Re: ALL_TRUSTED always shown in X-Spam-Status header

2018-11-11 Thread Matus UHLAR - fantomas
to check amavis settings. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. One OS to rule them all, One OS to find them, One OS to bring

Re: ALL_TRUSTED always shown in X-Spam-Status header

2018-11-11 Thread Matus UHLAR - fantomas
ave also commented you need to investigate the patch, have you already? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I don't have lysde

Re: ALL_TRUSTED always shown in X-Spam-Status header

2018-11-11 Thread Matus UHLAR - fantomas
. With complete headers. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. BSE = Mad Cow Desease ... BSA = Mad Software Producents Desease

Re: Bayes underperforming, HTML entities?

2018-11-09 Thread Matus UHLAR - fantomas
On Nov 8, 2018, at 2:30 AM, Matus UHLAR - fantomas wrote: Do you use autolearn? There are a few rules to detect ham (score negatively), many of them based on default whitelists and DNS whitelists, where many mails come from grey area companies, not necessarily spam, but training their mail

Re: Bayes underperforming, HTML entities?

2018-11-08 Thread Matus UHLAR - fantomas
non-token data: last expiry atime 0.000 05529600 0 non-token data: last expire atime delta 0.000 0 1173 0 non-token data: last expire reduction count -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive

Re: config files in spamasassin is unintended tlds :/

2018-11-04 Thread Matus UHLAR - fantomas
is treating those as URLs. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Atheism is a non-prophet organization.

Re: Version 3.4.2, Debian Stretch

2018-10-26 Thread Matus UHLAR - fantomas
prepared to do builds for yourself always. Simply do NOT do this, not on debian. If you really want built, download source package from sid and try building on stretch/jessie. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: Cannot install SpamAssassin on Ubuntu 18.04.1 (gpg not found?)

2018-10-25 Thread Matus UHLAR - fantomas
On Thu, 25 Oct 2018 16:07:02 +0200 Matus UHLAR - fantomas wrote: >On Thu, 25 Oct 2018 08:37:45 -0400 Alexander Lieflander wrote: >> As a side-note, it seems like the error message returned by dpkg >> (and thus SpamAssassin, I guess) is incorrect. Where it mentions >> “s

Re: Cannot install SpamAssassin on Ubuntu 18.04.1 (gpg not found?)

2018-10-25 Thread Matus UHLAR - fantomas
assin (and sa-update) should be installed and configured. well, I checked on debian 8 and debian 9, not on ubuntu 18.04 -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVA

Re: Extreme scores from FRNAME rules.

2018-10-25 Thread Matus UHLAR - fantomas
On 25/10/2018 11:43, Matus UHLAR - fantomas wrote: On 25/10/2018 10:33, Matus UHLAR - fantomas wrote: bug number would help more... On 25.10.18 10:58, Reio Remma wrote: The bug contains no additional info. :) I was simply asked to post to the list. and this is exactly why it would

Re: Extreme scores from FRNAME rules.

2018-10-25 Thread Matus UHLAR - fantomas
to the attachment... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Linux - It's now safe to turn on your computer. Linux - Teraz mozete pocitac bez

Re: Extreme scores from FRNAME rules.

2018-10-25 Thread Matus UHLAR - fantomas
... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Posli tento mail 100 svojim znamim - nech vidia aky si idiot Send this email to 100 your friends

Re: Error 74 with spamc

2018-10-23 Thread Matus UHLAR - fantomas
re, admins are advised to copy them to /etc and make modifications there, instead of modifying files that get overwritten at upgrade (debian checks for config file changes, but init files aren't apparently config files). -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warni

Re: Is fuzzyocr i.e. Image scanning

2018-10-17 Thread Matus UHLAR - fantomas
On 16.10.18 18:42, RW wrote: Bayes might work, but I wouldn't like to see it added to body text because corrupted text could look like obfuscation. On Wed, 17 Oct 2018, Matus UHLAR - fantomas wrote: it should be pushed back to body text just for filters like bayes. The same could/should

