Re: Custom rule to please the Mayor

2019-11-25 Thread Matus UHLAR - fantomas
ut people must still be sure. That's why some people for years recommend using PGP or S/MIME mail signatures. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT ak

Re: Getting spamass-milter to work with postfix

2019-11-24 Thread Matus UHLAR - fantomas
On 24/11/2019 15:57, Matus UHLAR - fantomas wrote: I have explained that this was caused by receiving mail for "admin" thus spamass-milter provider username admin. Since the admin doesn't exist locally (apparently alias or remote user), spamd falled back to nobody. On 24.11.19 1

Re: Getting spamass-milter to work with postfix

2019-11-24 Thread Matus UHLAR - fantomas
On 24/11/2019 14:47, Matus UHLAR - fantomas wrote: then you have your problem fixed. On 24.11.19 15:21, Linkcheck wrote: More or less. It works (although not sure what will happen on reboot - will it auto-run spamass-milter and spamd?) but I am trying to clean up the remaining log entries

Re: Getting spamass-milter to work with postfix

2019-11-24 Thread Matus UHLAR - fantomas
"admin" thus spamass-milter provider username admin. Since the admin doesn't exist locally (apparently alias or remote user), spamd falled back to nobody. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this

Re: Getting spamass-milter to work with postfix

2019-11-24 Thread Matus UHLAR - fantomas
On 24/11/2019 14:00, Matus UHLAR - fantomas wrote: relative to the chroot value. On 24.11.19 14:22, Linkcheck wrote: I repeat, no chroot involved! Otherwise, the two values are the same... if you don't use chroot, then it's "/". main.cf unix:/var/run/spamass/spama

Re: Getting spamass-milter to work with postfix

2019-11-24 Thread Matus UHLAR - fantomas
working. It clearly did pass mail and the username (admin) to spamd. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. The early bird may get the worm, but the second mouse gets the cheese.

Re: Where is SA getting config info?

2019-11-23 Thread Matus UHLAR - fantomas
On 22.11.19 12:14, Jerry Malcolm wrote: I am trying to add bayes to SA.  I see in the docs that there is a use_bayes parm and the path parm.  I made the changes to /usr/share/spamassassin/local.cf. On 11/22/2019 12:25 PM, Matus UHLAR - fantomas wrote: the config files and rules are usually

Re: Where is SA getting config info?

2019-11-22 Thread Matus UHLAR - fantomas
seen by SA. you thought wrong, I don't know where did you get that info. /etc/ stores system-wide settings on UN*X systems.     -- Finally, where should I put custom rule files such as KAM.cf so they are used, but not erased with sa_update? see LOCAL_RULES_DIR in your debug output --

Re: Getting spamass-milter to work with postfix

2019-11-18 Thread Matus UHLAR - fantomas
sr/sbin/postfix executable. So, you should NOT use inet:localhost:783 for milter socket, since it's not the milter, but the spamd socket. find out which socket has spamass-milter open and try connecting postfix to that one. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/

Re: How to Bypass Specific Spamassassin Rule

2019-11-15 Thread Matus UHLAR - fantomas
ok_languages setting. if amavis (global settings), wouldn't it be better to add that language to ok_languages I feel amavis can use per-destination domain rules, is you use it, maybe ask in its list? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish N

Re: Getting spamass-milter to work with postfix

2019-11-13 Thread Matus UHLAR - fantomas
On 13.11.19 12:01, Linkcheck wrote: I was rather hoping someone could supply a basic setup that would allow spamass-milter to run with postfix, which is why I originally posted so much information. On 13.11.19 14:12, Matus UHLAR - fantomas wrote: You mention having Mint (Ubuntu 16). Ubuntu

Re: Getting spamass-milter to work with postfix

2019-11-13 Thread Matus UHLAR - fantomas
= smtp inet n - y - - smtpd -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Atheism is a n

Re: Getting spamass-milter to work with postfix

2019-11-12 Thread Matus UHLAR - fantomas
smtpd is run on your system without chroot. May not be true on the OPs system. Let's change it to: "with postfix, you may need to set up milter wocket within its chroot" -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: Getting spamass-milter to work with postfix

2019-11-10 Thread Matus UHLAR - fantomas
o tried spamass-milter:postfix. with postfix, you need to set up milter wocket within its chroot. on debian/ubuntu consult /etc/default/spamass-milter -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie:

Re: Bombard by spam source in India that wasn't in any RBL used by spamassassin.

