Re: RP_MATCHES_RCVD

2016-05-11 Thread Matus UHLAR - fantomas
RH> RP_MATCHES_RCVD removed 1.7 points On 11.05.16 16:29, Reindl Harald wrote: which proves again how badly auto-qa works and why you need to adjust some rules up to remove them eniterily with a zero score Am 11.05.2016 um 16:34 schrieb Matus UHLAR - fantomas: afaik, auto-qa scores _a

Re: RP_MATCHES_RCVD

2016-05-11 Thread Matus UHLAR - fantomas
s spam ... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Micro$oft random number generator: 0, 0, 0, 4.33e+67, 0, 0, 0...

Re: DCC doesn't seem to be doing anything

2016-04-30 Thread Matus UHLAR - fantomas
he log line. you can simply stop running dccifd daemon. But I recommend configure it in SA and run it. Not because of the logs, but I assume it's more effcient -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Var

Re: DCC doesn't seem to be doing anything

2016-04-29 Thread Matus UHLAR - fantomas
28, 2016, at 2:34 AM, Matus UHLAR - fantomas <uh...@fantomas.sk> wrote: do you see any DCC_CHECK in spam headers? On 28.04.16 11:58, @lbutlr wrote: A few, but they always seem to be “1.1” and they occur in about a third of the messages in the Spam folder, but the daily report into maillog

Re: DCC doesn't seem to be doing anything

2016-04-28 Thread Matus UHLAR - fantomas
appears every day at midnight. It it matters, SA is being called by amavis. do you see any DCC_CHECK in spam headers? do you have dcc_home set up in SA configuration? If SA does not find dccifd socket, it uses dccproc interface. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk

Re: DNS to mirror failed when running sa-update

2016-04-07 Thread Matus UHLAR - fantomas
ses, this is one of them. "dig any mirrors.updates.spamassassin.org. @b.auth-ns.sonic.net." produces OK output. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVA

Re: Configuration Help Request: Spoofed Email Being Whitelisted

2016-03-31 Thread Matus UHLAR - fantomas
On 30 Mar 2016, at 9:48, Matus UHLAR - fantomas wrote: On 30.03.16 06:18, redtailjason wrote: [] The headers you have posted show mail that only goes through internal IPs and localhost, that mail doesn't seem to come from outside. On 31.03.16 09:23, Bill Cole wrote: I believe

Re: Configuration Help Request: Spoofed Email Being Whitelisted

2016-03-30 Thread Matus UHLAR - fantomas
- View this message in context: http://spamassassin.1065346.n5.nabble.com/Configuration-Help-Request-Spoofed-Email-Being-Whitelisted-tp120328.html Sent from the SpamAssassin - Users mailing list archive at Nabble.com. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I

Re: def_whitelist_auth inconsistencies

2016-03-23 Thread Matus UHLAR - fantomas
config at once: whitelist_from_dkim *@*.bbcmail.co.uk def_whitelist_auth *@*.bbcmail.co.uk and run the mail through spamassassin -D -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: def_whitelist_auth inconsistencies

2016-03-23 Thread Matus UHLAR - fantomas
. check for this carefully... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. BSE = Mad Cow Desease ... BSA = Mad Software Producents Desease

Re: HEADER_HOST_IN_BLACKLIST

2016-03-13 Thread Matus UHLAR - fantomas
ME/.spamassassin/ would provide the same result, however - check for _uri_host would find enlist_uri_host and blacklist_uri_host - should check all HOME directories. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address.

Re: Missed spam, suggestions?

2016-03-08 Thread Matus UHLAR - fantomas
On Mar 8, 2016, at 7:31 AM, Matus UHLAR - fantomas <uh...@fantomas.sk> wrote: how can these two stats be different? On 08.03.16 10:19, @lbutlr wrote: Because one is for SPAM and one is for HAM. On Mar 8, 2016, at 10:41 AM, Matus UHLAR - fantomas <uh...@fantomas.sk> wrote:

Re: Missed spam, suggestions?

