Joe,
You probably need to download the all_list.dat file that acts as the
database for this filter. See the following post for the location and
more info:
http://www.mail-archive.com/[EMAIL PROTECTED]/msg11348.html
Note that COUNTRIES checks all hops, and COUNTRY checks only the last
hop.
Better yet, create a IP4R query for the most offending countries:
i.e. China, Brazil, Argentina.
I find this incredibly useful:
http://blackholes.us
Best Regards,
Phillip B. Holmes
> -Original Message-
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED] On Behalf Of
> Matthew Br
Is the Country/Countries Filter test supposed to work with the release
version, 1.75?
This filter isn't working for me so I wanna make sure I have the proper
version since I don't see any documentaion in the manual. Are there any
docs? even for a beta version?
I see a line such as:
X-Country-
Matt, something that might help track this down. Turn on the spool file name
on the header like this in the Global.cfg;
XSPOOLNAME ON
Not saying that it is, but you could be looking at 2 different messages. By
have Declude put the spool name in the header, you will know for sure.
Also, put
I wrote:
>I'm setting it back to bounce again to see what happens.
I did and its back to normal log entries and behavior using 1.79b
--
---
Matt Robertson, [EMAIL PROTECTED]
MSB Designs, Inc. http://mysecretbase.com
Paul wrote:
>How can it be OK and failing at the same time?? Am I misreading
>something here?
No, you aren't missing anything. This isn't supposed to happen. ere's a msg from
11/2, a couple of days ago. This one was a bounce as expected.
The only real difference is that in $default$.junkm
Yup. Pro Registered jm and std reg virus.
Here's the text from the spamattach email.
Message-ID: <[EMAIL PROTECTED]>
From: "Declude JunkMail" <[EMAIL PROTECTED]>
To: <%ALLRECIPS%>
Subject: You have spam
Date: %RFCDATETIME%
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="%RAND
Matt,
I don't know the answer, but here's another question. on these lines in
your JM log:
> 11/04/2003 13:54:02 Q1fc2024f002acd29 Msg failed WEIGHT1319 (Total weight
between 13 and 19.). Action=ATTACH.
> 11/04/2003 13:54:02 Q1fc2024f002acd29 L1 Message OK
How can it be OK and failing at the
>What does the log show?
See below for the latest arrival in my inbox. Included are the headers,
plus Declude and Imail logs; the latter of which looks pretty normal.
If I switch back to "bounce" they bounce as expected.
If you type "\IMail\Declude -diag" from a command prompt (without changing
>What version of Declude?
1.76b. Downloaded it yesterday.
>What does the log show?
See below for the latest arrival in my inbox. Included are the headers, plus Declude
and Imail logs; the latter of which looks pretty normal.
If I switch back to "bounce" they bounce as expected.
Complete head
Per Scott's earlier suggestion I fixed the spamattach.eml. I've gotten
three of these in the last several minutes: a completely intact spam with
no sign of Declude acting on it except for the headers (below). No proper
'you've got spam' attachment msgs rcvd yet
What version of Declude are you
Per Scott's earlier suggestion I fixed the spamattach.eml. I've gotten three of these
in the last several minutes: a completely intact spam with no sign of Declude acting
on it except for the headers (below). No proper 'you've got spam' attachment msgs
rcvd yet
The WEIGHT1319 test is a weight
I set the Global.cfg log level high, and I can see that the
bsumariwalla.junkmail file is being used, and some mail is being processed
per the rules setup in bsumariwalla.junkmail, but the mail doesn't arrive
to web messaging or my POP3 client.
The per-user configuration file is indeed being us
There is an awful lot of spam from that domain and I filter it! Careful
though, I have found a few legitimate clients of ours that I had to white
list in order to receive their mail...
But, the spam has stopped! (At least from them)
Jon Lapp
Computer Systems Specialist
Northstar Computer Forms, I
Hello List,
Oopps forgot the log files
I tried to setup user/domain setting with multiple actions for Junkmail,
and it does not seem to be working.
I've setup two actions per test attach, and mailbox. The parameter for the
mailbox option is bsumariwalla-spam, where bsumariwalla indicates
Hello List,
I tried to setup user/domain setting with multiple actions for Junkmail,
and it does not seem to be working.
I've setup two actions per test attach, and mailbox. The parameter for the
mailbox option is bsumariwalla-spam, where bsumariwalla indicates a
Imail user account. What I'd
Can I safely block email that comes from client.attbi.com? I see an aweful
lot of spam from this network and I think this is just dialup or DSL?
Sheldon
Sheldon Koehler, Owner/Partnerhttp://www.tenforward.com
Ten Forward Communications 360-457-9023
Nationwide access, neighborh
Paul,
The feature you request is available in DLAnalyzer
(http://www.dlanalyzer.com). That report you would be looking to pull would
be the advanced report.
Darrell
Check Out DLAnalyzer a comprehensive reporting tool for
Declude Junkmail Log
Scott wrote:
>Does the first line begin with "Message-ID:"? If not, IE destroyed the
>file -- in that case, you can right-click the link and choose "Save
Target
>As" to get the proper file.
Cowabunga.
Did as suggested and got quite a different file.
Thanks!
---
[This E-mail was scanned f
Very easy to do with the UNIX utilities for Win32 located at
http://unxutils.sourceforge.net. If you download them and need help
creating a script to do what you want, let me know and I can help.