2019-11-08 Thread Matus UHLAR - fantomas
On 06.11.19 14:33, Mark London wrote: >I was able to successfully add rules for spamrats and gbudb. Does >anyone have experience with those? On Thu, 7 Nov 2019 19:22:09 +0100 Matus UHLAR - fantomas wrote: bad experience iirc. https://mail-archives.apache.org/mod_mbox/spamassassin

Re: Getting spamass-milter to work with postfix

2019-11-07 Thread Matus UHLAR - fantomas
rotocol = 6 smtpd_milters = unix:/var/run/opendkim/opendkim.sock, unix:/var/run/opendmarc/opendmarc.sock, unix:/var/run/spamass/spamass.sock, this is afaik the default spamass-milter socket on debian/ubuntu. unix:/var/run/clamav/clamav-milter.ctl non_smtpd_milters = unix:/var/run/opendkim/o

Re: Bombard by spam source in India that wasn't in any RBL used by spamassassin.

2019-11-07 Thread Matus UHLAR - fantomas
On 06.11.19 14:33, Mark London wrote: I was able to successfully add rules for spamrats and gbudb. Does anyone have experience with those? bad experience iirc. https://mail-archives.apache.org/mod_mbox/spamassassin-users/200904.mbox/<20090408151911.GA21449%40fantomas.sk> -- Matus

Re: use of razor/pyzor/dcc on not english messages

2019-10-24 Thread Matus UHLAR - fantomas
On 22.10.19 16:24, hg user wrote: I'm wondering if the plugins listed in the subject may help with messages that are not in english... yes. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovani

Re: Monitoring the effectiveness of anti-spam measures

2019-10-02 Thread Matus UHLAR - fantomas
/2019 10:53 AM, Matus UHLAR - fantomas wrote: maybe just nobody did answer. Maybe you didn't post a question to be answered? On 01.10.19 11:05, Ramon F Herrera wrote: I did not receive my copy and after that, I posted something else without a problem. Then, I tried sending the same messag

Re: Monitoring the effectiveness of anti-spam measures

2019-10-01 Thread Matus UHLAR - fantomas
nobody did answer. Maybe you didn't post a question to be answered? Well, here is goes again, this time as an attachment. no, don't post attachments to the list. if you need to send a spample, use pastebin. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warni

Re: Setting Threshold (Resolved)

2019-09-28 Thread Matus UHLAR - fantomas
On 28.09.19 00:21, Jerry Malcolm wrote: With my extra parameter added /usr/bin/perl -T -w /usr/bin/spamd --pidfile /var/run/spamd.pid -D -d -c -m5 -H --cf=required_score 4.0 On 9/28/2019 9:38 AM, Matus UHLAR - fantomas wrote: the "required_score 4.0" should be enclosed in

Re: Setting Threshold

2019-09-28 Thread Matus UHLAR - fantomas
ng no argument, spamd will use the spamc caller's home directory instead." so, the calling user $HOME/.spamassassin/user_prefs is used -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Va

Re: 3 Lines of Defense

2019-09-28 Thread Matus UHLAR - fantomas
that were missed by spamhaus. that's mostly because clients rejected by spamcop were already rejected by spamhaus. btw I have very good experience with FEATURE(`greet_pause', `6000') -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to

Re: regex rule

2019-09-25 Thread Matus UHLAR - fantomas
e part of e-mail and it's being added when delivering mail to mailbox. How do you run spamassassin? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek rek

Re: possible FORGED_GMAIL_RCVD false positive

2019-09-19 Thread Matus UHLAR - fantomas
On Wed, 18 Sep 2019 12:29:43 +0200 Matus UHLAR - fantomas wrote: > I have received following spam: > > https://pastebin.com/SkvkVWik > > This hits FORGED_GMAIL_RCVD although the message came from google mail > servers. > > According to HeaderEval.pm, message apparentl

possible FORGED_GMAIL_RCVD false positive

2019-09-18 Thread Matus UHLAR - fantomas
? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Linux is like a teepee: no Windows, no Gates and an apache inside...

