Re: new kind of spam with bizarre custom headers getting through

2014-09-05 Thread SM
. Here is one of the headers with my addresses redacted: The odd headers change on each run. You should be able to catch them with Bayes. Regards, -sm

60_adsp_override_dkim.cf (was: Plans for a DMARC plugin ???)

2014-05-01 Thread SM
custom_med adsp_override yahoo.com.au custom_med adsp_override yahoo.com.br custom_med adsp_override yahoo.com.cn custom_med adsp_override yahoo.com.hk custom_med ... I did a quick verification. The above domains do not publish an ADSP record. Regards, -sm

Re: FSL_HELO_BARE_IP_2 RCVD_NUMERIC_HELO

2013-10-18 Thread SM
that there is any violation of the specification. Regards, -sm

Re: rdns in received header

2013-02-24 Thread SM
to add with ESMTP to the received headers. The following is about ESMTP: For instance, servers MUST support the EHLO command even if they do not implement any specific extensions and clients SHOULD preferentially utilize EHLO rather than HELO. Regards, -sm

Re: rdns in received header

2013-02-24 Thread SM
At 11:07 24-02-2013, Kevin A. McGrail wrote: I'm referring to other RFCs such as 1651 which says: That's an obsoleted RFC. It might be better to refer to RFC 5321 (Section 4.4) for information about the Received: header. Regards, -sm

Re: wrong RCVD_IN_PBL?

2012-11-20 Thread SM
that rule. Regards, -sm

Re: How to report a spam botnet

2012-11-20 Thread SM
At 16:44 20-11-2012, Matt wrote: authenticated SMTP to relay not? Is there a way in apache .htaccess to block access based on xbl.spamhaus.org? I want to block exploited IP's from webmail etc as well. http://www.lucaercoli.it/mod_spamhaus.html Regards, -sm

Re: SA rules matching of private addresses

2012-10-04 Thread SM
, -sm

Re: How to check from that is not on the header?

2012-09-26 Thread SM
/spamassassin/EnvelopeSenderInReceived Regards, -sm

Re: Responsibility of sites that hold user-created documents (was Re: One-line URI body spam)

2011-10-26 Thread SM
as responsibility of free services that hold user-created documents. Regards, -sm

Re: blacklist based on authoritative nameservers of sender domain

2011-08-27 Thread SM
positives. You might be able to do some scoring instead of blacklisting. Regards, -sm

Re: How to prevent SA to make as112 calls?

2011-05-01 Thread SM
** 192.168.0.69, 17549- 173.45.100.146, 53 (from COM1 Outbound) You can create the zones mentioned in http://tools.ietf.org/html/draft-ietf-dnsop-default-local-zones-15 Regards, -sm

Re: Score on sender domain by country

2011-04-11 Thread SM
the country, you can put in a score for such a rule. You may have to allow some exceptions (e.g. by domain name). Regards, -sm

Re: SpamAssassin Integration

2010-06-17 Thread SM
At 05:18 17-06-10, Matt Kettler wrote: The best docs would be the RFC standards: RFC 2822 Internet Message Format RFC 822 (obsoleted by above, but sometimes useful for understanding the history of the format, making intent clearer.) RFC 2822 obsoleted by RFC 5322. Regards, -sm

Re: rsys4.com and Paypal?

2010-04-20 Thread SM
At 10:18 20-04-10, LuKreme wrote: I got a mail from Paypal, but it is not FROM paypal, but it appears to have passed DKIM If it passed DKIM and it is signed by info.paypal.com, it's from Paypal. Regards, -sm

RE: [LinkedIn Spam] Re: unwhitelist from_dkim?

2010-03-22 Thread SM
in the format *-l...@.* or other common mailing list address formats. It wouldn't catch all of them, I'm sure (m...@gnome.org, for example), but it might help. There isn't a reliable way to identify mailing list addresses. Regards, -sm

Re: MTAmark (was: MTX plugin functionally complete?)