Re: Is fuzzyocr i.e. Image scanning

2018-10-17 Thread Matus UHLAR - fantomas
fuscation. it should be pushed back to body text just for filters like bayes. The same could/should be done for attachhed .doc, .pdf files etc. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tu

Re: Is fuzzyocr i.e. Image scanning

2018-10-16 Thread Matus UHLAR - fantomas
ing with bayes and other rules. As for your question about the place for image scanning, if your MTA has the resources to do so, why not? Because it's better if it's combined with other information. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I w

Re: Bayes

2018-10-16 Thread Matus UHLAR - fantomas
On 15.10.18 21:04, Antony Stone wrote: I thought http://xkcd.org/2059 was appropriate to highlight on this list :) Any volunteers to implement this in SA? ;-) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: RBL

2018-10-11 Thread Matus UHLAR - fantomas
On 10/11/2018 01:35 AM, Matus UHLAR - fantomas wrote: I for example run spamass-milter with -r 10 (rejects score over 10) at one machine, and amavisd-milter with "spam_kill_level_maps=> 10", along with postscreen. This way mail gets refused when listed in DNSBLs, while no

Re: RBL

2018-10-11 Thread Matus UHLAR - fantomas
plain sending mail (SA scanning at MTA level) taked too long. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. M$ Win's are shit, do not use it !

Re: repeated sa-update problems

2018-10-08 Thread Matus UHLAR - fantomas
On 20.09.18 16:05, Matus UHLAR - fantomas wrote: I looked at update times and they are different each day - debian script sleeps random number of seconds (up to one hour) in order to lower the impact at mirror servers. I have removed the "--fail" option from curl and will look at err

Re: FPs on FORGED_MUA_MOZILLA (for my own hand-typed messages from my latest-version Thunderbird)

2018-10-02 Thread Matus UHLAR - fantomas
On 10/2/2018 9:59 AM, Matus UHLAR - fantomas wrote: can you post the headers? or at least the Message-Id? On 02.10.18 11:07, Rob McEwen wrote: Here is the message as THEIR system saw it (with my client's info masked)  - but it looks like their Kerio (or the customer's email client?) might

Re: FPs on FORGED_MUA_MOZILLA (for my own hand-typed messages from my latest-version Thunderbird)

2018-10-02 Thread Matus UHLAR - fantomas
ng on their end, and then they changed the score to .001 - so just please ignore that for the purpose of this discussion. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chc

Re: repeated sa-update problems

2018-09-28 Thread Matus UHLAR - fantomas
: It can wait.  Matus also had the issue hitting my mirror and I know I don't use a CDN. On 20.09.18 16:05, Matus UHLAR - fantomas wrote: I looked at update times and they are different each day - debian script sleeps random number of seconds (up to one hour) in order to lower the impact at mirror

Re: Hints needed for spf rule

2018-09-22 Thread Matus UHLAR - fantomas
JMQ_SPF_ALL SPF set to +all!   score    JMQ_SPF_ALL 0.5 endif remove those ?'s: /^v=spf1 .*\?all/ and /^v=spf1 .*\+all/ -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: repeated sa-update problems

2018-09-20 Thread Matus UHLAR - fantomas
ption from curl and will look at error message if there's any. I'll keep you updated and will fill bugreport if I'm able to find out anything useful. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovani

Re: repeated sa-update problems

2018-09-20 Thread Matus UHLAR - fantomas
On Wed, 5 Sep 2018 10:08:24 +0200 Matus UHLAR - fantomas wrote: I (imho too often) get problems when running sa-update (Debian 8, SA 3.4.0) found at /usr/bin/curl Sep  5 07:38:31.810 [16137] dbg: http: /usr/bin/curl -s -L -O --remote-time -g --max-redirs 2 --connect-timeout 30 --max-time 300