Re: Something missing in AvoidingFpsForSenders?

2019-09-14 Thread Matus UHLAR - fantomas
date version: X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on mail-tester.com but it looks like they don't update their rules. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address

Re: Score in subject differs from score in headers

2019-09-06 Thread Matus UHLAR - fantomas
and when delivering to end-users (you)? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I wonder how much deeper the ocean would be without sponges.

Re: Scoring TLS.

2019-09-06 Thread Matus UHLAR - fantomas
TLSv1.0 is EOLed and should not be used nor supported. On 6 Sep 2019, at 01:57, Matus UHLAR - fantomas wrote: well, if your clients (some old server installations) only support tls1.0, it's better to allow it than forgint it to go plaintext or reject the mail at all. On 06.09.19

Re: Score in subject differs from score in headers

2019-09-06 Thread Matus UHLAR - fantomas
sin between the mail server and me that could have added the score to the subject. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Due

Re: Scoring TLS.

2019-09-06 Thread Matus UHLAR - fantomas
On 6 Sep 2019, at 00:51, Reio Remma wrote: Even though I recall QMail having TLSv1 back when we were still using it. On 06.09.19 00:57, @lbutlr wrote: TLSv1.0 is EOLed and should not be used nor supported. On 06/09/2019 10:57, Matus UHLAR - fantomas wrote: well, if your clients (some

Re: Scoring TLS.

2019-09-06 Thread Matus UHLAR - fantomas
x27;s better to allow it than forgint it to go plaintext or reject the mail at all. http://postfix.1071664.n5.nabble.com/Update-to-recommended-TLS-settings-td78583.html http://postfix.1071664.n5.nabble.com/Update-to-recommended-TLS-settings-td96604.html just FYI -- Matus UHLAR - fantomas, uh...@fantom

Re: Spanish language i.c.w. DRUGS_ERECTILE et al.

2019-08-30 Thread Matus UHLAR - fantomas
hn Hardin wrote: And a familiarity with potentially many languages... maybe that deeper logic could understand per-language list of words that cause FPs, That apparently needs issues related to normalize_charset fixed. Those languages often use non-ascii charsets in those words. -- Matus UH

Re: Spanish language i.c.w. DRUGS_ERECTILE et al.

2019-08-29 Thread Matus UHLAR - fantomas
that URL here.) As this is a body rule, feel free to mangle the headers as needed for privacy, apart possibly from the Subject... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu c

Re: announcement about invaluement (or more like a tease?)

2019-08-26 Thread Matus UHLAR - fantomas
This technology will then be shared with other blacklists - so that they can partake in this industry "reset". It will be at least as monumental as the release of the first URI/domain blacklist (of which I was heavily involved). -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://

Re: How to block mails from unknown ip addresses?

2019-08-25 Thread Matus UHLAR - fantomas
ke mess on debian system. Onlly install debian packages unless you really need and can take care of manually installed packages. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOS

Re: sendmail milter

2019-08-02 Thread Matus UHLAR - fantomas
t modified (except headers). Is it the milter that it preventing doing this ? apparently. I don't think spamass-milter supports report_safe. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie:

Re: amavisd 100% cpu load - 470 queued messages...

2019-06-28 Thread Matus UHLAR - fantomas
ve >different hashes On Fri, Jun 28, 2019 at 01:23:38PM +0200, Matus UHLAR - fantomas wrote: 6 seconds message scanning is quite fast. I have set up razor,pyzor,dcc,dnsbl timeouts to 20 seconds to improve acurracy (maybe marginally, but I don't care). If you receive that much mail oft

Re: amavisd 100% cpu load - 470 queued messages...

2019-06-28 Thread Matus UHLAR - fantomas
(and they are effective so don't mess them up). -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Atheism is a non-prophet organization.

Re: amavisd 100% cpu load - 470 queued messages...

2019-06-28 Thread Matus UHLAR - fantomas
create accuracy. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Nothing is fool-proof to a talented fool.

Re: spamass-milter reject?

