Re: "deadline shrunk" in logs ?

2024-05-27 Thread Bill Cole
e all pending DNS queries were complete and before the fixed timeout deadline was reached. The most common cause is a DNS-based rule configured to shortcircuit while other queries are outstanding. -- Bill Cole

Re: Extract Local-part from To: Adress to use in spamassassin rule

2024-05-23 Thread Bill Cole
se it in another. I don't have a working rule for you, but that's the mechanism I would use. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: double backslash in the log messages

2024-05-21 Thread Bill Cole
-characters escaped. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Difference between spamc -L and sa-learn

2024-05-18 Thread Bill Cole
expensive to execute perl and have it load the many SpamAssassin modules needed to learn a message. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Error parsing sql configuration

2024-05-18 Thread Bill Cole
('%',_DOMAIN_) ORDER BY username ASC Is there a bug when parsing the preferences from sql? It's not really a parsing error, it's a configuration error. You cannot set "use_pyzor" or "use_razor" in user preferences, as they are both restricted to system-wide config.

Re: SA treats percentage spaces wording as uri

2024-05-14 Thread Bill Cole
be assuming there's a TLD after it. I agree. That's a step too far. The days when appending .com was a reasonable tactic for qualifying hostnames are long gone. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses

Re: dkim https://16years.secvuln.info/

2024-05-13 Thread Bill Cole
system administration, not bad code or distribution config. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Score 0.001

2024-05-11 Thread Bill Cole
e active site-specific rule management (and FP avoidance) than most systems ever receive. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Score 0.001

2024-05-10 Thread Bill Cole
On 2024-05-10 at 14:15:56 UTC-0400 (Fri, 10 May 2024 14:15:56 -0400) Bill Cole is rumored to have said: > On 2024-05-09 at 18:19:14 UTC-0400 (Thu, 9 May 2024 15:19:14 -0700) > jdow > is rumored to have said: > >> On 20240509 15:05:46, Thomas Barth wrote: >>> Am 2024

Re: Score 0.001

2024-05-10 Thread Bill Cole
enough performers to get included in the daily active list will still be pulled into the active list with a trivial score if derivative meta rules which are good enough for real scores depend on them. -- Bill Cole

Re: Score 0.001

2024-05-10 Thread Bill Cole
a rules that have more significant scores, but are not significantly spam or ham signs on their own. -- Bill Cole

Re: Rule: "1.0 R_DCD 90% of .com. is spam"

2024-05-10 Thread Bill Cole
ell enough to in the active list. If your system generated that hit, it is one of your own local rules. If it came from elsewhere, ask them. -- Bill Cole

Re: Whitelist rules should never pass on SPF fail

2024-05-10 Thread Bill Cole
ing to adopt SRS or any other mechanisms to avoid SPF breakage to ever change. There is no ROI in trying to fix such cases individually but users still want their college email addresses to work decades after graduating and some colleges have pandered to them. So have some professional orgs. --

Re: Using -t to test rule changes

2024-05-09 Thread Bill Cole
the pre-check prep. It may be relevant what you have set report_type to in your local config. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Whitelist rules should never pass on SPF fail

2024-05-09 Thread Bill Cole
On 2024-05-09 at 08:37:06 UTC-0400 (Thu, 09 May 2024 14:37:06 +0200) Benny Pedersen is rumored to have said: Bill Cole skrev den 2024-05-09 14:22: In fact, I can't think of any whitelist test that should pass if SPF fails. If you operate on the theory that a SPF failure is always a sign

Re: Whitelist rules should never pass on SPF fail

2024-05-09 Thread Bill Cole
ules if a specific rule hits. This will also skip any other 'late' checks, so you have to set priorities with care to avoid shortcircuiting rules that you want checked. Consult the docs for details. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billm

Re: Tips for improving bounce message deliverability?

2024-04-24 Thread Bill Cole
SSAGE (and hence also ANY_BOUNCE_MESSAGE) is fairly unlikely to be spam, but we have pegged the scores for all the *BOUNCE_MESSAGE rules at 0.1 just to make sure that they are always published and visible as control points that can be used by sites that have a particular need to accept (or shun) some or all bounces. -- Bill Cole

Re: Defining what the default welcomelist means

2024-04-14 Thread Bill Cole
I believe we are in solid agreement, a few notes below explaining how... On 2024-04-14 at 08:00:19 UTC-0400 (Sun, 14 Apr 2024 08:00:19 -0400) Greg Troxel is rumored to have said: > Bill Cole writes: > >> On 2024-04-12 at 18:56:15 UTC-0400 (Fri, 12 Apr 2024 18:56:15 -0400) &g