Re: repeated sa-update problems

2018-09-20 Thread Matus UHLAR - fantomas
On Wed, 5 Sep 2018 10:08:24 +0200 Matus UHLAR - fantomas wrote: I (imho too often) get problems when running sa-update (Debian 8, SA 3.4.0) found at /usr/bin/curl Sep 5 07:38:31.810 [16137] dbg: http: /usr/bin/curl -s -L -O --remote-time -g --max-redirs 2 --connect-timeout 30 --max-time 300

Re: Hints needed for spf rule

2018-09-19 Thread Matus UHLAR - fantomas
set to ?all! scoreJMQ_SPF_NEUTRAL_ALL 0.5 endif do you not check for "+all" by a reason? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Posl

Re: Fwd: Spam Tagging Issue - V3.4.1 with Postfix 3.1.0

2018-09-10 Thread Matus UHLAR - fantomas
md.sock --socketowner=spamd --socketgroup=spamd --socketmode=0660" PIDFILE="/var/run/spamd.pid" CRON=1 (comments and newlines removed) ubuntu@mail:~$ cat /etc/default/spamass-milter OPTIONS="-u spamass-milter -i 127.0.0.1 -m -I -- --socket=/var/spool/postfix/spa

Re: __HDR_ORDER_FTSDMCXXXX hitting windows live mail (and outlook express)

2018-09-07 Thread Matus UHLAR - fantomas
om trusting local clients - but since they must be trusted to avoid local blacklist, I see no way to avoid this than change to SA trust path (drop all Received: after this hosts). comments welcome. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-m

repeated sa-update problems

2018-09-05 Thread Matus UHLAR - fantomas
anin=98,lanout=283697 This kind of error happens with different mirrors. Now my questions: - is this possible problem with mirrors? - when do mirrors update? - do mirrors updates propagate atomically? or should I dig into that deeper to find out what happens? -- Matus UHLAR - fantomas, uh...@fantomas.s

Re: __HDR_ORDER_FTSDMCXXXX hitting windows live mail (and outlook express)

2018-09-01 Thread Matus UHLAR - fantomas
On Fri, 31 Aug 2018, Matus UHLAR - fantomas wrote: Note that I list internal clients as trusted, not as internal. Maybe this is the problem. Long time ago I learned to configure dynamic IP addresses (dialups) as trusted, but not as internal. On 31.08.18 12:07, John Hardin wrote: Hrm

Re: __HDR_ORDER_FTSDMCXXXX hitting windows live mail (and outlook express)

2018-09-01 Thread Matus UHLAR - fantomas
, XPRIO_SHORT_SUBJ, ...? Now that you pulled this out... Yes, it would also help on some servers I maintain (where HDR_ORDER_FTSDMCXX* caused troubles). The question I still have is, if this is not in contrast with proposed usage of __ANY_EXTERNAL or !ALL_TRUSTED -- Matus UHLAR - fantomas, uh

Re: __HDR_ORDER_FTSDMCXXXX hitting windows live mail (and outlook express)

2018-08-31 Thread Matus UHLAR - fantomas
On 31 Aug 2018, at 4:53, Matus UHLAR - fantomas wrote: Long time ago I learned to configure dynamic IP addresses (dialups) as trusted, but not as internal. On 31.08.18 09:37, Bill Cole wrote: They probably should be neither. In this case, clients are internal, not dialup, but I still think

Re: __HDR_ORDER_FTSDMCXXXX hitting windows live mail (and outlook express)

2018-08-31 Thread Matus UHLAR - fantomas
On Thu, 30 Aug 2018, Matus UHLAR - fantomas wrote: That further causes hitting HDR_ORDER_FTSDMCXX_DIRECT and HDR_ORDER_FTSDMCXX_NORDNS in cases where client uses the mail client on local network, without SMTP authentication, and without DNS (which may be quite common in some organizations

Re: __HDR_ORDER_FTSDMCXXXX hitting windows live mail (and outlook express)

2018-08-31 Thread Matus UHLAR - fantomas
there's a check for unparsable relays in the perl. __DOS_SINGLE_EXT_RELAY would work in my case (client sending direclty to mailserver). But when considering multiple trusted server (client, trusted and internal MTA, my MTA), it would hit again. I will have to think of this again... -- Mat