2016-03-08 Thread Matus UHLAR - fantomas
On Mar 8, 2016, at 7:31 AM, Matus UHLAR - fantomas <uh...@fantomas.sk> wrote: how can these two stats be different? On 08.03.16 10:19, @lbutlr wrote: Because one is for SPAM and one is for HAM. Why did you remove the important part? TOP SPAM RULES FIRED RANKRUL

Re: Missed spam, suggestions?

2016-03-08 Thread Matus UHLAR - fantomas
%OFRULES %OFMAIL %OFSPAM %OFHAM 1 HTML_MESSAGE16473 9.13 50.51 87.85 90.80 how can these two stats be different? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address

Re: RCVD_NUMERIC_HELO

2016-03-05 Thread Matus UHLAR - fantomas
Am 04.03.2016 um 09:29 schrieb Matus UHLAR - fantomas: I why are you complaining (again), when you can simply zero the score, when you have no problem highly tuning other scores. On 04.03.16 10:40, Reindl Harald wrote: because this thread was about *another* deep header test and wrong

Re: RCVD_NUMERIC_HELO

2016-03-04 Thread Matus UHLAR - fantomas
out other common characteristics of messages hitting those scores and post results here so we see what to exclude. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: RCVD_NUMERIC_HELO

2016-03-04 Thread Matus UHLAR - fantomas
On 03.03.16 16:54, RW wrote: >RCVD_NUMERIC_HELO is an independent deep check and overlaps heavily >with either FSL_* rule. On Thu, 3 Mar 2016 17:59:33 +0100 Matus UHLAR - fantomas wrote: I wouldn't say so, at least on my system. % zcat /var/log/mail*.gz | cat - /var/log/mail /var/log/

Re: RCVD_NUMERIC_HELO

2016-03-03 Thread Matus UHLAR - fantomas
, at least on my system. % zcat /var/log/mail*.gz | cat - /var/log/mail /var/log/mail.1 | grep RCVD_NUMERIC_HELO | grep -c FSL_HELO_BARE_IP 5 % zcat /var/log/mail*.gz | cat - /var/log/mail /var/log/mail.1 | grep RCVD_NUMERIC_HELO | grep -vc FSL_HELO_BARE_IP 36 -- Matus UHLAR - fantomas, uh...@fant

Re: dcc checks

2016-03-03 Thread Matus UHLAR - fantomas
On 02.03.16 12:48, Roman Gelfand wrote: >I have awl disabled and dcc checks configured. Why, sometimes, >spamassassin doesn't do dcc checks? On Wed, Mar 2, 2016 at 2:50 PM Matus UHLAR - fantomas <uh...@fantomas.sk> wrote: that has nothing to do with AWL. You have already aske

Re: dcc checks

2016-03-02 Thread Matus UHLAR - fantomas
it here? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Enter any 12-digit prime number to continue.

Re: CHARSET_FARAWAY and other charsets

2016-03-02 Thread Matus UHLAR - fantomas
;. quite probably, but it highly depends on how you filter the spam. For example, using spamassassin/spamc from spamass-milter or per-user procmail/maildrop filters, the SA can use users' ~/.spamassassin/user_prefs where the directives are configured. So, how do you call spamassassin? -- Matus

Re: regex help

2016-02-22 Thread Matus UHLAR - fantomas
, according to http://regexstorm.net/tester that below seems to work in the meantime Postfix: 127.0.4.[0..20] SA: ^127\.0\.4\.(0?[0-1]?[0-9]|20)$ (1?[0-9]|20) should be enough, I think check_rbl doesn't keep leading zeroes -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk

Re: Google Drive/Docs spam

2016-02-18 Thread Matus UHLAR - fantomas
UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. If Barbie is so popular, why do you have to buy her friends?