Re: Defining what the default welcomelist means

2024-04-13 Thread Bill Cole
t; trigger. YMMV and YAMV (Attitude). FWIW, we can't maintain SA to accommodate the obstinacy of gated BITNET LISTSERV nodes in '89. The only reasons for unsub difficulties in 2024 are technical failures and spammer excuses. Modern SpamAssassin is only supposed to deal with modern realities,

Re: Defining what the default welcomelist means

2024-04-13 Thread Bill Cole
st has lost alignment with its origins. The original was a tactical mitigation against heavy phishing in a largely unauthenticated-sender world, deployed in part to forestall extreme responses to the problem of everyone claiming to send Paypal notifications to everyone. -- Bill Cole b...@scconsult.com

Re: Defining what the default welcomelist means

2024-04-13 Thread Bill Cole
On 2024-04-12 at 18:56:15 UTC-0400 (Fri, 12 Apr 2024 18:56:15 -0400) Greg Troxel is rumored to have said: > I see it very slightly differently, but mostly agree > > Bill Cole writes: > >> 1. We serve our users: receivers, not senders. Senders claiming FPs >> need the su

Re: Dynamic blacklist ?

2024-04-12 Thread Bill Cole
this if you have a directory full of fresh spam whose senders you want to shun: cd $spamdirectory spamassassin --add-to-blocklist * And if you have a bunch of mail you value in a directory, use "-W" instead. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpyboz

Defining what the default welcomelist means

2024-04-12 Thread Bill Cole
being added to the default welcomelist. As with everything SpamAssassin: input from users and other contributors is eagerly desired..., -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

WARNING: Microsoft has earned removal from SA default welcomelist

2024-04-12 Thread Bill Cole
een promulgated and accepted by the PMC or the user community. More to follow in a separate thread. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: problems with Plugin::ASN and spam

2024-04-11 Thread Bill Cole
p; sa1 run the same spamassassin/spamd configurations, neither of > them add the X-Spam-ASN headers. All other add_header entries work fine. Validate that configs on both machines match. In this sort of setup, only the SA config on the spamd hosts of the user spamd is run as makes any difference. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: problems with Plugin::ASN and spam

2024-04-10 Thread Bill Cole
annel for config and etermine which config files are actually being used by spamd and by spamassassin. (spamc knows nothing of SA configs...) -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: OT: Trigger words in email addresses?

2024-04-09 Thread Bill Cole
f complex multipart/alternative messages with HTML or (WORSE) pure HMTL. Modern MUAs recognize URLs in plaintext and for basic confirmations like this, you should keep the message as simple, clear, and unadorned as possible. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @gr

Re: Multiple test failures

2024-04-03 Thread Bill Cole
g the port spamd uses for testing. That is rare because it selects an unused high port on the loopback interface for the test run, but if you have a very tight network security policy in place, that can fail. SELinux and AppArmor can also interfere. Thanks Tuc On Wed, Apr 3, 2024 at 10:46 AM

Re: Syslog local3

2024-04-03 Thread Bill Cole
is set with the "-s" option, as documented in the man page. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Multiple test failures

2024-04-03 Thread Bill Cole
186. # Failed test at t/SATest.pm line 926. t/spamd_client.t .. 52/52 # Looks like you failed 14 tests of 52. t/spamd_client.t .. Dubious, test returned 14 (wstat 3584, 0xe00) Failed 14/52 subtests Any indications as to the issue? Thanks, Tuc -- Bill Cole

Re: Doesn't spamc/spamd need block/welcomeliist support???

2024-03-21 Thread Bill Cole
On 2024-03-21 at 13:21:54 UTC-0400 (Thu, 21 Mar 2024 18:21:54 +0100) is rumored to have said: > On 3/20/24 21:58, Bill Cole wrote: >> I'm not sure how I've not noticed before, but unless I'm missing something, >> there is no way to replicate the [block,welcome]list

Re: Doesn't spamc/spamd need block/welcomeliist support???

2024-03-21 Thread Bill Cole
On 2024-03-21 at 12:08:48 UTC-0400 (Thu, 21 Mar 2024 17:08:48 +0100) Matus UHLAR - fantomas is rumored to have said: On 20.03.24 16:58, Bill Cole wrote: I'm not sure how I've not noticed before, but unless I'm missing something, there is no way to replicate the [block,welcome]list

Re: Doesn't spamc/spamd need block/welcomeliist support???