Re: __HDR_ORDER_FTSDMCXXXX hitting windows live mail (and outlook express)

2018-08-31 Thread Matus UHLAR - fantomas
the network admins they must to implement it now that I have installed spamassassin, is not acceptable. Tuning DNS is of course possible but it requires some time. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address

Re: __HDR_ORDER_FTSDMCXXXX hitting windows live mail (and outlook express)

2018-08-30 Thread Matus UHLAR - fantomas
production in June 2006. I'm not sure how much weight we can give to an email sent with it. On Thu, Aug 30, 2018 at 9:46 AM, Matus UHLAR - fantomas wrote: note that the issue is exactly the same with Windows Live Mail, which, while unsupported, was available until Jan 2017 (and still seems to be us

Re: __HDR_ORDER_FTSDMCXXXX hitting windows live mail (and outlook express)

2018-08-30 Thread Matus UHLAR - fantomas
focus on ALL_TRUSTED implies to me this is 100% internal mail. Is that correct? internal and/or outgoing. Do you (or anyone other) find problems when using ALL_TRUSTED? On Thu, Aug 30, 2018 at 9:14 AM, Matus UHLAR - fantomas wrote: the __HDR_ORDER_FTSDMC rule catches mail sent from

__HDR_ORDER_FTSDMCXXXX hitting windows live mail (and outlook express)

2018-08-30 Thread Matus UHLAR - fantomas
m to add && !ALL_TRUSTED to HDR_ORDER_FTSDMCXX_DIRECT and HDR_ORDER_FTSDMCXX_NORDNS ? (maybe even HDR_ORDER_FTSDMCXX_001C and HDR_ORDER_FTSDMCXX_BAT, if their score will be more than zero) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-

Re: Bayes overtraining

2018-08-20 Thread Matus UHLAR - fantomas
>On 08/08/2018 15:04, Matus UHLAR - fantomas wrote: >>...of last 40 mail in my spambox, 14 matches MAILING_LIST_MULTI >>...of last 100 mail in spambox, 27 matches MAILING_LIST_MULTI On 09.08.18 08:54, Daniele Duca wrote: >I practically zeroed MAILING_LIST_MULTI the day it ca

Re: Update to Ubuntu 18.04.1 seems to have partially broken SA

2018-08-17 Thread Matus UHLAR - fantomas
1899) line 19. Any suggestions on a fix? Installed info below: apt-cache policy spamassassin unless ubuntu's spamassassin includes vlamav module, this is not a problem of spamassassin but the clamav plugin -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning:

Re: Bayes overtraining

2018-08-09 Thread Matus UHLAR - fantomas
On 08/08/2018 15:04, Matus UHLAR - fantomas wrote: ...of last 40 mail in my spambox, 14 matches MAILING_LIST_MULTI ...of last 100 mail in spambox, 27 matches MAILING_LIST_MULTI On 09.08.18 08:54, Daniele Duca wrote: I practically zeroed MAILING_LIST_MULTI the day it came in the ruleset. I

Re: Bayes overtraining

2018-08-08 Thread Matus UHLAR - fantomas
ention, and reduce writes into the >database. On Thu, 26 Jul 2018 17:36:19 +0200 Matus UHLAR - fantomas wrote: well, I have a bit different experience. On 26.07.18 21:25, RW wrote: I didn't say auto-training itself, is a good idea. I mean, if I set bayes_auto_learn_on_error 1, the sc

Re: Issues with Yahoo/AOL emails and RCVD_NUMERIC_HELO

2018-07-30 Thread Matus UHLAR - fantomas
ompare to another header you have posted. That would indicate bug in header parsing code. Received: from ip70-189-131-151.lv.lv.cox.net (EHLO [192.168.0.105]) ([70.189.131.151]) ... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive

Re: Why is RCVD_IN_BL_SPAMCOP_NET not '-lastexternal'?