Re: Allow User Rules problem

2016-02-18 Thread Matus UHLAR - fantomas
t must be configured to use them. I have never heard of this software, and I don't know if it suppports multiuser setup at all. I for example use spamass-milter that does, and on some servers amavis and MailScanner that do not... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas

Re: Allow User Rules problem

2016-02-17 Thread Matus UHLAR - fantomas
You do NOT need "allow_user_rules 1" to use "blacklist_from" and you should not allow user rules by "allow_user_rules 1" -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie:

Re: how to fix this issue-spam

2016-02-05 Thread Matus UHLAR - fantomas
, related to charater set conversion that may be ligitimately done by servers. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Linux - It's now

Re: FSL_HELO_BARE_IP_2 fires on wrong header

2016-01-25 Thread Matus UHLAR - fantomas
l 130 cat maillog | grep FSL_HELO_BARE_IP_2 | grep BAYES_00 | wc -l 93 excuse me, did you get a FP? Together with BAYES_00? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: problem integrating spamassasin into postfix

2016-01-12 Thread Matus UHLAR - fantomas
A1695FF9: to=<catalin.badi...@domain.com <mailto:catalin.badi...@domain.com>>, relay=spamfilter, delay=3908, delays=3907/0.04/0/0.47, dsn=4.3.0, status=deferred (temporary failure. Command output: pipe: fatal: pipe_command: execvp /home/spamd/spamfilter.sh: No such file or directory )

Re: Customized header (add_header) doesn't work

2015-12-17 Thread Matus UHLAR - fantomas
-in. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I don't have lysdexia. The Dog wouldn't allow that.

Re: SPF rules and my domain

2015-12-11 Thread Matus UHLAR - fantomas
fails SPF? http://pastebin.com/36hzGcTs On 11.12.15 08:56, Matus UHLAR - fantomas wrote: the envelope sender seems to be bounce-15_html-74319930-51788793-10834732...@bounce.e.tripadvisor.com bounce.e.tripadvisor.com seems to have no SPF record, so I also don't understand why SPF tests should

Re: SPF rules and my domain

2015-12-10 Thread Matus UHLAR - fantomas
your MTA should not be refused. However they should use SMTP Authentication and that should be prevented from SPF checks. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDO

Re: SPF rules and my domain

2015-12-10 Thread Matus UHLAR - fantomas
y a server > > > > > > > > > that is not in my SPF record. On Thu, 10 Dec 2015, Matus UHLAR - fantomas wrote: The SPF fail SHOULD be triggered in that case. On Thu, Dec 10, 2015 at 10:28 AM, John Hardin <jhar...@impsec.org> wrote: Matus, I think you misrea

Re: question re/ RDNS_NONE

2015-11-24 Thread Matus UHLAR - fantomas
- to limit the number of outgoing DNS requests and focus on that haven't been done before. That's why SA uses existing headers like Received: and Received-SPF: -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Var

Re: ClamAV.pm Plugin Not Working

2015-11-23 Thread Matus UHLAR - fantomas
. maybe group permissions could be enough: putting spamd to group that has read permissions on the directory... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: question re/ RDNS_NONE

2015-11-23 Thread Matus UHLAR - fantomas
mta setup that is fetched with fetchmail I would put that one even in the internal_networks, so SA can check hosts the ISP received mail from... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie

Re: Spamassassin SPF plugin headers

2015-11-19 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas skrev den 2015-11-19 10:36: in any case, spamass-milter will prepend Received: header before all other headers, including Received-SPF added by your policy service, which means SA won't trust it... On 19.11.15 11:02, Benny Pedersen wrote: using spampd here since

Re: Spamassassin SPF plugin headers

2015-11-19 Thread Matus UHLAR - fantomas
On 11/19/2015 10:59, Matus UHLAR - fantomas wrote: From what I know, the locally added Received: header is not visible in milter and the spamass-milter must fake it. Therefore, if Received-SPF exists, the Received: is prepended before it, which explains the issue. On 19.11.15 11:15, Elod G

Re: Spamassassin SPF plugin headers

2015-11-19 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas skrev den 2015-11-19 09:59: From what I know, the locally added Received: header is not visible in milter and the spamass-milter must fake it. Therefore, if Received-SPF exists, the Received: is prepended before it, which explains the issue. On 19.11.15 10:13, Benny

Re: Spamassassin SPF plugin headers

2015-11-19 Thread Matus UHLAR - fantomas
is not visible in milter and the spamass-milter must fake it. Therefore, if Received-SPF exists, the Received: is prepended before it, which explains the issue. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address

Re: Trouble with SPF plugin

2015-11-19 Thread Matus UHLAR - fantomas
e 0) for some reason, just you have turned it on :-) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Your mouse has moved. Windows NT will now