2010-02-16 Thread SM
also saw a few links to personal pages at space.net, but they're long gone. There is experimental support for MTAMARK in a well-known MTA. The proposal had less exposure than SPF. Regards, -sm

Re: SA on outgoing SMTP

2010-02-16 Thread SM
is not a good idea. Sign up for feedback loops. Rate limit mail submissions or set up triggers to identify abnormalities. You may also wish to do traffic flow analysis to see what's going through your network. Regards, -sm

Re: SA on outgoing SMTP

2010-02-16 Thread SM
positive... I can't let a user thinking we sent his mail when we wrongly dropped it. I am not talking about dropping mail. False positives _will_ happen. Regards, -sm

Re: Pipe characters in From and To's

2010-02-12 Thread SM
rules into sendmail, so SA is my avenue of choice. Having a rule in sendmail is less work. Regards, -sm

Re: Hostkarma: to be or not to be in SA defaults

2009-09-30 Thread SM
to you. :-) Regards, -sm

Setting a Reply-To header for this mailing list (was: [sa] Re: Any one interested in using a proper forum?)

2009-07-28 Thread SM
At 10:27 28-07-2009, Charles Gregory wrote: :0fw * ^(To|Cc):.*(use...@spamassassin|spamassassin.users) | /usr/bin/formail -IReply-To: users@spamassassin.apache.org Match on the List-Id: header instead of the To: or Cc:. Regards, -sm

Re: Spam Filter Law Suit

2009-07-15 Thread SM
/keyword spam filter called filter.plx ( http://spamassassin.apache.org/prehistory/ ). I don't know whether the patent about enhancing touch and feel on the Internet is related to your questions. Regards, -sm

Re: OT: Website protection

2009-07-11 Thread SM
that for webpages. As the system is compromised, you cannot rely on the scan. Any ideas where to look for such a beast /or a mailing list that deals with this type of issue? Search for tripwire. Regards, -sm

Re: mailbox-list in sender: header?

2009-07-10 Thread SM
not familiar with? Did you mean Sender: header instead of Subject: header? Multiple addresses rarely appear in the From: header. It's better to have a rule for the multiple addresses in the Sender: header if you are receiving a lot of spam with the above headers. Regards, -sm

Re: twitter spam why RCVD_IN_DNSWL?

2009-07-10 Thread SM
so that you can be spammed. :-) If you are running mailing lists, don't whitelist those domains. That also applies if you don't want to be spammed by those domains. Regards, -sm

Re: constantcontact.com

2009-07-06 Thread SM
/%3cac9ad70907041849m735b0b68mb0909b83216b0...@mail.gmail.com%3e ) Regards, -sm

Re: constantcontact.com

2009-07-06 Thread SM
. Regards, -sm

Re: Apache.org spam??

2009-06-25 Thread SM
? The message was sent by a mailing list subscriber to a list which generally discusses about spam. It scored 4.0 on Apache.org. Why is the message obvious spam? What rules would you recommend to catch it? Regards, -sm

Re: Apache.org spam??

2009-06-25 Thread SM
) describe NO_RESENT_MAIL Meta: please dont resend mail to maillists score NO_RESENT_MAIL 3.0 if i cant fix others problems but imho apache.org need the above :) Nice. The above rules cannot be applied for all apache.org traffic as it's not only for mailing lists. Regards, -sm

Re: unclosed if error

2009-06-22 Thread SM
) The end if should not be in the describe line. Add endif after the describe line to close the ifplugin condition. See http://mail-archives.apache.org/mod_mbox/spamassassin-users/200906.mbox/%3cpine.lnx.4.64.0906020849430.10...@mercury.impsec.org%3e Regards, -sm

RE: unclosed if error

2009-06-22 Thread SM
/mail/spamassassin/jp.cf: if plugin (Mail::SpamAssassin::Plugin::MIMEHeader) Tar the jp.cf file and send it to me off-list. Regards, -sm