2018-07-30 Thread Matus UHLAR - fantomas
IP addresses change hands. Many ISPs > assign IP addresses to customers dynamically, so addresses are > changing all the time." On Sat, 28 Jul 2018 18:12:42 +0200 Matus UHLAR - fantomas wrote: and the point is? A-ha. ou put it in subject: Re: Why is RCVD_IN_BL_SPAMCOP_NET not

Re: Issues with Yahoo/AOL emails and RCVD_NUMERIC_HELO

2018-07-29 Thread Matus UHLAR - fantomas
]|\z)/i # Bug 5878 && $1 !~ /$IP_PRIVATE/) { return 1; } but maybe I read wrong. Which SA version do you have? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: Why is RCVD_IN_BL_SPAMCOP_NET not '-lastexternal'?

2018-07-28 Thread Matus UHLAR - fantomas
addresses. Therefore it's useful to do deep header scanning for spamcop listings. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. We are b

Re: Bayes overtraining

2018-07-26 Thread Matus UHLAR - fantomas
uses score being ignored. Only the "noautolearn" flag should be used for this so at least BAYES_99 and BAYES_00 could be takein into account when learning. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Va

Re: Help with own RBL

2018-07-25 Thread Matus UHLAR - fantomas
ulations are complex" is not an answer to "what calculations". Maybe you could do those calculations offline and push their results to DNS. Maybe you could create rules or SA plugin instead. Do any kind of complex calculations for a DNS request is useless, especially when you use it l

Re: Score from command line is different from the one in the webmail

2018-07-15 Thread Matus UHLAR - fantomas
time. Why do I have different scores and how do I get same score on both configurations ? you can't get the same score when the URI is not in blacklist anymore. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: Question regarding auto-learning

2018-07-04 Thread Matus UHLAR - fantomas
bayes_auto_learn_threshold_spam 12.0 Can this be used before training the database or is it more often used to supplement (on an ongoing basis), a database that has already be trained ? those don't contradict each other. you can use manual and automatic learning both. -- Matus UHLAR - fantomas, uh

Re: Remove SA tagging when learning as ham

2018-06-20 Thread Matus UHLAR - fantomas
g >or doing some additional training, but then the plugin is of limited >relevance. On Tue, 19 Jun 2018 10:41:51 +0200 Matus UHLAR - fantomas wrote: Of course, both autotraining AND the fixing errors are required to work properly. On 19.06.18 22:27, RW wrote: Then you have worst of both world

Re: Remove SA tagging when learning as ham

2018-06-19 Thread Matus UHLAR - fantomas
IMO the plugin is best left to statistical filters like DSPAM. isn't dspam dead? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I intend to live forever - so far so good.

Re: Question regarding trusted_networks

2018-06-17 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas skrev den 2018-06-16 16:37: not external networks. only external mail servers you trust not to forge e-mail headers. They may send spam but are not the spam sources. On 16.06.18 19:06, Benny Pedersen wrote: not correct spamassassin need to know all wan ips your own

Re: Question regarding trusted_networks

2018-06-17 Thread Matus UHLAR - fantomas
On 16.06.18 10:12, David Jones wrote: That is basically the same thing worded a little differently. If you have an internal mail relay and your SA server has a private IP on it, then that will be an RFC 1918 IP or range in your internal_networks. Matus UHLAR - fantomas skrev den 2018-06-16

Re: MISSING_SUBJECT

2018-06-17 Thread Matus UHLAR - fantomas
MESSAGE and MISSING_SUBJECT which is the real problem here. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Fighting for peace is like fucking for virginity...