2024-03-21 Thread Bill Cole
On 2024-03-21 at 11:57:43 UTC-0400 (Thu, 21 Mar 2024 11:57:43 -0400) Kris Deugau is rumored to have said: Bill Cole wrote: I'm not sure how I've not noticed before, but unless I'm missing something, there is no way to replicate the [block,welcome]list functionalities of the spamassassin

Doesn't spamc/spamd need block/welcomeliist support???

2024-03-20 Thread Bill Cole
for this missing functionality? I don't expect that it would be difficult to add. (Something I've believed every time I've taken on a coding task...) -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available

Re: OT: Microsoft Breech

2024-03-19 Thread Bill Cole
gt; >> Curiously, NOBODY has received any breach notifications from Microsoft, >> despite personal information being compromised. >> >> What has anyone else experienced? >> >> Thanks, >> >> -- Jared Hall >> -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Callout verification with SpamAssassin ?

2024-02-19 Thread Bill Cole
real problem. All set then. SA is not the right tool for you. Try something like Exim, MailMunge, or MIMEDefang that let you write arbitrary code for the mail-handling flow. I suppose you may be able do it in sendmail.cf too, if you're into self-torture. -- Bill Cole b...@scconsult.com

Re: Plugin fo content modification

2024-02-19 Thread Bill Cole
utter uselessness in the '90s. Aside from the fact that this would do active damage to the comprehensibility of some perfectly legitimate messages, it would invalidate any sort of authenticating signature (DKIM, PGP, S/MIME, whatever) -- Bill Cole b...@scconsult.com or billc...@apache.org

Re: SpamAssassin4 + DCC not populating "X-Spam-DCC: : " header ?

2024-02-18 Thread Bill Cole
dns_available set to 'no' -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Bayes "corpus" - how old?

2024-01-31 Thread Bill Cole
, Bill Cole wrote: If spammers can 'abuse' ALL_TRUSTED you have a major problem. Either a serious misconfiguration or compromised machines in trusted_networks. Can't ALL_TRUSTED happen if spammer delivers mail directly to my network, or, if last mail server removes Received: headers? I think

Re: Bayes "corpus" - how old?

2024-01-30 Thread Bill Cole
in trusted_networks. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Bayes "corpus" - how old?

2024-01-30 Thread Bill Cole
les. There are non-obvious fingerprints in some spam that imply decades-long spamming operations. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: install SA p a i n f u l l

2024-01-30 Thread Bill Cole
going to run cpan with force because that may hide *real* errors. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Dinged for .Date

2024-01-17 Thread Bill Cole
is not so big. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: symlinking config files

2024-01-05 Thread Bill Cole
m puzzled by this. -- Written by Thomas Krichel http://openlib.org/home/krichel on his 21399th day. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Question about forwarding email (not specifically SA, pointers greatly appreciated)

2024-01-03 Thread Bill Cole
ming service because it is forwarding spam. If users POP their mail instead of having it forwarded via SMTP, that does not happen. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: MS-relayed spam

2024-01-02 Thread Bill Cole
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: CO6PR20MB3698 And there's that correlating nonce again... I don't know if any of those thoughts will give ideas for good actual rules for you (or anyone) but they are what comes to mi9nd when I look at thos

Re: Spreadsheet::Excel ?

2023-12-29 Thread Bill Cole
-critical. In my experience it has been workable to just reject mail with .xls and .xlsx attachments by default at any Internet-facing MX. 20+ years of warnings about how reckless it is to share MS documents ought to suffice for anyone. -- Bill Cole b...@scconsult.com or billc...@apache.org

Re: Bayes always reject.

2023-12-13 Thread Bill Cole
with proper training. *IN THEORY* one could fix a corrupted DB by 'unlearning' messages which learned incorrectly, but as a practical matter that's usually a fantasy. Most of the scanning and DB details that you included are not useful. You cannot fix the bad DB, you need to rebuild it. -- Bill

Re: long delay with the new rules from 8 dec

2023-12-08 Thread Bill Cole
to 5/12 and it's back to 200 ~ 5000 ms. Note: I also have some personal rules. Am I the only one seeing this? -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: proper use of internal_networks?

2023-12-07 Thread Bill Cole
to" and "all_spam_to". Users in the first level may still get some spammish mails blocked, but users in "all_spam_to" should never get mail blocked. Those are all implemented through rules which you can adjust scores for and/or shortcircuit

Re: sa-learn on an Exchange public folder

2023-12-04 Thread Bill Cole
, while it uses its own proprietary formats internally. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Catch a rejected message ?