Re: Lots of 419/scam and investment spams getting through suddenly

2009-06-19 Thread SM
At 22:59 18-06-2009, Chip M. wrote: Here's a dump of the complete Countries routes of your samples (frequency first, then square brackets around the IP immediately outside your own network): 2 [France], Nigeria Do you really get such emails from Nigeria? :-) Regards, -sm

Re: Lots of 419/scam and investment spams getting through suddenly

2009-06-19 Thread SM
or Hong Kong won't help that much because of the mode of operation of these senders. One of the advantages of SpamAssassin is that it doesn't use one specific rule to detect spam. If you rely on one specific rule only, it will be subverted. Regards, -sm

Re: Lots of 419/scam and investment spams getting through suddenly

2009-06-19 Thread SM
At 17:26 19-06-2009, RW wrote: The last hop into the internal network is rarely from Nigeria, but I find it turns up in X-Spam-Relay-Countries in about 9% of my own spam. Can you send me a sample of the email headers off-list? Regards, -sm

Re: List headers and footers [Re: Unsubscribe]

2009-06-16 Thread SM
At 05:08 16-06-2009, McDonald, Dan wrote: Altering message bodies might break gpg|pgp signatures, but not DKIM. It generally invalidates the DKIM signature. This mailing list does not use Mailman. Regards, -sm

Re: 419 scams in .doc and .rtf attachments

2009-06-16 Thread SM
rules, you would have to render the content before passing the modified message to SpamAssassin. Regards, -sm

Re: Unsubscribe

2009-06-12 Thread SM
. Regards, -sm

RE: Odd behaviour under load.

2009-05-08 Thread SM
Hi John, At 06:50 08-05-2009, John Hardin wrote: I suspect the sender is timing out waiting for the 250 OK after sending the message, hence my (humorous) 100 Please hold... suggestion. (Jeeze, SM, lighten up!) There has already been such a proposal. Someone might take your humorous

Re: Odd behaviour under load.

2009-05-07 Thread SM
At 13:15 07-05-2009, John Hardin wrote: Heh. Does the SMTP protocol need a 100 Please hold... reply? No. Fix the mail server instead of the protocol. Regards, -sm

Re: emailBL

2009-04-27 Thread SM
character for a hostname. The example you gave is not a hostname. Regards, -sm

Re: Another bad kind of spams, for Pfizer knockoffs with image

2009-04-24 Thread SM
. The following rule may help. You'll need the ImageInfo plugin. body PNG_200_400 eval:image_size_range('png', 200, 400, 250, 450) describe PNG_200_400 Contains png 200-250 x 400-450 score PNG_200_400 0.1 Adjust the score to fit your needs. Regards, -sm

Re: Phishing

2009-04-24 Thread SM
, there is a larger problem if there are hacked accounts available on the sending network and on your network. Regards, -sm

Re: emailreg.org (was: zen.spamhaus.org)

2009-04-10 Thread SM
of expiration date? Who knows? It will be interesting to see whether the rules are included in a SpamAssassin distribution. Regards, -sm

emailreg.org (was: zen.spamhaus.org)

2009-04-09 Thread SM
money to a site with a domain owner hidden by the Whois privacy registration? :-) Some antispam offers are big and easy money as there's always somebody ready to pay or to jump on the bandwagon because it is free. Regards, -sm

Re: Ways to block bouncebacks?

2009-04-05 Thread SM
any spam You can use BATV. You must then submit all messages for the domain through a mail server that supports BATV. Regards, -sm

Re: Suddenly bouncing emails

2009-03-23 Thread SM
URIBL_PH_SURBL Contains an URL listed in the PH SURBL blocklist Do a DNS test for a non-existent hostname. If you receive an answer, switch to a name server (you can run one locally) that provides genuine replies. Regards, -sm

Re: efax sends it own phishing email.? or java script I can't decode?