Re: Question regarding trusted_networks

2018-06-16 Thread Matus UHLAR - fantomas
09:37 AM, Matus UHLAR - fantomas wrote: no. only servers that deliver mail to you, as your MX servers or other mailservers directly within your organization should be in internal_networks. On 16.06.18 10:12, David Jones wrote: That is basically the same thing worded a little differently

Re: Question regarding trusted_networks

2018-06-16 Thread Matus UHLAR - fantomas
mail filtering. This will tell SA to go back one more Received: header to test for "last_external" checks and RBL checks. not external networks. only external mail servers you trust not to forge e-mail headers. They may send spam but are not the spam sources. -- Matus UHLAR - fa

Re: MISSING_SUBJECT

2018-06-16 Thread Matus UHLAR - fantomas
On 15.06.18 09:04, Matus UHLAR - fantomas wrote: On Tue, 12 Jun 2018, micah anderson wrote: I had a message marked with: 2.3 EMPTY_MESSAGE Message appears to have no textual parts and no Subject: It did not have a subject, but it did have content (although only encrypted) John Hardin

Re: A question about DCC and learning.

2018-06-15 Thread Matus UHLAR - fantomas
On 15.06.18 16:24, Reio Remma wrote: I'm curious, if I turn on DCC learning, does it learn with both the learn and report options to sa-learn or only report? sa-learn only trains bayes. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e

Re: MISSING_SUBJECT

2018-06-15 Thread Matus UHLAR - fantomas
message part to be a text body part. What was the MIME type of that part? On 14.06.18 12:17, micah anderson wrote: pgp/mime and wat is an attachment or just the e-mail came with mime type pgp/mime;2~? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: MISSING_SUBJECT

2018-06-13 Thread Matus UHLAR - fantomas
did not have one, but have you looked in your Spam folder lately? All spam has a subject, pretty much always an informal survey of my trash heap showed 4 messages out of 400 did not have a Subject, and two of them were repeats. Matus UHLAR - fantomas writes: and what is your point

Re: MISSING_SUBJECT

2018-06-13 Thread Matus UHLAR - fantomas
hitting MISSING_SUBJECT is ham. if the percentage is very different in there two cases, the rule gets high positive (or negative) score. Some scores are tuned for safety reasons. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: SPF_HELO_FAIL triggers on domain with valid SPF record and HELO settings

2018-06-11 Thread Matus UHLAR - fantomas
l.sinclair-accounting.co.uk: result: fail, comment: Please see http://www.openspf.org/Why?s=helo;id=mail.sinclair-accounting.co.uk;ip=80.229.84.190;r=obelisk.open-t.lan, text: Mechanism '-all' matched -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to rece

Re: More outlook phish

2018-06-11 Thread Matus UHLAR - fantomas
On 06/10/2018 12:02 PM, Matus UHLAR - fantomas wrote: I believe M$ requires users to be authenticated within the domain before they are allowed to send using your domain. On 10.06.18 16:55, Grant Taylor wrote: Is that authenticating to the MS SMTP server with any recognized account

Re: More outlook phish

2018-06-10 Thread Matus UHLAR - fantomas
ands of IP addresses that could conceivably be used to spoof any other domain that's "hosted" using one of those IPs? I believe M$ requires users to be authenticated within the domain before they are allowed to send using your domain. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; ht

Re: Problem with sa-update via proxy

2018-06-05 Thread Matus UHLAR - fantomas
as well. do you run manually /etc/cron.daily/spamassassin or sa-update? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "Two words: Wi

Re: List From and Reply-To

2018-06-01 Thread Matus UHLAR - fantomas
don't like doing it this way -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Eagles may soar, but weasels don't get sucked into jet engines.

Re: Garbage string emails

2018-05-31 Thread Matus UHLAR - fantomas
be common (for the mail I have seen) - one line, 5 words, 7 characters each seems to be common too. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklam

Re: [Offtopic] List From and Reply-To

2018-05-30 Thread Matus UHLAR - fantomas
eaders that may change on the way (e.g. Received:) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. 42.7 percent of all statistics are m

Re: rewrite_header Subject and Bayes

2018-05-30 Thread Matus UHLAR - fantomas
On 30.05.18 15:12, Palvelin Postmaster wrote: I prepend my spam emails’ subject fields with a specific string to indicate spam, like many do, I presume. Will that string get noticed by bayes and if so, should I do something to prevent it? On 30 May 2018, at 15:21, Matus UHLAR - fantomas