2023-12-01 Thread Bill Cole
cousin MailMunge both use a unique working directory for each message, and it is trivial to just replicate that whole structure elsewhere for safekeeping. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available

Re: ATT RBL f---wits

2023-11-27 Thread Bill Cole
l with this bullocks and gotten it resolved? Yes. Twice. Time is your friend. AT still operates like it's 1970... -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: spamc -L does not return 5, or 6

2023-11-08 Thread Bill Cole
it should be doing, >> except that it gives back 0 instead of 5 or 6. >> > It seems to be a documentation bug, see > https://bz.apache.org/SpamAssassin/show_bug.cgi?id=6069 and > https://bz.apache.org/SpamAssassin/show_bug.cgi?id=1201#c47 > Documentation fixed

Re: Getting error 74

2023-11-01 Thread Bill Cole
LinkedIn: http://www.linkedin.com/in/cecilwesterhof -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: spamd: still running as root

2023-10-30 Thread Bill Cole
for asking this is the log entry, just forget about it. 'man spamd' provides more info. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: external API request

2023-10-27 Thread Bill Cole
it, you'd need to create it yourself. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Missing Mail::SpamAssassin::Plugin::WelcomeListSubject

2023-10-26 Thread Bill Cole
n. Consult the author of 'w7_whitelist.cf' for support of whatever configuration it includes. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: def_welcomelist_auth versus def_whitelist_auth in 60_welcomelist_auth.cf

2023-10-12 Thread Bill Cole
th.cf Transmitting file data .done Committing transaction... Committed revision 1912923. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Getting phishing from sender in 60_welcomelist_auth.cf

2023-10-12 Thread Bill Cole
def_whitelist_auth *@*.subaru.com def_whitelist_auth *@*.aexp.com -def_whitelist_auth *@*.usssa.com def_whitelist_auth *@*.bestwesternrewards.com def_whitelist_auth *@*.email-weightwatchers.com def_whitelist_auth *@*.email-allstate.com On Thu, Oct 12, 2023 at 8:48 AM Bill Cole wrote: On 2023

Re: Getting phishing from sender in 60_welcomelist_auth.cf

2023-10-12 Thread Bill Cole
aren't open to being used for mischief and can justify the removal later if asked to. The bar for removal is very low (being listed is a privilege, not a right) but it can't be simply 'someone said...' On Wed, Oct 11, 2023 at 9:25 PM Bill Cole wrote: On 2023-10-11 at 16:45:15 UTC-0400

Re: Getting phishing from sender in 60_welcomelist_auth.cf

2023-10-11 Thread Bill Cole
in 60_welcomelist_auth.cf with def_welcomelist_auth/def_whitelist_auth entries with *@*.usssa.com. If anyone has a shareable sample spam to substantiate this, that would be helpful. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses

Re: Pre-processor for spamassassin

2023-10-08 Thread Bill Cole
ues of how to integrate a 'preprocessor' with your existing MTA and whatever yopu're using as 'glue' for SA. (content_filter script, spamass-milter, MIMEDefang, etc.) -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently

Re: Filtering emails from word-oliv...@somewhere.com

2023-10-05 Thread Bill Cole
autolearn it as spam, and (hopefully) recognize its sibling messages as such. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Mysterious bogus DKIM hits (was: Re: users Digest 29 Sep 2023 01:08:28 -0000 Issue 5575)

2023-09-29 Thread Bill Cole
f such violence if you compel it.) -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: DMARC and SA4

2023-09-26 Thread Bill Cole
ault scores don't make sense to me. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

NOTE: Score updates stalled.

2023-09-17 Thread Bill Cole
. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Stealth HREF= (missed by SA)

2023-09-15 Thread Bill Cole
ATTR publish On Thursday, September 14, 2023 at 04:37:15 PM GMT+2, wrote: On 9/14/23 16:24, Bill Cole wrote: On 2023-09-14 at 04:37:03 UTC-0400 (Thu, 14 Sep 2023 17:37:03 +0900) Joe Wein via users is rumored to have said: I filed a bug for this issue on Bugzilla (#8186) but so far no r

Re: Stealth HREF= (missed by SA)

2023-09-14 Thread Bill Cole
best approach may not be in trying to parse the bogus tag to glean a domain that may or may not be known to be bad, but rather to detect the general pattern, which is itself a direct indicator of bad intent. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.sccon