2019-06-27 Thread Matus UHLAR - fantomas
On 27 Jun 2019, at 9:33, Matus UHLAR - fantomas wrote: for mail received from the net I use amavisd-new with amavisd-milter. Content filter accepts message, I don't want to drop it, send bounce or send it to anyone. I use content filter for mail sent from internal network or th

Re: spamass-milter reject?

2019-06-27 Thread Matus UHLAR - fantomas
send it to anyone. I use content filter for mail sent from internal network or through alternative ports. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akuk

Re: spamass-milter reject?

2019-06-26 Thread Matus UHLAR - fantomas
I simply overcame this by setting SA’s required_score parameter to a desired value in mail/spamassassin/local.cf On 25 Jun 2019, at 22:14, Matus UHLAR - fantomas wrote: I have different value in required_score than I use in -r flag. However that's sendmail installation. There's

Re: How to create my personal RBL

2019-06-25 Thread Matus UHLAR - fantomas
tool is a *lot* faster than ferreting through a set of very large mail folders with your MUA, though of course the effort of creating and maintaining the database, mail loader, query tools and SA plugin is non trivial. well, if THIS is the real reason... -- Matus UHLAR - fantomas, uh...@fan

Re: spamass-milter reject?

2019-06-25 Thread Matus UHLAR - fantomas
than I use in -r flag. However that's sendmail installation. There's something strange here. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek rekl

Re: check_rbl digging too deep

2019-06-25 Thread Matus UHLAR - fantomas
as a poison-pill DNSBL. That would avoid any chance of it being used "too deeply"... no. Many people consider Zen reliable enough to reject connections from listed IP. Deep header scanning is something very different. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fanto

Re: How to create my personal RBL

2019-06-25 Thread Matus UHLAR - fantomas
k the simpler solution would be a list in SA...) you don't need restart SA to refresh RBL data. rbldnsd stores data in simple files but is able to reload them automatically. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertisi

Re: check_rbl digging too deep

2019-06-25 Thread Matus UHLAR - fantomas
', 'zen.spamhaus.org.') header RCVD_IN_XBL eval:check_rbl('zen-lastexternal', 'zen.spamhaus.org.', '^127\.0\.0\.[45678]$') header RCVD_IN_PBL eval:check_rbl('zen-lastexternal', 'zen.spamhaus.org.', '^127\.0\

Re: spamass-milter reject?

2019-06-23 Thread Matus UHLAR - fantomas
<58406><0HQIDZ6kD10m5AAAIdGjjQ>: sieve: msgid=<0.0.0.18.1d529dd9c4b5bac.2d3...@mail.jake-powers.com>: stored mail into mailbox ‘Junk' What else do I need to do so that the -r 10 setting actually rejects the high scoring spam? is the milter really in action? is it the

Re: Um, T'Bird and Spamassassin are not seeing eye to eye lately

2019-06-19 Thread Matus UHLAR - fantomas
eceived =~ /iPlanet Messaging Server/ header __HOTMAIL_BAYDAV_MSGID MESSAGEID =~ /^<[A-Z]{3}\d+-(?:DAV|SMTP)\d+[A-Z0-9]{25}\@phx\.gbl>$/m header __SYMPATICO_MSGID MESSAGEID =~ /^$/m -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: Mail to local users

2019-06-18 Thread Matus UHLAR - fantomas
On 17 Jun 2019, at 02:07, Matus UHLAR - fantomas wrote: But how do I tell spamass-milter not to check for PBL and other similar tests on mails from local users to local users? don't. This is exactly what spammers try for years to avoid being detected. On 17.06.19 08:30, @lbutlr

Re: Mail to local users

2019-06-17 Thread Matus UHLAR - fantomas
milter not to check for PBL and other similar tests on mails from local users to local users? don't. This is exactly what spammers try for years to avoid being detected. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: SPF Fail for Amazon mails, although mail headers say its a pass

2019-06-06 Thread Matus UHLAR - fantomas
hould be used after mail leaves the server. I have to think about this a bit more. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. 2

Re: SPF Fail for Amazon mails, although mail headers say its a pass

2019-06-06 Thread Matus UHLAR - fantomas
On 06.06.19 00:59, MarcelM wrote: Ahh... I see. So probably other headers are modified by the mail server as well, and that is why SA's SPF check fails! Why would it do that ? I will read up on that. because, after forwarding is done, SPF would fail - that is why SRS applied. -- Matus