Re: rewrite_header Subject and Bayes

2018-05-30 Thread Matus UHLAR - fantomas
, unless you check for spamminess, tag and check again... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Save the whales. Collect the whole set.

spamcannibal DNSBL issue

2018-05-30 Thread Matus UHLAR - fantomas
IN A 91.195.240.117 not mentioning where does its web page redirect... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Windows 2000: 640 MB ought

Re: training bayes database

2018-05-10 Thread Matus UHLAR - fantomas
) on the mail server? The requirement is not for caching server - it's for recursing server dnsmasq is forwarding server, get rid of if when possible. It's even documented: https://wiki.apache.org/spamassassin/CachingNameserver -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk

Re: training bayes database

2018-05-10 Thread Matus UHLAR - fantomas
127.0.0.1 i cannot believe that is not the default.  i always assumed my dns was working correctly. It's not default to have DNS server on your system. And it's not default to have localhost in resolv.conf - it may be authoritative-only. -- Matus UHLAR - fantomas, uh...@fantomas

Re: rejection w/o sender (or recipient) knowing == dropping

2018-04-30 Thread Matus UHLAR - fantomas
ot sending or droping bounce is what's wrong and it happens on senders side. Matus UHLAR - fantomas wrote: STOP calling rejection a dropping. Rejecting is NOT dropping. They are two different things. If you try to hand me an envelope, and I will refuse to take it, It is NOT the same as if I took it a

Re: dropping other's email(s) as a "best practice" for hosted email?

2018-04-27 Thread Matus UHLAR - fantomas
. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. 2B|!2B, that's a question!

Re: dropping other's email(s) as a "best practice" for hosted email? (was: "anyone recognize these headers? ...")

2018-04-27 Thread Matus UHLAR - fantomas
y how mail system works (and always worked), just because you have misunderstood (or assumed) it. I didn't realize email was no longer considered unreliable afaik e-mail was NEVER considered reliable, mostly because of reasons mentioned above. -- Matus UHLAR - fantomas, uh...@fantomas

Re: Anti Phish Rules

2018-04-27 Thread Matus UHLAR - fantomas
" tag to see if there is a URL there, and if they do not match, consider it a phis so apply said phis score to the message. Has anyone done this? module even? On 26/04/2018 18:12, Matus UHLAR - fantomas wrote: the main problem: may non-spam senders do that, see: https://wiki.apache.org/sp

Re: Anti Phish Rules

2018-04-26 Thread Matus UHLAR - fantomas
discussion in linked bug: https://bz.apache.org/SpamAssassin/show_bug.cgi?id=4255 -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Micro$oft ran

Re: Why emails relayedfrom trusted/internal networks trigger rules?

2018-04-26 Thread Matus UHLAR - fantomas
(EEST)⁩ -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. 10 GOTO 10 : REM (C) Bill Gates 1998, All Rights Reserved!

Re: Spamassassin and spamc do not use same rules

2018-04-25 Thread Matus UHLAR - fantomas
quot;allow_user_rules" is enabled, which may be the error I don't advise per-user rules, I would better advise configure rules globally but enable/disable them only for some users, which can be done in user_prefs. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warnin

Re: Spamassassin and spamc do not use same rules

2018-04-25 Thread Matus UHLAR - fantomas
sin. That way, different users' settings are used. check how does your spamd run (which user, if any) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu po

Re: anyone recognize these headers? From SA or are they from another spam product?

