Re: Avoid processing of email with specific headers

2009-07-25 Thread mouss
Pietro a écrit : In my installation, SA is called by Postfix. Any idea? Thanks in advance. This is really a postfix question. Follow up on the postfix-users list if needed. you can skip filtering using header_checks. for example /^X-Spam-Status: Yes/ FILTER smtp:[127.0.0.1]:10025 assuming

SA Not Checking emails

2009-07-25 Thread twofers
So I (think) I know that if SA is sent a message of a specific large size, SA will not process it (Recent thread here) and I also (think) I know that if the server is overyly busy, etc. that SA will not check the email. Now I may be totally wrong about this, but my assumptions are based on

Re: Avoid processing of email with specific headers

2009-07-25 Thread Jari Fredriksson
Pietro a écrit : In my installation, SA is called by Postfix. Any idea? Thanks in advance. This is really a postfix question. Follow up on the postfix-users list if needed. you can skip filtering using header_checks. for example /^X-Spam-Status: Yes/ FILTER smtp:[127.0.0.1]:10025

Re: SA Not Checking emails

2009-07-25 Thread Benny Pedersen
On Sat, July 25, 2009 16:19, twofers wrote: Here is a full header to one of the emails. Maybe someone can tell me what may be going on. http://old.openspf.org/wizard.html?mydomain=allradiohead.comsubmit=Go! do you see any softfails at all ?, or even fail ?, is spf_helo_pass seen in

Re: SA Not Checking emails

2009-07-25 Thread Benny Pedersen
On Sat, July 25, 2009 16:59, Benny Pedersen wrote: On Sat, July 25, 2009 16:19, twofers wrote: Here is a full header to one of the emails. Maybe someone can tell me what may be going on. http://old.openspf.org/wizard.html?mydomain=allradiohead.comsubmit=Go! ups i forgot to say non fqdn mx

Re: anchor forgery

2009-07-25 Thread mouss
Mike Cardwell a écrit : Just checking through my Spam folder and I came across a message that contained this in the html: a target=_blank href=http://www.kanotiser.se/images/logo.html;https://www.paypal.co/us/webscr.php?cmd=_login-runcmd=_secure /a Yet, there was no mention of this

Re: whitelist_from questions

2009-07-25 Thread Matus UHLAR - fantomas
On 25.07.09 01:25, jida...@jidanni.org wrote: Actually there should be one or two more whitelists, so one can e.g., score -100 one's friends -10 one's schools -1 one's country we still have def_whitelist_* with score of -15. -- Matus UHLAR - fantomas, uh...@fantomas.sk ;

Re: anchor forgery

2009-07-25 Thread Matt Kettler
mouss wrote: Mike Cardwell a écrit : Just checking through my Spam folder and I came across a message that contained this in the html: censored example, Verizon won't let me send it Yet, there was no mention of this obvious forgery in the spamassassin rules which caught the

Re: anchor forgery

2009-07-25 Thread Karsten Bräckelmann
On Sat, 2009-07-25 at 15:59 +0100, Mike Cardwell wrote: Just checking through my Spam folder and I came across a message that contained this in the html: Hey, it was classified spam. ;) And it's a phish anyway... a target=_blank href=http://www.example.net;https://www.example.com/a How

pilz spammers with new variations

2009-07-25 Thread McDonald, Dan
Looks like the pilz spammers have finally ditched the letters+numbers format. I'm now using this rule: body__MED_OB

Re: Avoid processing of email with specific headers

2009-07-25 Thread mouss
Jari Fredriksson a écrit : snip did you see this: This is really a postfix question. Follow up on the postfix-users list if needed. did you see that? [snip] Got the following error, when tried that. I'm using stock postfix on Debian Lenny w/ backports. postfix/cleanup[1602]:

Re: Avoid processing of email with specific headers

2009-07-25 Thread Benny Pedersen
On Sun, July 26, 2009 00:06, mouss wrote: Please move this to the postfix-users list. This is my last response here. truly a lie :) -- xpoint

RE: whitelist_from questions

2009-07-25 Thread Robert
There are no doubt lots of ways, but how about: egrep 'whitelist_from[^_]' local.cf | awk '{FS=@; print $2 TXT;}' | xargs dig | grep v=spf1 John. john, what is this supposed to do? - rh

RE: whitelist_from questions

2009-07-25 Thread McDonald, Dan
From: Robert [mailto:list...@abbacomm.net] There are no doubt lots of ways, but how about: egrep 'whitelist_from[^_]' local.cf | awk '{FS=@; print $2 TXT;}' | xargs dig | grep v=spf1 what is this supposed to do? select all of your whitelist_from entries, parse out the domain part, dig the

bayes not active although enabled?