Re: SPF Fail for Amazon mails, although mail headers say its a pass

2019-06-06 Thread Matus UHLAR - fantomas
nd here... but the mail server obviously thinks it's valid, which it probably is, at least it is legit and amazon should have correctly configured mail servers - I hope... Return-Path: this is mail from ampel-24.de, not amazon. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas

Re: MISSING_SUBJECT rule on email with subject

2019-06-04 Thread Matus UHLAR - fantomas
BJECTMissing Subject: header so the spam scanner both did and did not see the From: header. What do you use for mail scanning? On 2019/06/04 10:55, Matus UHLAR - fantomas wrote: On 3 Jun 2019, at 2:20, Stephan Fourie wrote: We're currently seeing the rule MISSING_SUBJECT sporadical

Re: MISSING_SUBJECT rule on email with subject

2019-06-04 Thread Matus UHLAR - fantomas
misformatted e-mail. But since FROM_AND_TO_IS_SAME_DOMAIN was hit, I don't think the spaces were stripped, so - we need to see the original message as it was scanned. Anything else, reformated by anyone (e.g. outlook or exchange use to reformat mail), can't help us much finding the issue. -- Matus U

Re: Is Bayes forgetting ?

2019-05-29 Thread Matus UHLAR - fantomas
massassin is actually used via amavis, in a zimbra setup. To teach sa-learn and to test the results via command line I use zimbra user. On Mon, May 27, 2019 at 1:18 PM Matus UHLAR - fantomas < [ mailto:uh...@fantomas.sk | uh...@fantomas.sk ] > wrote: On 27.05.19 12:51, hg user wrote: >

Re: my spamassassin has serious config problems

2019-05-28 Thread Matus UHLAR - fantomas
ns :-) I excluded all the headers of my antivirus and internal/external/trusted. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Spam is

Re: my spamassassin has serious config problems

2019-05-28 Thread Matus UHLAR - fantomas
and I was shocked by what I saw ! > >x-spam-relays-external lists all the hops of the message *including* internal >servers and so x-spam-relays-internal is empty... I specifically asked to >add the antivirus and other internal MTAs to the internal list... how? -- Matus UHLAR - fanto

Re: my spamassassin has serious config problems

2019-05-28 Thread Matus UHLAR - fantomas
have these configs set properly, he just must use zimbra's settings which I don't know how to manage. "spamassassin" binary ues $HOME/ while zimbra installation stores them in directory that is not in $HOME of any user. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://ww

Re: my spamassassin has serious config problems

2019-05-27 Thread Matus UHLAR - fantomas
*including* internal servers and so x-spam-relays-internal is empty... I specifically asked to add the antivirus and other internal MTAs to the internal list... how? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this

Re: Is Bayes forgetting ?

2019-05-27 Thread Matus UHLAR - fantomas
turns BAYES_50 *wait a few minutes, no new messages learnt* spamassassin -t corpus/spam/phish-tst returns BAYES_00 apparently zimbra does more than just this. Did you try to ask in zimbra forums first? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to rece

Re: Is Bayes forgetting ?

2019-05-27 Thread Matus UHLAR - fantomas
n Mon, May 27, 2019 at 1:18 PM Matus UHLAR - fantomas wrote: On 27.05.19 12:51, hg user wrote: >the Linux user is the same. the same as what? >Bayes db is on Linux. seems I wasn't clear at my question: How do you use spamassassin? milter, amavis, procmail filter, postfix filter .

Re: Is Bayes forgetting ?

2019-05-27 Thread Matus UHLAR - fantomas
On 27.05.19 12:51, hg user wrote: the Linux user is the same. the same as what? Bayes db is on Linux. seems I wasn't clear at my question: How do you use spamassassin? milter, amavis, procmail filter, postfix filter ... ? -- Matus UHLAR - fantomas, uh...@fantomas.sk ;

Re: Is Bayes forgetting ?