Re: ClamAV.pm Plugin Not Working

2015-11-19 Thread Matus UHLAR - fantomas
made clamscan/clamscan the owner. -rwxrwxrwx. 1 clamscan clamscan 69 Nov 19 05:09 eicar.txt [root@ tmp]# clamdscan -c /etc/clamd.d/scan.conf /tmp/eicar.txt /tmp/eicar.txt: lstat() failed: No such file or directory. ERROR does clamd run? Doesn't it run chrooted? -- Matus UHLAR - fantomas, uh

Re: Spamassassin SPF plugin headers

2015-11-19 Thread Matus UHLAR - fantomas
On 19.11.15 14:29, Elod G wrote: So I understand the milter protocol requires the own local received header to not be present, and Postfix hides it from milters Am 19.11.2015 um 14:01 schrieb Matus UHLAR - fantomas: the milter protocol requires mail to be passed as received - without locally

Re: Spamassassin SPF plugin headers

2015-11-19 Thread Matus UHLAR - fantomas
else, to all other data must be passed through pseudo-headers. Which makes it quite hard when you need locally added Received: header after data received from other milter. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: Debian jessie - new setup, missing data directory

2015-11-09 Thread Matus UHLAR - fantomas
pam filter your mail. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Linux - It's now safe to turn on your computer. Linux - Teraz mozete p

Re: How to get rid of this spam? Spam assassin does not catch it

2015-10-28 Thread Matus UHLAR - fantomas
server for SpamAssassin to use. You're apparently doing DNS blacklist queries via a public DNS server (your ISPs?) and the aggregate traffic level is exceeding the URIBL free usage limits. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: Spamassassin and amavisd-new wont' check (faked) bounce with zip-archive/exe (maleware)

2015-10-27 Thread Matus UHLAR - fantomas
, why our AMaVis's allowed those faked bounce-messages with mailware. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Spam = (S)tupid (P

Re: spf records and cnames

2015-10-27 Thread Matus UHLAR - fantomas
10.2015 um 13:55 schrieb Matus UHLAR - fantomas: I don't get this. HELO must be canonical name, so it must not be CNAME. Thus, there's no need to follow CNAMEs in SPF when checking for HELO. when you check HELO, the CNAME should be treated as error On 22.10.15 13:58, Reindl Harald wrote:

Re: spf records and cnames

2015-10-22 Thread Matus UHLAR - fantomas
result with no holes to abuse -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. He who laughs last thinks slowest.

Re: Learning only on read emails?

2015-10-20 Thread Matus UHLAR - fantomas
things their way just because they are huge companies and don't care about (even backwards) compatibility and correctness Speaking of learning spam… your email address will be joining the blacklist very soon. just be careful when blacklisting and spam-training... -- Matus UHLAR - fantom

Re: spamass-milter and virtual config dir

2015-10-18 Thread Matus UHLAR - fantomas
d sendmail macro "{i}". sendmail macrop $i means the queue id. But how does the message look like? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek rekl

Re: SPF code change?

2015-10-17 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas skrev den 2015-10-16 17:17: the SPF wasn't reported to fail on own domains. it was reported for foreign domains like facebookmail, when coming through secondary MXes, which is clearly problem of SA configuration... On 16.10.15 17:51, Benny Pedersen wrote: in that case

Re: SPF code change?

2015-10-16 Thread Matus UHLAR - fantomas
). This is exactly what internal_networks is for... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I just got lost in thought

Re: SPF code change?

2015-10-16 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas skrev den 2015-10-16 14:43: the MX servers for your domain MUST be listed in internal_network (and in trusted_network too). This is exactly what internal_networks is for... On 16.10.15 14:58, Benny Pedersen wrote: just that is not completely true if spf fails on own

Re: Training Bayes with BAYES_999 Mail

2015-10-02 Thread Matus UHLAR - fantomas
already detect? Should I only be training it with miscategorized emails and emails in the 20-80% confidence range? imho, the more uncertain BAYES score is, the more it's usefull to train. something hitting BAYES_999 is not worth imho. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http

Re: SPAM from our own domain

2015-10-01 Thread Matus UHLAR - fantomas
ago... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. 10 GOTO 10 : REM (C) Bill Gates 1998, All Rights Reserved!