2009-03-21 Thread SM
. That is usually done by email. Regards, -sm

Re: Dealing with low scoring spam - tighter MTA integration [was: 2 + 2 != 4 - Spamassassin needs a new paradigm]

2009-03-04 Thread SM
as there is less overhead. The downside is that you will get more false positives. Regards, -sm

Re: ReturnPath, Habeas, BondedSender

2009-03-03 Thread SM
At 17:20 02-03-2009, J.D. Falk wrote: (BTW, a quick visit to your favorite search engine should alleviate any fears that either Neil or I are marketers.) I can confirm that J.D. is not in marketing. He did not top-post or send his message in HTML format. :-) Regards, -sm

Re: How to disable DNSWL?

2009-03-03 Thread SM
and the rules that message hit. Regards, -sm

Re: Something doofuzzled in a * ^To: line.

2009-02-23 Thread SM
. Regards, -sm

Re: Something doofuzzled in a * ^To: line.

2009-02-23 Thread SM
, -sm

Re: HELO checks give too high score together

2009-02-22 Thread SM
At 23:16 21-02-2009, Benny Pedersen wrote: why does a smtp server have dynamic hostname alike in the first place ? What is a dynamic hostname? Regards, -sm

Re: HELO checks give too high score together

2009-02-22 Thread SM
At 01:20 22-02-2009, Benny Pedersen wrote: you dont know it either ? The term dynamic hostname is used in intermediate system routing. Regards, -sm

Re: Error ''connect to spamd on 127.0.0.1 failed, retrying (# 1 of 3): Connection timed out ''

2009-02-17 Thread SM
message, spamd is not listening on localhost. Regards, -sm

Re: Filtering/ blocking forged emails

2009-02-06 Thread SM
it with the domain? There are three RCVD_IN_BSP_ rules for that. Regards, -sm

Re: Filtering/ blocking forged emails

2009-02-06 Thread SM
At 13:10 06-02-2009, Michael Scheidell wrote: (ps, someone has a FP on whois_contactpriv) Doesn't look like apache or espphotograpy.com or dslextreme.com It's not a false positive. There was xxx.com in the message. Regards, -sm

RE: country in africa

2009-01-31 Thread SM
Bayes to deal with that type of email. Regards, -sm

RE: country in africa

2009-01-31 Thread SM
this mailing list will trigger their antispam filters as the discussion is generally about spam. Regards, -sm

Re: Bayesian per domain filtering

2009-01-18 Thread SM
have to patch the code to do that. Regards, -sm

RE: Temporary 'Replacements' for SaneSecurity

2009-01-15 Thread SM
, post some samples on a web site together with the rules that were hit. Regards, -sm

Re: Temporary 'Replacements' for SaneSecurity

2009-01-14 Thread SM
that technology certified for illegal content only? :-) Sanesecurity could have been better protected against DDOS attacks. They are a ripe target. Regards, -sm

Re: Temporary 'Replacements' for SaneSecurity

2009-01-14 Thread SM
who only receive mail from the US or Europe, I'll point out that it also causes false positive for that kind of mail traffic. As you mentioned above, the problem is not really with Botnet plugin if we understand that it does not detect botnets. Regards, -sm

Eudora content concentrator (was: Whitelist not working - Ugh please help)

2009-01-09 Thread SM
to hide the headers only, you can use the TabooHeaders setting. Regards, -sm

Re: Whitelist not working - Ugh please help

2009-01-08 Thread SM
At 18:40 08-01-2009, Evan Platt wrote: For the THIRD time, SpamAssassin is not marking the mail as Spam. Mailscanner is. You need to ask on a mailscanner list. The footer at the bottom of the original message is a hint as to why your advice won't be understood. :-) Regards, -sm

Re: A lot of spams go through, see example

2008-12-26 Thread SM
or reduce the score for autolearning ham until you fix this problem. As a quick fix, add a header rule to catch the FreeCreditReports360.com in the From header. Regards, -sm

Re: [OT] GPG Signatures

2008-12-15 Thread SM
of the message instead of the sender. Regards, -sm

Re: Preemptive URI blocklisting

2008-12-14 Thread SM
the registrant information available from Whois and see whether such domains regularly appear in spam or ham. Regards, -sm