2019-05-27 Thread Matus UHLAR - fantomas
earnt (autolearn=no), the message is reported as BAYES_00 !!! I'm testing with command line spamassassin -t file. hos do you use bayes? THe most common reason for this is that people use different user for checking (e.g. amavis uses user 'amavis') than for training (the current us

Re: TVD_RCVD_SINGLE hitting

2019-05-24 Thread Matus UHLAR - fantomas
On Thu, 23 May 2019, Matus UHLAR - fantomas wrote: I see. This is another case where local clients hit bunch of rules designed to catch remote bots. I'm thinking if I should disable the rule or if it's better to re-write it only to match on remote (untrusted) hosts. On 23.05.19 1

Re: TVD_RCVD_SINGLE hitting

2019-05-23 Thread Matus UHLAR - fantomas
On Thu, 23 May 2019 19:52:41 +0200 Matus UHLAR - fantomas wrote: >> On 22.05.19 09:34, John Hardin wrote: >> >I'm surprised it's still present - the masscheck corpus spam/ham >> >is > >> >It could probably be safely removed if there's any qu

Re: TVD_RCVD_SINGLE hitting

2019-05-23 Thread Matus UHLAR - fantomas
On 22.05.19 09:34, John Hardin wrote: >I'm surprised it's still present - the masscheck corpus spam/ham is >It could probably be safely removed if there's any question about >it. On Thu, 23 May 2019 16:59:01 +0200 Matus UHLAR - fantomas wrote: well, the sco

Re: TVD_RCVD_SINGLE hitting

2019-05-23 Thread Matus UHLAR - fantomas
D_RCVD_SINGLE/detail It could probably be safely removed if there's any question about it. well, the score is still high: score TVD_RCVD_SINGLE 0.242 1.213 0.001 2.172 and it matches any helo string containing of uppercase characters (and some companies still have local computers with u

TVD_RCVD_SINGLE hitting

2019-05-22 Thread Matus UHLAR - fantomas
hostnames consisting of uppercase characters and undersores, or more recisely, every hostname not containing lowercase, number, dash or dot. Is this the expected behaviour? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to

Re: SpamAssassin Scoring For MDAEMON_DNSBL

2019-05-14 Thread Matus UHLAR - fantomas
On 14.05.19 06:18, cyflhn wrote: but what about this one "FREEMAIL_FORGED_REPLYTO". why it got 2.1 score? this is standard rule where mail predenting to come from one freemail service really comes from another freemail service. -- Matus UHLAR - fantomas, uh...@fantomas

Re: Rule for non-DKIM-signed messages

2019-05-10 Thread Matus UHLAR - fantomas
y Microsoft mail servers on the way out. If DKIM_VALID was hit, then it means the spam wasn't modified. I also doubt if DKIM_VALID is enough. To be sure, the mail should hit DKIM_VALID_AU to prove it was signed by the sender's mail server... -- Matus UHLAR - fantomas, uh...@fantomas.sk

Re: DOS_OUTLOOK_TO_MX dependency on T_DOS_OUTLOOK_TO_MX_IMAGE

2019-04-29 Thread Matus UHLAR - fantomas
On Mon, 29 Apr 2019, Matus UHLAR - fantomas wrote: I see that DOS_OUTLOOK_TO_MX is complementary to T_DOS_OUTLOOK_TO_MX_IMAGE: meta DOS_OUTLOOK_TO_MX __ANY_OUTLOOK_MUA && !__OE_MUA && __DOS_DIRECT_TO_MX && !T_DOS_OUTLOOK_TO_MX_IMAGE meta T_DOS_OUTLOOK_TO_MX_

DOS_OUTLOOK_TO_MX dependency on T_DOS_OUTLOOK_TO_MX_IMAGE

2019-04-29 Thread Matus UHLAR - fantomas
!__OE_MUA && __DOS_DIRECT_TO_MX && __ANY_IMAGE_ATTACH I am not sure whether it's wise to have rule depending on test (T_) rule. it also lowers final score, because: score DOS_OUTLOOK_TO_MX 2.636 1.449 1.737 2.845 while T_ only has 0.01 -- Matus UHLAR - fantomas, uh...@fantoma

Re: locally submitted / outgoing mail hitting multiple rules

2019-04-27 Thread Matus UHLAR - fantomas
On Fri, 26 Apr 2019, Matus UHLAR - fantomas wrote: Btw, sorry John for not answering your last question: https://marc.info/?l=spamassassin-users&m=153633826515464&w=2 For now, I believe that using (ALL_TRUSTED && __DOS_SINGLE_EXT_RELAY) is just what I need to prevent all r