Re: SPAM from our own domain

2015-09-28 Thread Matus UHLAR - fantomas
:Wed, 23 Sep 2015 11:28:46 GMT To:helen.papp...@motec.com.au From:"Incoming Fax" <incoming@motec.com.au> -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: URIBL_BLOCKED while using local BIND

2015-09-18 Thread Matus UHLAR - fantomas
On 16.09.15 09:50, Bowie Bailey wrote: The SA config is probably a better solution than the bind exemptions. I would say just the opposite. For example, MTA at SMTP level can look up RBLs, and SA would benefit from having records in local cache. -- Matus UHLAR - fantomas, uh...@fantomas.sk

Re: Live upgrade safe?

2015-09-14 Thread Matus UHLAR - fantomas
Am 12.09.2015 um 19:15 schrieb Matus UHLAR - fantomas: funny, at least debian SA package does download updates at install time... you obviously have no experience with distributions... On 12.09.15 19:18, Reindl Harald wrote: can we stop that stupid discussion? I just wanted to point out

Re: Live upgrade safe?

2015-09-14 Thread Matus UHLAR - fantomas
On 12.09.15 15:27, Reindl Harald wrote: and no, i am not the package maintainer but the first person who would file a bug for *any* package which rely on a internet connection due update Am 14.09.2015 um 17:25 schrieb Matus UHLAR - fantomas: in such case it's up to the distributions

Re: Live upgrade safe?

2015-09-12 Thread Matus UHLAR - fantomas
Am 12.09.2015 um 16:08 schrieb Matus UHLAR - fantomas: did this really happen? On 12.09.15 16:13, Reindl Harald wrote: what did really happen? RPM packages are not supposed to contact network *3rd party* ressources at install time and when you think 1 second you know why - who tells you

Re: Live upgrade safe?

2015-09-12 Thread Matus UHLAR - fantomas
Am 11.09.2015 um 21:08 schrieb Matus UHLAR - fantomas: if your distribution restarts spamassassin, it will most probably download the rules before. Not everyone uses distributions... On 12.09.15 04:20, Reindl Harald wrote: no, the service restarts are usually rpm-macros in the %post section

Re: Live upgrade safe?

2015-09-12 Thread Matus UHLAR - fantomas
Am 11.09.2015 um 21:08 schrieb Matus UHLAR - fantomas: if your distribution restarts spamassassin, it will most probably download the rules before. Not everyone uses distributions... On 12.09.15 04:20, Reindl Harald wrote: no, the service restarts are usually rpm-macros in the %post section

Re: Live upgrade safe?

2015-09-11 Thread Matus UHLAR - fantomas
upgrade but before the restart? if your distribution restarts spamassassin, it will most probably download the rules before. Not everyone uses distributions... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address.

Re: Fwd: Large volume of 0.0 scores suddenly

2015-09-11 Thread Matus UHLAR - fantomas
spamassassin see the whole e-mails, including all headers? the NO_RELAYS test looks like you are not pushing the whole mails to SA, which significantly decreases score. Also, do you have way to train your spamassassin with spam? Since all spams have BAYES_00, you should train them... -- Matus UHLAR

Re: SA doesn't respect my user_prefs

2015-09-11 Thread Matus UHLAR - fantomas
Am 09.09.2015 um 15:01 schrieb Matus UHLAR - fantomas: how do you plug spamassassin into your mail flow? How do you call spamassassin? mta, mail client ... ? On 09.09.15 16:11, Marc Richter wrote: I'm running postfix as my MTA. In it's master.cf there is configured to pipe my mail through

Re: SA doesn't respect my user_prefs

2015-09-09 Thread Matus UHLAR - fantomas
user_prefs -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Boost your system's speed by 500% - DEL C:\WINDOWS\*.*

Re: SA gone mad

2015-09-09 Thread Matus UHLAR - fantomas
message, or at least all headers and part of the textual body to pastebin? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "Where do you want to go to die?" [Microsoft]

Re: SA gone mad

2015-09-09 Thread Matus UHLAR - fantomas
and network rules should make SA behave much better than banned words rules. Debian 6.0.10 Samassassin 3.3.2-5+deb7u2 perl 5.10.1-17squeeze6 very outdated this is included in debian 6 LTS it should still be better to upgrade to more current versions. -- Matus UHLAR - fantomas, uh...@fantomas.sk

Re: SA doesn't respect my user_prefs

2015-09-09 Thread Matus UHLAR - fantomas
How do you call spamassassin? mta, mail client ... ? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Enter any 12-digit prime number to continue.