Bill
- Original Message -
From: "paul" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Tue
HI,
Is there a way to delete all incoming emails that begin with (for example)
[EMAIL PROTECTED]
I get hundreds of these [EMAIL PROTECTED] .com emails and they are all spam.
Also, same for bounce*.*
Thanks, ANdy
- Original Message -
From: "paul" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED
OK, I just confirmed that a test I had set to ATTACH (I have Pro) is
doing nothing.
I have a spamattach.eml in the /declude/ folder, and it is identical to
the Declude.com download.
Does the first line begin with "Message-ID:"? If not, IE destroyed the
file -- in that case, you can right-click t
OK, I just confirmed that a test I had set to ATTACH (I have Pro) is
doing nothing.
I have a spamattach.eml in the /declude/ folder, and it is identical to
the Declude.com download.
I have this in my $default$.junkmail:
WEIGHT1319 ATTACH
That test is a weight range test that formerly was "WEIGH
That's right! I'm using Killerwebmail to setup a common address book for the
group.
By editing the config_CommonAddrBook.cgi file you can create a common
address book for all users.
Sorry about the mix up.. But it would be cool if declude could also read
this file.
Thanks,
Greg
-Original Me
I noticed that the common addresses in the users webmail address book are
not used in the Autowhitelist search. Only the users addresses are used. Why
is this?
Is it possible to also use the common addresses?
That's because IMail doesn't have common addresses, AFAIK.
Are you using a third-party a
I was just wondering if anyone here has ever thought of, or worked on, a
Declude log analyzer that can, similar to Scott's AWESOME bouncefinder, list
the deleted mail? Maybe list it as email address + weight? This way, if
someone calls about missing mail, if you run daily log analyzing, you can
sea
Found the problem (just needed to upgrade to the latest version)
Question...
I noticed that the common addresses in the users webmail address book are
not used in the Autowhitelist search. Only the users addresses are used. Why
is this?
Is it possible to also use the common addresses?
Thanks,
G
Well Scott it doesn't appear to be working.
Here are the logs and showing points assigned from "Spamchk" but declude
should have whitelisted because the from addy is in my webmail address book.
11/04/2003 11:39:00, file C:\IMail\spool\Dd620200.SMD, Result 0H 0L 15K,
total 15
From:<[EMAIL PRO
Received: from microsoft.com [12.203.15.235] by
mail.eservicesforyou.net
(SMTPD32-8.03) id AED48AE01CA; Tue, 04 Nov 2003 08:07:48 -0800
Date: Tue, 04 Nov 2003 16:28:30 +
From: PayPal <[EMAIL PROTECTED]>
Subject: PayPaI officiaI notice
To: Andre <[EMAIL PROTECTED]>
References: <[
I have seen that before. I have x-transfer-number: and X-transfer-stamp: in
by header greyfilter.
John Tolmachoff
Engineer/Consultant/Owner
eServices For You
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-mail came from the Declude.JunkMail mailin
Is it possible to test the Autowhitelist On feature? Or is there a command
line option that can verify that the option is turned on?
If you have a line "AUTOWHITELIST ON" in the global.cfg file, with no other
lines beginning with "AUTOWHITELIST", then it should be on.
To test it, you could send
Is it possible to create/setup a per-user blacklist that each user can
maintain?
Thanks,
Greg
<>
Is it possible to test the Autowhitelist On feature? Or is there a command
line option that can verify that the option is turned on?
Thanks,
Greg
<>
I'm not having any problems filtering the enclosed item, just passing it along as a
curiosity
because the header is so bizarre.
Keith Purtell, Web/Network Administrator
VantageMed Operations (Kansas City)
Email: [EMAIL PROTECTED]
CONFIDENTIALITY NOTICE: This email message, including any attachm
I believe the sender is one of the most commonly forged parts of the e-mail
conversation.
Dan
[EMAIL PROTECTED]
- Original Message -
From: "Greg Foulks" <[EMAIL PROTECTED]>
To: "Declude JunkMail (E-mail)" <[EMAIL PROTECTED]>
Sent: Tuesday, November 04, 2003 9:53 AM
Subject: [Declude.Junk
I thought it was not possible to forge the Declude-Sender address?
It is 100% forgeable. It is whatever the sender wants it to be. There is
no way to guarantee that any information about an E-mail is not forged,
except for the IP address.
-S
Yes.. That is what we received on several occasions.
We had DECLUDE in header as whitelist for this group but soon realized we
were getting spam with that very header.
I guess what that means is the people sending us the spam are also using
Declude or are just adding it manually ..
Regards,
Kam
I thought it was not possible to forge the Declude-Sender address?
Check out these headers...
Message-ID: <[EMAIL PROTECTED]>
From: "Declude JunkMail" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Subject: You have spam
Date: Tue, 4 Nov 2003 08:53:16 -
MIME-Version: 1.0
Content-Type: multipart
Alan,
When filtering out what you describe below I use the SPAMDOMAINS test.
Dan
[EMAIL PROTECTED]
- Original Message -
From: "Alan Walters" <[EMAIL PROTECTED]>
To: "Declude. JunkMail" <[EMAIL PROTECTED]>
Sent: Monday, November 03, 2003 8:36 PM
Subject: [Declude.JunkMail] Compare Sender
39 matches
Mail list logo