Re: DNS Help

2023-09-12 Thread Bill Cole
9.23 09:07, Bill Cole wrote: I believe that anyone with committer status in the SA repo can fix it. At first I was mystified by your problem description, but I believe I have fixed the issue (corrected the anchor in the referring link to "DnsBlocklists-dnsbl-block") I meant that the ht

Re: DNS Help

2023-09-12 Thread Bill Cole
locklists-dnsbl-block") -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Scoring Explanation Please

2023-08-30 Thread Bill Cole
. Essentially a very 'small' rule is duplicative of the detection being effectively done by a network source. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: To/CC to RCPT compare

2023-08-22 Thread Bill Cole
despise...) -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: uninitialized value $result in string eq at AuthRes.pm line 302

2023-08-19 Thread Bill Cole
nk/lib/Mail/SpamAssassin/Plugin/AuthRes.pm?r1=1907938=1907937=1907938 -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: spam_pid not found

2023-08-16 Thread Bill Cole
Sleeping 5 - Retry # 19 You cannot expect the build-time tests to succeed if you run them as root OR on a machine already running spamd. If this is not clear from reading the test documentation in the source distribution, please think about how we can make it clearer and make a sugges

Re: allow general access after 1 auth

2023-08-12 Thread Bill Cole
is available for everyone. Some inactivity timeout should lock the url again. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: unsubscore down?

2023-08-09 Thread Bill Cole
files on their website do not work. Their main website no longer makes any mention of the UBL. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: SA and UTF-8 Filename Attachments

2023-08-03 Thread Bill Cole
in Unicode handling was made between 3.4.x and 4.x and some distros that cherry-pick improvements may have backported fixes into what they call '3.4.6'. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Really hard-to-filter spam

2023-07-27 Thread Bill Cole
; marks and the like) that break the pattern and for lookalike non-ASCII characters (often Cyrillic or Greek) in the target string. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Ensuring SPF/DKIM for @gmail.com

2023-07-26 Thread Bill Cole
or so. Paul Vixie and I had both posted about how a 'reverse MX' or 'Mail Sender' record in DNS might work prior to that (and Paul credited someone else with the original idea) but those were not fully-developed mechanisms that anyone could actually deploy. -- Bill Cole b...@scconsult.com

Re: Welcome/unwelcome list not working correctly.

2023-07-21 Thread Bill Cole
ctives reverse the actions of welcomelist and blocklist directives. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: spamd runs as root on Fedora Server 38 ?! - was Re: Newb on sa-learn - didn't get what I expected as a response...

2023-07-09 Thread Bill Cole
sound reasons and they have not had security problems with it, in many years of operations. What you choose to do should be based on what YOU want. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available

Re: ALL_TRUSTED is Always in Headers

2023-06-23 Thread Bill Cole
ternally. See https://cwiki.apache.org/confluence/display/SPAMASSASSIN/DebugChannels for details. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: DMARC Aggregate reports - false positives

2023-06-22 Thread Bill Cole
, PYZOR_CHECK=1.392, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, T_TVD_MIME_NO_HEADERS=0.01] --  Simon Wilson M: 0400 121 116 -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many

Re: spamassassin4.x - problem

2023-06-20 Thread Bill Cole
On 2023-06-20 at 12:33:05 UTC-0400 (Tue, 20 Jun 2023 18:33:05 +0200) Patrick Proniewski is rumored to have said: On 20 Jun 2023, at 17:49, Bill Cole wrote: On 2023-06-20 at 09:39:04 UTC-0400 (Tue, 20 Jun 2023 15:39:04 +0200) Patrick Proniewski is rumored to have said: Hello, I'm running

Re: spamassassin4.x - problem

2023-06-20 Thread Bill Cole
amavis/tmp/.spamassassin271224psFL1itmp 132K/var/lib/amavis/tmp/.spamassassin27122814VcUntmp 228K/var/lib/amavis/tmp/.spamassassin271228ITPqiKtmp 8,0K/var/lib/amavis/tmp/.spamassassin271228MHHOoPtmp For test I downgrade one spamassassin from 4.x to 3.4.6 and problem not exists any idea ? -- -- B

Re: Help with rule

2023-06-06 Thread Bill Cole
On 2023-06-06 at 01:32:14 UTC-0400 (Tue, 6 Jun 2023 08:32:14 +0300) Henrik K via users is rumored to have said: On Tue, Jun 06, 2023 at 12:12:10AM -0400, Bill Cole wrote: Escape the @ with a \ SA uses Perl, so you need to escape %, @, and $ in regular expressions. Perl regular expressions

Re: Help with rule

2023-06-05 Thread Bill Cole
FROM_CLIENT_EMAIL From =~ /client@client\.com/i Escape the @ with a \ SA uses Perl, so you need to escape %, @, and $ in regular expressions. I think "spamassassin --lint" will catch unescaped special characters in rules, and it is always a good idea to run that when you add or change rules. -- B

Re: Mail::DKIM missing ed25519-sha256 ?