Re: Problem with Bayes

2015-09-09 Thread Matus UHLAR - fantomas
stsanding what it may cause. it may work, but also may fsck up spam filtering. I have restarted and will see what happens. I am using the ubuntu exim-daemon heavy and it calls spamd directly. that means how? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I

Re: Problem with Bayes

2015-09-09 Thread Matus UHLAR - fantomas
On 09/09/2015 04:55 PM, Matus UHLAR - fantomas wrote: On 09.09.15 15:21, Ben Whyall wrote: I didnt have that option but I did have bayes_sql_username set I have added the sql_override as well. I don't think you should set such options without understsanding what it may cause. it may work

Re: Resume / Doc Spam

2015-09-09 Thread Matus UHLAR - fantomas
eople will argument against this ;-) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Chernobyl was an Windows 95 beta test site.

Re: Bayes Portal

2015-09-04 Thread Matus UHLAR - fantomas
would it work? Spam is a personal experience. One's spam may be another's ham after all. Right? yes, otoh, there are many cases organizations sharing the same database. is that different on gmail? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish

Re: Bayes Portal

2015-09-04 Thread Matus UHLAR - fantomas
ed address, they are coming via sendmail while the MTA rejects the original That is the glue, not the SA. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu po

Re: Amazon Route53 nameservers listed in SBL?

2015-09-03 Thread Matus UHLAR - fantomas
On 02.09.15 17:49, Reindl Harald wrote: [harry@mail-gw:~]$ cat maillog | grep URIBL_SBL | wc -l 16 wow what about "grep -c URIBL_SBL maillog"? http://porkmail.org/era/unix/award.html -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to

Re: UCE not stopped

2015-08-11 Thread Matus UHLAR - fantomas
system that uses single account for scoring, you must train that account -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. 42.7 percent of all

Re: UCE not stopped

2015-08-11 Thread Matus UHLAR - fantomas
On Tue, 2015-08-11 at 09:06 +0200, Matus UHLAR - fantomas wrote: 2. how do you run SA? If you are using amavis or other system that uses single account for scoring, you must train that account On 11.08.15 10:04, Martin Skjöldebrand wrote: This is the output of ps aux | grep spamd root

Re: Ignore forwarding headers from specific sender

2015-07-31 Thread Matus UHLAR - fantomas
wonder if gmail would start marking mail forwarded through your account as spam... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Silvester

Re: Spamassasin always RDNS_NONE

2015-07-23 Thread Matus UHLAR - fantomas
On 23.07.15 13:47, basti wrote: all my incomming mails get always 1.3 RDNS_NONE also with a vaild PTR. Does your mail server check for reverse DNS? If not, turn it on. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

Re: Bayes Filtering

2015-07-22 Thread Matus UHLAR - fantomas
you don't like! however, for the OP it is another reason not even to score high on BAYES_* -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu

Re: Report spam to Razor

2015-07-22 Thread Matus UHLAR - fantomas
can use a directory: smapassassin -r /home/bob/Maildir/.Spam/ ? No: it explicitly says you can only use with message, you must specify path without the . -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address

Re: Bayes Filtering

2015-07-22 Thread Matus UHLAR - fantomas
is 8.0 - the other rules are there to avoid false-positives and false-negatives for a good reason Am 22.07.2015 um 13:40 schrieb Matus UHLAR - fantomas: So THIS explains, why you blame (us) for every single low-scoring rule for hitting something you don't like! On 22.07.15 14:01, Reindl Harald

Re: SPF confusion

2015-07-16 Thread Matus UHLAR - fantomas
or spf2.0/pra ?all Better not. Don't jump on dead horse. Microsoft SPF/2 is dead, let it die and don't even try to fix things by implementing it, since may break things working properly. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: Return Path (TM) whitelists

2015-07-09 Thread Matus UHLAR - fantomas
with these SA headers and I remember it was hard (if not impossible) to find spam report link on their site. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu

Re: Write a custom rule to match sender's ip address.

