Re: Mail account brute force / harassment

2019-04-14 Thread mj via dovecot
Hi, On 4/12/19 11:05 PM, Joseph Tam via dovecot wrote: "www.blocklist.de" is a nifty source.  Could you suggest other publically available blacklists? The ones we are using are: "file:///etc/ipset-blacklist/ip-blacklist-custom.list" # optional, for your personal nemeses (no typo,

Re: Mail account brute force / harassment

2019-04-12 Thread mj via dovecot
Hi, What we do is: use https://github.com/trick77/ipset-blacklist to block IPs (from various existing blacklists) at the iptables level using an ipset. That way, the known bad IPs never even talk to dovecot, but are dropped immediately. We have the feeling it helps a lot. MJ On 4/12/19

AD ldap, filter to exclude various kinds of expired, disabled etc etc users

2019-03-08 Thread mj via dovecot
Hi, I was revising our AD ldap user_filter and pass_filter to exclude more types of expired / disabled accounts. I started adding things like: