Alan,
When filtering out what you describe below I use the SPAMDOMAINS test.
Dan
[EMAIL PROTECTED]
- Original Message -
From: Alan Walters [EMAIL PROTECTED]
To: Declude. JunkMail [EMAIL PROTECTED]
Sent: Monday, November 03, 2003 8:36 PM
Subject: [Declude.JunkMail] Compare Sender to
Yes.. That is what we received on several occasions.
We had DECLUDE in header as whitelist for this group but soon realized we
were getting spam with that very header.
I guess what that means is the people sending us the spam are also using
Declude or are just adding it manually ..
Regards,
I thought it was not possible to forge the Declude-Sender address?
It is 100% forgeable. It is whatever the sender wants it to be. There is
no way to guarantee that any information about an E-mail is not forged,
except for the IP address.
I believe the sender is one of the most commonly forged parts of the e-mail
conversation.
Dan
[EMAIL PROTECTED]
- Original Message -
From: Greg Foulks [EMAIL PROTECTED]
To: Declude JunkMail (E-mail) [EMAIL PROTECTED]
Sent: Tuesday, November 04, 2003 9:53 AM
Subject: [Declude.JunkMail]
I'm not having any problems filtering the enclosed item, just passing it along as a
curiosity
because the header is so bizarre.
Keith Purtell, Web/Network Administrator
VantageMed Operations (Kansas City)
Email: [EMAIL PROTECTED]
CONFIDENTIALITY NOTICE: This email message, including any
Is it possible to test the Autowhitelist On feature? Or is there a command
line option that can verify that the option is turned on?
Thanks,
Greg
attachment: winmail.dat
Is it possible to create/setup a per-user blacklist that each user can
maintain?
Thanks,
Greg
attachment: winmail.dat
Is it possible to test the Autowhitelist On feature? Or is there a command
line option that can verify that the option is turned on?
If you have a line AUTOWHITELIST ON in the global.cfg file, with no other
lines beginning with AUTOWHITELIST, then it should be on.
To test it, you could send
I have seen that before. I have x-transfer-number: and X-transfer-stamp: in
by header greyfilter.
John Tolmachoff
Engineer/Consultant/Owner
eServices For You
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-mail came from the Declude.JunkMail
Received: from microsoft.com [12.203.15.235] by
mail.eservicesforyou.net
(SMTPD32-8.03) id AED48AE01CA; Tue, 04 Nov 2003 08:07:48 -0800
Date: Tue, 04 Nov 2003 16:28:30 +
From: PayPal [EMAIL PROTECTED]
Subject: PayPaI officiaI notice
To: Andre [EMAIL PROTECTED]
References:
Well Scott it doesn't appear to be working.
Here are the logs and showing points assigned from Spamchk but declude
should have whitelisted because the from addy is in my webmail address book.
11/04/2003 11:39:00, file C:\IMail\spool\Dd620200.SMD, Result 0H 0L 15K,
total 15
From:[EMAIL
Found the problem (just needed to upgrade to the latest version)
Question...
I noticed that the common addresses in the users webmail address book are
not used in the Autowhitelist search. Only the users addresses are used. Why
is this?
Is it possible to also use the common addresses?
Thanks,
I was just wondering if anyone here has ever thought of, or worked on, a
Declude log analyzer that can, similar to Scott's AWESOME bouncefinder, list
the deleted mail? Maybe list it as email address + weight? This way, if
someone calls about missing mail, if you run daily log analyzing, you can
I noticed that the common addresses in the users webmail address book are
not used in the Autowhitelist search. Only the users addresses are used. Why
is this?
Is it possible to also use the common addresses?
That's because IMail doesn't have common addresses, AFAIK.
Are you using a third-party
That's right! I'm using Killerwebmail to setup a common address book for the
group.
By editing the config_CommonAddrBook.cgi file you can create a common
address book for all users.
Sorry about the mix up.. But it would be cool if declude could also read
this file.
Thanks,
Greg
-Original
OK, I just confirmed that a test I had set to ATTACH (I have Pro) is
doing nothing.
I have a spamattach.eml in the /declude/ folder, and it is identical to
the Declude.com download.
I have this in my $default$.junkmail:
WEIGHT1319 ATTACH
That test is a weight range test that formerly was
OK, I just confirmed that a test I had set to ATTACH (I have Pro) is
doing nothing.
I have a spamattach.eml in the /declude/ folder, and it is identical to
the Declude.com download.
Does the first line begin with Message-ID:? If not, IE destroyed the
file -- in that case, you can right-click
Very easy to do with the UNIX utilities for Win32 located at
http://unxutils.sourceforge.net. If you download them and need help
creating a script to do what you want, let me know and I can help.