2015-07-01 Thread Matus UHLAR - fantomas
-- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Honk if you love peace and quiet.

Re: Rules needed...

2015-06-30 Thread Matus UHLAR - fantomas
. I don't agree with Harald very often, but I find smtp-time scoring safe, if properly set up -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu

Re: Rules needed...

2015-06-28 Thread Matus UHLAR - fantomas
needs the mail). -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. You have the right to remain silent. Anything you say will be misquoted

Re: No BAYES_XX tags in X-Spam-Report

2015-06-23 Thread Matus UHLAR - fantomas
, does it? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I just got lost in thought. It was unfamiliar territory.

Re: Problem with Spamassassin

2015-06-20 Thread Matus UHLAR - fantomas
, SHORT_HELO_AND_INLINE_IMAGE=1.39] autolearn=no this looks like our customer is using your server as mail relay, without using SMTP autehntication. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem

Re: Problem with TxRep's HELO handling

2015-06-18 Thread Matus UHLAR - fantomas
to 'localhost'. It would make more sense if TxRep uses the lastest (first) Received header setting $helo to 'mail-wi0-f175.google.com'. shouldn't that logically be more like lasttrusted header? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e

Re: Must-Have Plugins?

2015-06-15 Thread Matus UHLAR - fantomas
On 10.06.15 04:34, Amir Caspi wrote: To: Matus UHLAR - fantomas uh...@fantomas.sk Cc: users@spamassassin.apache.org pleaase, avoid personal mail. The list is for public discussion. Subject: Re: Must-Have Plugins? On Jun 10, 2015, at 12:32 AM, Matus UHLAR - fantomas uh...@fantomas.sk wrote

Re: Must-Have Plugins?

2015-06-10 Thread Matus UHLAR - fantomas
there don't have proper rDNS, how many? I'm happy to block them for years... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. We

Re: Must-Have Plugins?

2015-06-09 Thread Matus UHLAR - fantomas
) TextCat (if you and your users are able to set up ok_languages) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. BSE = Mad Cow Desease

Re: Must-Have Plugins?

2015-06-09 Thread Matus UHLAR - fantomas
... (2) Check the HELO the other guy sends and reject if it's not a FQDN (i.e. it's not got any periods at all). or if it's your FQDN, or your IP - they should use their FQDN, not yours. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail

Re: user_prefs custom rules, not matching

2015-05-27 Thread Matus UHLAR - fantomas
will set their own score (this is enabled by default) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I wonder how much deeper the ocean would

Re: Confused about Bayes expiry

2015-05-26 Thread Matus UHLAR - fantomas
+0200, Matus UHLAR - fantomas wrote: Matus what other things? Journal is here to fasten database updates, Matus not to avoid database writes. too big journal slows things down. Matus The main reason to use manual expire is to avoid ocassional Matus delays with automatic expire noted in the bugreport

Re: Confused about Bayes expiry

2015-05-25 Thread Matus UHLAR - fantomas
, not to avoid database writes. too big journal slows things down. The main reason to use manual expire is to avoid ocassional delays with automatic expire noted in the bugreport you posted link to. so, again, what are reasons you want to avoid journal syncs? -- Matus UHLAR - fantomas, uh...@fantomas.sk

Re: Particularly annoying spam

2015-05-02 Thread Matus UHLAR - fantomas
3.5 for BAYES_99 just enough - properly trained BAYES db should be enough. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Linux - It's now

Re: Particularly annoying spam

2015-05-02 Thread Matus UHLAR - fantomas
this is to manually increase score for rules URIBL_BLACK, SPF_FAIL and BAYES_80 ? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. - Have you got

Re: AWL defeating my SPAM classification

2015-04-30 Thread Matus UHLAR - fantomas
on the caching nameserver in my DMZ. Is that useful in any way to resolve this issue? you can set up forwarding to the rbldnsd server, if it contains proper zones. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising

<    5   6   7   8   9   10   11   12   13   14   >