Re: __DOS_DIRECT_TO_MX superflous __DOS_RELAYED_EXT

2019-04-27 Thread Matus UHLAR - fantomas
On Fri, 26 Apr 2019 15:44:54 +0200 Matus UHLAR - fantomas wrote: when looking at __DOS_DIRECT_TO_MX I have noticed that it consists of one superflous rule: ... I believe hitting __DOS_SINGLE_EXT_RELAY implies not hitting __DOS_RELAYED_EXT, because: header __DOS_SINGLE_EXT_RELAY X-Spam

locally submitted / outgoing mail hitting multiple rules

2019-04-26 Thread Matus UHLAR - fantomas
TO_MX - I don't think adding && !ALL_TRUSTED should cause an issue here __DOS_SINGLE_EXT_RELAY is currently only used in rules DOS_FIX_MY_URI - adding !ALL_TRUSTED shouldn't break anything HDR_ORDER_FTSDMCXX_DIRECT - !ALL_TRUSTED was added already HDRS_LCASE T_MANY_HDRS_LCASE

__DOS_DIRECT_TO_MX superflous __DOS_RELAYED_EXT

2019-04-26 Thread Matus UHLAR - fantomas
iI][vV][eE][dD]:\s/s looking at the docs, __DOS_RELAYED_EXT only matches when there are multiple Received: headers in external relays, however such mail would have multiple relays in X-Spam-Relays-External and thus it could not match __DOS_SINGLE_EXT_RELAY do I misunderstand this? -- Matus UHL

Re: Mail::SpamAssassin::Plugin::TextCat

2019-04-25 Thread Matus UHLAR - fantomas
re. Note that I reject spam scoring too much. AFAIK, it has/had problems with utf encoding, but if this is fixed, rules should work great again. the only issue is that users must set up their wanted languages -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish N

Re: Amazon continues to get tagged as spam

2019-04-02 Thread Matus UHLAR - fantomas
picking up the local.cf file? spamass-milter can make spamd use receiving user's user_prefs if you user "-u defaultuser" option. When there are multiple receiving users, the "defaultuser" is used. Can't user_prefs clear whitelists? -- Matus UHLAR - fantomas, uh...@fantomas

Re: Amazon continues to get tagged as spam

2019-04-02 Thread Matus UHLAR - fantomas
On 2 Apr 2019, at 03:52, Matus UHLAR - fantomas wrote: whitelist_from_rcvd @amazon.com amazonses.com should apparently be: whitelist_from_rcvd *@amazon.com amazonses.com On 02.04.19 04:11, @lbutlr wrote: I'll try that. and why doesn't whitelist_from order-upd...@amazon.com wor

Re: Amazon continues to get tagged as spam

2019-04-02 Thread Matus UHLAR - fantomas
_from order-upd...@amazon.com work could be shown in SA debug mode. (maybe you put it there after the mail came?) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT aku

Re: Filtering at border routers: Is it possible?

2019-03-26 Thread Matus UHLAR - fantomas
On 25 Mar 2019, at 09:49, Matus UHLAR - fantomas wrote: I can't see anywhere how smtps could mean multicast audio. On 25.03.19 22:27, @lbutlr wrote: That may have been a different use for port 465? I was operating from memory. different use, but it was not called ssmtp. what I want t

Re: Filtering at border routers: Is it possible?

2019-03-25 Thread Matus UHLAR - fantomas
w typical for them), which is compatible now. Finally, I hope we have discussed this and can finish this thread :) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. 42.7 percent of all statistics are made up on the spot.

Re: Filtering at border routers: Is it possible?

2019-03-24 Thread Matus UHLAR - fantomas
://web.archive.org/web/20150603202057/http://www.imc.org/ietf-apps-tls/mail-archive/msg00204.html -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu

Re: Filtering at border routers: Is it possible?