2009-07-25 Thread snowweb
In /etc/mail/spamassassin/local.cf bayes_auto_learn 1 But when I examine the message headers, X-Spam-Status: No, score=3.0 required=4.7 tests=ALL_TRUSTED,AWL,HTML_MESSAGE, MIME_HTML_ONLY,TVD_RCVD_IP autolearn=no version=3.2.4 Is there anywhere else that I need to switch this on? --

Score -71 for VERY spammy message!

2009-07-25 Thread snowweb
This is the result, X-Spam-Level: X-Spam-Status: No, score=-71.4 required=4.7 tests=HELO_DYNAMIC_IPADDR, HTML_IMAGE_ONLY_20,HTML_IMAGE_RATIO_02,HTML_MESSAGE,HTML_SHORT_LINK_IMG_3, MIME_HTML_ONLY,MISSING_DATE,MISSING_MID,RCVD_IN_BL_SPAMCOP_NET,RCVD_IN_PBL,

Re: Score -71 for VERY spammy message!

2009-07-25 Thread Terry Carmen
This is the result, X-Spam-Level: X-Spam-Status: No, score=-71.4 required=4.7 tests=HELO_DYNAMIC_IPADDR, HTML_IMAGE_ONLY_20,HTML_IMAGE_RATIO_02,HTML_MESSAGE,HTML_SHORT_LINK_IMG_3, MIME_HTML_ONLY,MISSING_DATE,MISSING_MID,RCVD_IN_BL_SPAMCOP_NET,RCVD_IN_PBL,

Re: Score -71 for VERY spammy message!

2009-07-25 Thread LuKreme
On Jul 25, 2009, at 9:07 PM, snowweb wrote: X-Spam-Status: No, score=-71.4 required=4.7 tests=HELO_DYNAMIC_IPADDR, HTML_IMAGE_ONLY_20 ,HTML_IMAGE_RATIO_02,HTML_MESSAGE,HTML_SHORT_LINK_IMG_3, MIME_HTML_ONLY ,MISSING_DATE,MISSING_MID,RCVD_IN_BL_SPAMCOP_NET,RCVD_IN_PBL, RCVD_IN_SORBS_DUL

Re: Score -71 for VERY spammy message!

2009-07-25 Thread snowweb
Terry Carmen wrote: This is the result, X-Spam-Level: X-Spam-Status: No, score=-71.4 required=4.7 tests=HELO_DYNAMIC_IPADDR, HTML_IMAGE_ONLY_20,HTML_IMAGE_RATIO_02,HTML_MESSAGE,HTML_SHORT_LINK_IMG_3, MIME_HTML_ONLY,MISSING_DATE,MISSING_MID,RCVD_IN_BL_SPAMCOP_NET,RCVD_IN_PBL,

Re: Score -71 for VERY spammy message!

2009-07-25 Thread Rob McEwen
snowweb wrote: USER_IN_WHITELIST That probably has something to do with it. And make sure you haven't whitelisted your own user because it is common for spammers to put the recipient's address in there as the from address, knowing that some portion of administrators will have whitelisted their

Solved: Tnx. Re: Score -71 for VERY spammy message!

2009-07-25 Thread snowweb
Rob McEwen wrote: snowweb wrote: USER_IN_WHITELIST That probably has something to do with it. And make sure you haven't whitelisted your own user because it is common for spammers to put the recipient's address in there as the from address, knowing that some portion of administrators

Re: bayes not active although enabled?

2009-07-25 Thread snowweb
Sorry, got mixed up. In /etc/mail/spamassassin/local.cf use_bayes 1 Is there anywhere else that I need to switch this on since it does not appear to be doing bayesian testing at all for any messages. -- View this message in context:

Re: Score -71 for VERY spammy message!

2009-07-25 Thread Matt Kettler
snowweb wrote: Terry Carmen wrote: This is the result, X-Spam-Level: X-Spam-Status: No, score=-71.4 required=4.7 tests=HELO_DYNAMIC_IPADDR, HTML_IMAGE_ONLY_20,HTML_IMAGE_RATIO_02,HTML_MESSAGE,HTML_SHORT_LINK_IMG_3,

Re: bayes not active although enabled?

2009-07-25 Thread Matt Kettler
snowweb wrote: Sorry, got mixed up. In /etc/mail/spamassassin/local.cf use_bayes 1 Is there anywhere else that I need to switch this on since it does not appear to be doing bayesian testing at all for any messages. check your sa-learn --dump magic SA won't activate bayes until it has

Re: Avoid processing of email with specific headers

2009-07-25 Thread Jari Fredriksson
# apt-get install postfix-pcre Please move this to the postfix-users list. This is my last response here. There is no need joining postfix-users, as the solutions is there already for me. Thank You :)