly
to you...
09/20/2002 12:18:34 Q4a5a438800aa39c6 Outgoing from 128.242.197.219: Sent
over 80 E-mails within 30 minutes; quarantining to hold2.
Thanks for the input !
-- Original Message --
From: Sanford Whiteman [EMAIL PROTECTED]
Reply-To: [EMAIL PROTECTED]
Date: Mon, 23 Sep 2002 18:36:07 -0400
Seems Yahoo (at least groups) fails the abuse test when they do have
an abuse account.
question on this filtering..
If I add the following line in myfilter.txt..
Body 0 Contains anal
This will cause any email with the word analysis in it to receive
whatever action I've given the test. Correct?
Sharyn
We are the worldwide producer and marketer of the award winning Cruzan
Analytically correct
George
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]] On Behalf Of Sharyn Schmidt
Sent: Tuesday, September 24, 2002 10:05 AM
To: [EMAIL PROTECTED]
Subject: RE: [Declude.JunkMail] spam rec'd using internal return address
question on this
Analytically correct
George
grin
Thanks again everyone! You all are great!
Sharyn
We are the worldwide producer and marketer of the award winning Cruzan
Single Barrel Rum, judged Best in the World at the annual
San Francisco Wine and Spirits Championships. For
more information, please
It was originally sent to [EMAIL PROTECTED] which is not a domain on our
Imail server. This domain is on a Verio server. But this guy has Mail
Forwarded set up for this account to forward to [EMAIL PROTECTED], which
is a domain on our Imail server. So it was forwarded from the Verio
When an email matches the bounce action does it hold the message in the spam
directory or does it just bounce it and delete it?
It acts like a standard bounce, just sending the bounce and deleting the
original E-mail.
-Scott
---
[This E-mail was scanned for
here it is...
09/20/2002 12:18:34 Q4a5a438800aa39c6 [EMAIL PROTECTED] is not local [0] 0.
09/20/2002 12:18:34 Q4a5a438800aa39c6 Outgoing from 128.242.197.219: Sent over 80
E-mails within 30 minutes; quarantining to hold2.
09/20/2002 12:18:34 Q4a5a438800aa39c6 Outgoing from 128.242.197.219:
09/20/2002 12:18:34 Q4a5a438800aa39c6 [EMAIL PROTECTED] is not local [0] 0.
Where does whittier.net appear in the IMail settings? Does it appear as
an official domain name, or a domain alias? Or does it appear somewhere else?
That message should only occur if IMail does not recognize
Whats even weirder is he's got his other account still forwarding to an account on our
server, but Declude HiJack is now logging these forwarded messages as Incoming...
09/24/2002 09:31:27 Q692f009d009eea55 Incoming from 128.242.197.219: OK.
...the only difference is on the 20th we were
It is the official hostname for a virtual domain. It is not a domain alias.
-Original Message-
From: R. Scott Perry
Sent: Tue, 24 Sep 2002 12:53:26 -0400
Subject: Re: [Declude.JunkMail] hijack question
09/20/2002 12:18:34 Q4a5a438800aa39c6 [EMAIL PROTECTED] is not local [0] 0.
Whats even weirder is he's got his other account still forwarding to an
account on our server, but Declude HiJack is now logging these forwarded
messages as Incoming...
09/24/2002 09:31:27 Q692f009d009eea55 Incoming from 128.242.197.219: OK.
...the only difference is on the 20th we were
I am out of the office this week and working from home through TS, so I
can not see the windows at all.
I have to leave in about 20 minutes, so I will check it again in a
couple of hours when I get back.
John Tolmachoff
IT Manager, Network Engineer
RelianceSoft, Inc.
Fullerton, CA 92835
I am seeing quite of few of these in the dec.log.
09/24/2002 00:22:48 Q127d011e02a48303 WARNING: DNS server 64.171.65.11
returned a SERVER FAILURE error for MX/A for dotcompselectronics.com.
09/24/2002 00:22:49 Q127d011e02a48303 R1 Message OK
09/24/2002 00:22:49 Q127d011e02a48303 R2 Message
I've been following this particular issue for months (just started on this mailing
list).
I've tried 3 different DNS servers (including one running on the same machine as
Declude) with no effect. Most of the failures appear to be legitimate badly
configured servers that the DNS server is
Is there a way that Declude JM can process mail forwarded from another
provider? I get a lot of junk mail from my other Addresses, and I would
like to set them up to forward to my primary domain, install JM, and have
it weed out the bad mail. Is this possible? I know this would change the
Is there a way that Declude JM can process mail forwarded from another
provider? I get a lot of junk mail from my other Addresses, and I would
like to set them up to forward to my primary domain, install JM, and have
it weed out the bad mail. Is this possible? I know this would change the
Your kill file is worth its weight in gold!
Thanks, glad it helps.
Regards,
Tom
Image`fx
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-mail came from the Declude.JunkMail mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED],
I'm not sure if you realized that this list contains great part of
european countries. (Germany, Italy, Austria, France, Finnland,
Netherlands...)
Do you realy want to stamp all messages from this countries as spam?
Or said in other words: Are you sure that in a report of recieved spams
Tom - I'm curious about this country code file. I filter allot
of these in the local mail application and it would be nice if
junk mail would just delete these when they come through,
It would be, but we can't do that, unless we can confirm it's
junk mail.
My question is this. Do I
use IPBYPASS ip address of third party mta in the global.cfg file
Have a great day!
Rick Davidson
Buckeye Internet Services
www.buckeyeweb.com
440-953-1900
-
- Original Message -
From: Todd [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Tuesday, September 24, 2002 4:21 PM
Subject:
That would only work providing that the mail was being forwarded by the
original mail server to the Declude server via SMTP. This would not work in
the case of a mail client downloading the mail and forwarding it to another
address. This would only work if you have the ability to have the
Is anyone else having difficulties with the Declude Web Site?
Jeff
*
TymeWyse Internet
P.O.Box 84 - 583 N. Main St., Canyonville, OR 97417
tel/fax: (541) 839-6027 - [EMAIL PROTECTED]
*
sorry was only for ron
- Original Message -
From: Matthew Lohr [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Tuesday, September 24, 2002 5:38 PM
Subject: Re: [Declude.JunkMail] Declude Console ?
if you need a temporary host for your site let me know. I would glad to
be
a backup for
I was there about two hours ago, but now it won't come up.
Keith Purtell, Web/Network Administrator
VantageMed Operations (Kansas City)
Email: [EMAIL PROTECTED]
CONFIDENTIALITY NOTICE: This email message, including any attachments, is for the sole
use of the
intended recipient(s) and may
Is anyone else having difficulties with the Declude Web Site?
There is a temporary problem at our web hosting company, but it should be
back up shortly.
-Scott
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-mail came
Yup - no joy for quite a bit now.
_M
]-Original Message-
]From: [EMAIL PROTECTED]
][mailto:[EMAIL PROTECTED]]On Behalf Of Jeff Kratka
]Sent: Tuesday, September 24, 2002 5:49 PM
]To: [EMAIL PROTECTED]
]Subject: [Declude.JunkMail] Web Site ?
]
]
]Is anyone else having difficulties with the
I do not belive that the ability to have the first mail server forward my
mail. I was hoping for a way to have Eudora download mail, process it with
filters, then forward any unknown mail to my mailserver running JM to
process the unknown ones, but this of course only have the headers of the
The next release of Declude JunkMail will have an *experimental* feature
(which may or may not become an official feature) that will allow for
filtering based on the countries that an E-mail passed through.
The filtering will require a file of about 200K that should occasionally be
updated as
I have a question. Are you talking about Imail's kill file or a different
kill file? I ask this because I thought that Imail only allowed the format
in the killfile to be userid@host or @host and would not work with .host .
Let me know because it would be helpful to me if I could use the .host
I've tried 3 different DNS servers (including one running on the same
machine as Declude) with no effect. Most of the failures appear to be
legitimate badly configured servers that the DNS server is reporting
incorrectly as a server failure to Declude.
Are you referring to remote DNS servers,
Ok, SpamReview mailFrom is working great for me with the proper
string detect...!!!
Now for another request. two more buttons:
Delete All - Deletes all entries.
Delete All and Exit - Deletes all entries then exits (deleting
deleted if switch is 'on')
This is really want is needed.
45 matches
Mail list logo