Bill
- Original Message -
From: paul [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Sent: Tuesday,
Scott wrote:
Does the first line begin with Message-ID:? If not, IE destroyed the
file -- in that case, you can right-click the link and choose Save
Target
As to get the proper file.
Cowabunga.
Did as suggested and got quite a different file.
Thanks!
---
[This E-mail was scanned for
Paul,
The feature you request is available in DLAnalyzer
(http://www.dlanalyzer.com). That report you would be looking to pull would
be the advanced report.
Darrell
Check Out DLAnalyzer a comprehensive reporting tool for
Declude Junkmail
Hello List,
I tried to setup user/domain setting with multiple actions for Junkmail,
and it does not seem to be working.
I've setup two actions per test attach, and mailbox. The parameter for the
mailbox option is bsumariwalla-spam, where bsumariwalla indicates a
Imail user account. What I'd
Hello List,
Oopps forgot the log files
I tried to setup user/domain setting with multiple actions for Junkmail,
and it does not seem to be working.
I've setup two actions per test attach, and mailbox. The parameter for the
mailbox option is bsumariwalla-spam, where bsumariwalla indicates
There is an awful lot of spam from that domain and I filter it! Careful
though, I have found a few legitimate clients of ours that I had to white
list in order to receive their mail...
But, the spam has stopped! (At least from them)
Jon Lapp
Computer Systems Specialist
Northstar Computer Forms,
Per Scott's earlier suggestion I fixed the spamattach.eml. I've gotten three of these
in the last several minutes: a completely intact spam with no sign of Declude acting
on it except for the headers (below). No proper 'you've got spam' attachment msgs
rcvd yet
The WEIGHT1319 test is a
Per Scott's earlier suggestion I fixed the spamattach.eml. I've gotten
three of these in the last several minutes: a completely intact spam with
no sign of Declude acting on it except for the headers (below). No proper
'you've got spam' attachment msgs rcvd yet
What version of Declude are
What version of Declude?
1.76b. Downloaded it yesterday.
What does the log show?
See below for the latest arrival in my inbox. Included are the headers, plus Declude
and Imail logs; the latter of which looks pretty normal.
If I switch back to bounce they bounce as expected.
Complete headers
What does the log show?
See below for the latest arrival in my inbox. Included are the headers,
plus Declude and Imail logs; the latter of which looks pretty normal.
If I switch back to bounce they bounce as expected.
If you type \IMail\Declude -diag from a command prompt (without changing
Matt,
I don't know the answer, but here's another question. on these lines in
your JM log:
11/04/2003 13:54:02 Q1fc2024f002acd29 Msg failed WEIGHT1319 (Total weight
between 13 and 19.). Action=ATTACH.
11/04/2003 13:54:02 Q1fc2024f002acd29 L1 Message OK
How can it be OK and failing at the
Yup. Pro Registered jm and std reg virus.
Here's the text from the spamattach email.
Message-ID: [EMAIL PROTECTED]
From: Declude JunkMail [EMAIL PROTECTED]
To: %ALLRECIPS%
Subject: You have spam
Date: %RFCDATETIME%
MIME-Version: 1.0
Content-Type: multipart/mixed;
Paul wrote:
How can it be OK and failing at the same time?? Am I misreading
something here?
No, you aren't missing anything. This isn't supposed to happen. ere's a msg from
11/2, a couple of days ago. This one was a bounce as expected.
The only real difference is that in
I wrote:
I'm setting it back to bounce again to see what happens.
I did and its back to normal log entries and behavior using 1.79b
--
---
Matt Robertson, [EMAIL PROTECTED]
MSB Designs, Inc. http://mysecretbase.com
Matt, something that might help track this down. Turn on the spool file name
on the header like this in the Global.cfg;
XSPOOLNAME ON
Not saying that it is, but you could be looking at 2 different messages. By
have Declude put the spool name in the header, you will know for sure.
Also, put
Is the Country/Countries Filter test supposed to work with the release
version, 1.75?
This filter isn't working for me so I wanna make sure I have the proper
version since I don't see any documentaion in the manual. Are there any
docs? even for a beta version?
I see a line such as:
Better yet, create a IP4R query for the most offending countries:
i.e. China, Brazil, Argentina.
I find this incredibly useful:
http://blackholes.us
Best Regards,
Phillip B. Holmes
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of
Matthew
Joe,
You probably need to download the all_list.dat file that acts as the
database for this filter. See the following post for the location and
more info:
http://www.mail-archive.com/[EMAIL PROTECTED]/msg11348.html
Note that COUNTRIES checks all hops, and COUNTRY checks only the last
35 matches
Mail list logo