2023-05-30 Thread Bill Cole
support but no later activity. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Phishing from domain present in USER_IN_DEF_SPF_WL

2023-05-23 Thread Bill Cole
gt; X-Mailer: Zendesk Mailer > X-Zendesk-From-Account-Id: 83f40dd > DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=zendesk.com; > q=dns/txt; s=zendesk2; t=168488; > bh=hZXuEvY/OemVRfx2BSZkm7AF9OUMlXdBZZugXDZhHF0=; > > ... > > > Thierry -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: comparing sender domain against recipient domain

2023-05-12 Thread Bill Cole
On 2023-05-12 at 15:16:59 UTC-0400 (Fri, 12 May 2023 21:16:59 +0200) Matija Nalis is rumored to have said: > But I was more interested if SA already has something like that? It does not. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.

Re: comparing sender domain against recipient domain

2023-05-11 Thread Bill Cole
with names containing TO_EQ_FROM in the default rule channel. Consult the rules files for implementation details. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: DKIM absence

2023-05-02 Thread Bill Cole
on something which is only wrong *IN YOUR HEAD* is hard. ADSP and DMARC both exist apart from DKIM. It is an entirely valid choice to NOT use them. (surely this is doable in a plugin; it's not conceptually hard) Feel free to implement it on your own and report back the results. -- Bill Cole b

Re: Did the whitelist_from_rcvd semantics change?

2023-05-01 Thread Bill Cole
:17 PM, Philip Prindeville wrote: On Apr 28, 2023, at 10:24 AM, Reindl Harald wrote: Am 28.04.23 um 18:11 schrieb Philip Prindeville: On Apr 25, 2023, at 6:28 AM, Bill Cole wrote: On 2023-04-24 at 16:32:55 UTC-0400 (Mon, 24 Apr 2023 14:32:55 -0600) Philip Prindeville is rumored

Re: Did the whitelist_from_rcvd semantics change?

2023-04-28 Thread Bill Cole
On 2023-04-28 at 12:11:02 UTC-0400 (Fri, 28 Apr 2023 10:11:02 -0600) Philip Prindeville is rumored to have said: On Apr 25, 2023, at 6:28 AM, Bill Cole wrote: On 2023-04-24 at 16:32:55 UTC-0400 (Mon, 24 Apr 2023 14:32:55 -0600) Philip Prindeville is rumored to have said: I thought

Re: FROM_RETURNPATH_MISMATCH

2023-04-28 Thread Bill Cole
) and the message header From address (RFC5322.From) which are not intrinsically identical but usually are in person-to-person email. The *actual* definition of that rule will be somewhere in your SA config, most likely in /etc/mail/spamassassin/local.cf -- Bill Cole b...@scconsult.com or billc

Re: Fine-tuning SA URI extraction

2023-04-26 Thread Bill Cole
that your analysis of what is happening is not entirely wrong. You may be able to nail down what is actually happening by scanning a problematic message with "-D all" and determining *exactly* what SA is parsing as a URI that it should not. -- Bill Cole b...@scconsult.com or billc...@

Re: Did the whitelist_from_rcvd semantics change?

2023-04-25 Thread Bill Cole
On 2023-04-24 at 16:32:55 UTC-0400 (Mon, 24 Apr 2023 14:32:55 -0600) Philip Prindeville is rumored to have said: I thought the matching included subdomains, and seem to remember that working. It never has. At least not in the past 17 years. -- Bill Cole b...@scconsult.com or billc

Re: Which commercial engine to combine with SpamAssassin?

2023-03-24 Thread Bill Cole
n antispam SDK to be combined with spamassassin? What gap in SA are you trying to fill? I'm reading "SDK" as "Software Development Kit" and your query is just not making sense to me in connection to SA. -- Bill Cole b...@scconsult.com or billc...@apache

Re: OFF-TOPIC ANNOUNCE: KAM Ruleset Turning PCCC Wild RBL Back On

2023-03-21 Thread Bill Cole
there... -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

  1   2   3   4   5   6   7   8   9   10   >