2018-04-25 Thread Matus UHLAR - fantomas
and considered best practice by many. It also puts handling the spam/virus erorrs on their senders, not recipients, which is a good thing imho. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: Can't locate Mail/SpamAssassin/Plugin/SpamCop.pm: lib/Mail/SpamAssassin/Plugin/SpamCop.pm: Permission denied

2018-04-20 Thread Matus UHLAR - fantomas
quot; and you'll see the problem is back. I think this problem started appearing few years ago when perl started throwing error when it could not search @INC because of permissions. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail adverti

Re: Can't locate Mail/SpamAssassin/Plugin/SpamCop.pm: lib/Mail/SpamAssassin/Plugin/SpamCop.pm: Permission denied

2018-04-19 Thread Matus UHLAR - fantomas
tory was not readable by the user running spamassassin checks. if by any chance you have lib/ or lib/Mail/ etc. in current directory that is not readable by current user, this can happen. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e

Re: Differing scores on spamassassin checks

2018-04-17 Thread Matus UHLAR - fantomas
On 15.04.18 20:04, RW wrote: >All setting bayes_path buys you here is the ability to run sa-learn >and spamassassin as root, something you should *never* do anyway. On Tue, 17 Apr 2018 13:55:13 +0200 Matus UHLAR - fantomas wrote: it's the only way to use per-user settings and ba

Re: Differing scores on spamassassin checks

2018-04-17 Thread Matus UHLAR - fantomas
sin and sa-learn should be done under spamd user. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I drive way too fast to worry about cholesterol.

Re: Differing scores on spamassassin checks

2018-04-15 Thread Matus UHLAR - fantomas
On 15.04.18 11:55, Computer Bob wrote: Here is a root scan:  https://pastebin.com/qdXMRzKb On Sun, 15 Apr 2018, Matus UHLAR - fantomas wrote: X-Spam-Status: Yes, score=10.2 required=4.0 tests=HTML_MESSAGE, RAZOR2_CF_RANGE_51_100,RAZOR2_CHECK,RCVD_IN_SBL_CSS,SPF_HELO_PASS

Re: Differing scores on spamassassin checks

2018-04-15 Thread Matus UHLAR - fantomas
he difference ? * * -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Atheism is a non-prophet organization.

Re: SPF_NONE rule for spamassassin

2018-04-12 Thread Matus UHLAR - fantomas
::Plugin::SPF in /etc/spamassassin/init.pre and maybe install perl mofule for mail-spf (no idea what's its name in redhat) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: low score on very spammy email

2018-04-11 Thread Matus UHLAR - fantomas
accept that a FP appears. otherwise, there would be no spam and no discussion here :-) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. &quo

Re: bayes: cannot open bayes databases lock failed: File exists

2018-04-10 Thread Matus UHLAR - fantomas
if you are running amavis, you need to check ~amavis/.spamassassin/ directory, not /.spamassassin. if you are running spamd unser one user, does the user homedir set to / ? otherwise, it can be a result of no mail trained, since you have bayes_auto_learn set to 0 -- Matus UHLAR - fantomas, uh

Re: bayes: cannot open bayes databases lock failed: File exists

2018-04-09 Thread Matus UHLAR - fantomas
h load, yes. if you use per-site bayes database, you can try redis - even faster than mysql. Much much much faster -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDO

Re: bayes: cannot open bayes databases lock failed: File exists

2018-04-06 Thread Matus UHLAR - fantomas
emails are analyzed per hour. under such load, yes. if you use per-site bayes database, you can try redis - even faster than mysql. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: how to remove T_RP_MATCHES_RCVD

2018-04-06 Thread Matus UHLAR - fantomas
, since I have already disabled this on some of systems we maintain in our company. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "Th

Re: This sucks

2018-04-02 Thread Matus UHLAR - fantomas
spamc+spamd does not. how do you run spamd? apparently when checking through spamd, different user preferences are used. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: BODY custom rule not working if text and html parts are different?

2018-04-01 Thread Matus UHLAR - fantomas
does not. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Microsoft dick is soft to do no harm

Re: FSL_BULK_SIG tweak?

2018-03-13 Thread Matus UHLAR - fantomas
ive. Afaik this is often a sign of spam, not ham. iirc such unsubscribe link was already reported as email address verifier, resulting into more spam being sent to such address. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail a

<    2   3   4   5   6   7   8   9   10   11   >