2019-03-23 Thread Matus UHLAR - fantomas
fix option smtpd_tls_auth_only (default no - I wonder why) does this. However, if you are able to force clients using alternative ports, it's better to disable auth at port 25 at all. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail adv

Re: whitelist_from_rcvd hits only sometimes

2019-03-01 Thread Matus UHLAR - fantomas
com >messagelabs.com whitelist_from_rcvd >quarant...@eu.quarantine.symantec.com messagelabs.net >Miss: On Fri, 1 Mar 2019 17:46:55 +0100 Matus UHLAR - fantomas wrote: this looks like the "mydomain Content Filter" has modified the message headers so spamassassin didn't parse

Re: whitelist_from_rcvd hits only sometimes

2019-03-01 Thread Matus UHLAR - fantomas
gt; From: Email Quarantine -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. You have the right to remain silent. Anything you say will be misquoted, then used against you.

Re: Spamassassin "ignoring" mail with embedded picture

2019-02-15 Thread Matus UHLAR - fantomas
l. spamc default limit is 500K, you can increase it to 256M. scanning of bigger mail can take minutes, e.g. FuzzyOCR calling OCR programs. I think the default timeout is 5 minutes. All other mails (with or without attachments) are going through just fine. Any ideas? Is there a known bug which cou

Re: sa-update when were last updates made?

2019-01-24 Thread Matus UHLAR - fantomas
are all dated 18-10-2018 these are not to be updated, they were installed with SA and are only used when you don't fetch newer in /var/... so.. are the files in /usr/…. running in preference to the files in /var/… and if so, how do I ensure the latest ones are used? answer above. -- Matus

Re: UTF8 character in [] doesn't match

2018-12-24 Thread Matus UHLAR - fantomas
> On Sun, 23 Dec 2018 20:04:28 +0100 > Matus UHLAR - fantomas wrote: > > I have tried to create rule that will match names "ján" and > > "jano" (john and johnny in slovak languages). > > > > I have created rule: > > > > body LOC

Re: UTF8 character in [] doesn't match

2018-12-23 Thread Matus UHLAR - fantomas
On Sun, 23 Dec 2018, Matus UHLAR - fantomas wrote: I have tried to create rule that will match names "ján" and "jano" (john and johnny in slovak languages). I have created rule: body LOCAL_JANO /\bJ[aá]no\b/i fixed: bodyLOCAL_JANO /\bJ[aá]no?\b/

UTF8 character in [] doesn't match

2018-12-23 Thread Matus UHLAR - fantomas
et to '1'. any idea what can cause this? Debian 9, SA 3.4.2, perl 5.24.1 -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "

Re: Help needed - Regex filter with exclude

2018-12-23 Thread Matus UHLAR - fantomas
@ is legal in Hungary. :S is blocking mail to info@ illegal in Hungary? if not, why bother? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. M

Re: repeated sa-update problems

2018-12-17 Thread Matus UHLAR - fantomas
g to this, I believe that the "-z" option for CURL should be dropped. On 20.09.18 16:05, Matus UHLAR - fantomas wrote: I looked at update times and they are different each day - debian script sleeps random number of seconds (up to one hour) in order to lower the impact at mirror s

Re: SpamSender with 2 @-signs in the address

2018-12-12 Thread Matus UHLAR - fantomas
e login name needs be specified as „user\shared“ - and if both use SMTP-formatted addresses, this would look like „u...@example.com\sharedmail...@example.com“. I don't think so. Just today I've seen header likce From: "name surname " -- Matus UHLAR - fantomas, uh...@fantomas.sk ;

Re: openssl 1.1.1 , FreeBSd 11.2 and spamassassin-3.4.2_2

2018-12-01 Thread Matus UHLAR - fantomas
byte long. Can you check the size of /tmp/1847701.tar.gz when that happens? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Microsoft dick is

Re: spoofing mail

2018-12-01 Thread Matus UHLAR - fantomas
El vie., 30 nov. 2018 a las 3:06, Matus UHLAR - fantomas () escribió: And, yes, there could be rule that catches message-id added by internal server. Note that: - Message-ID is not required (has SHOULD in RFC) - many mailservers add message-id if it doesn't exist. >> https://p

Re: spoofing mail

2018-12-01 Thread Matus UHLAR - fantomas
that mail." I am of course aware of such policies, but they differ site to a site, admin to an admin and company to a company. The fact that you refuse some kind of e-mail does not mean that others should be doing the same. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas

<    1   2   3   4   5   6   7   8   9   10   >