Re: sought rules updates

2008-12-11 Thread SM
checking the signature is not enough. Regards, -sm

Re: sought rules updates

2008-12-10 Thread SM
way. If you want the simplest way, you can ignore these steps and face the consequences when something goes wrong. Regards, -sm

Re: sought rules updates

2008-12-10 Thread SM
as the private key is secure and the signer still has your trust. Regards, -sm

Re: [sa-list] Re: [sa-list] Re: Spamd and ipv6

2008-12-03 Thread SM
are sharing their code for free.If we need a specific feature or find a bug, we can always send a patch. If you read the URL I posted previously, you will see that the developers have been working on IPv6 support. Regards, -sm

Re: I'm thinking about offering a free MX backup service

2008-12-02 Thread SM
At 11:51 02-12-2008, Marc Perkel wrote: Tell me if you think this is a good idea. Everything that helps to promote your business is a good idea. :-) Regards, -sm

Re: [sa-list] Re: Spamd and ipv6

2008-12-01 Thread SM
. See https://issues.apache.org/SpamAssassin/show_bug.cgi?id=4964 Additionally, even when I get this working, I am unable to specify ipv6 addresses to -A, either with or without square brackets. That part of the code is IPv4 specific. Regards, -sm

Re: [sa-list] Re: [sa-list] Re: Spamd and ipv6

2008-12-01 Thread SM
the patch. You can either wait for 3.3 to be released or adapt that patch for your version of SpamAssassin. Regards, -sm

Re: Spamd and ipv6

2008-11-30 Thread SM
the -i parameter to specify the IPv6 address. The -A parameter to specify the host which can connect to spamd and not the IP address on which spamd should listen on. Regards, -sm

Re: IPv6 only sa-update channels?

2008-11-28 Thread SM
are dealing with. Some educational institutions exchange a significant amount of mail over IPv6. The amount of spam is still quite low or non-existent for some. Regards, -sm

Re: SURBL Usage Policy change

2008-11-12 Thread SM
X messages or if your site has more than Y users? Regards, -sm

Re: Spamassassin Restart and E-Mail being scanned at time of restart.

2008-11-12 Thread SM
, the software interacting with SpamAssassin will not get a negative or positive response. The software might defer mail delivery and retry later, hence causing a rescan. Regards, -sm

Re: Accidentally Filtering through Spamassassin Twice

2008-11-06 Thread SM
be filtered twice. Is that a correct assumption? Yes. So I'm probably wasting resources if my Spamassassin host is configured as such? Yes. See http://wiki.apache.org/spamassassin/UsedViaProcmail for more information about calling SpamAssassin from procmail. Regards, -sm

Re: Accidentally Filtering through Spamassassin Twice

2008-11-06 Thread SM
will pass the message to the spamd daemon and get the result. Regards, -sm

Re: prefork: oops! no idle kids in need_to_del_server?

2008-11-02 Thread SM
. See whether your issue is OS specific. Regards, -sm

Re: Phishing rules?

2008-11-01 Thread SM
want to blacklist that host? Regards, -sm

Re: Spamassassin+amavis

2008-10-30 Thread SM
on outbound mail where the customer is relaying through your mail server. Regards, -sm

Re: Spamassassin+amavis

2008-10-24 Thread SM
to catch them. Regards, -sm

Re: Spamassassin+amavis

2008-10-24 Thread SM
by the SpamAssassin project ( http://wiki.apache.org/spamassassin/RuleUpdates ). The sought rules ( http://wiki.apache.org/spamassassin/SoughtRules ) are quite effective in catching fresh spam messages. Regards, -sm

Re: bogusmx [Was: DNS restrictions for a mail server]

2008-10-23 Thread SM
preferences are processed to determine where a message should be delivered. That influenced the decision on discouraging CNAMEs in the data section of MX RRs. My comment is not about bogusmx or antispam; it's about how to determine in a reliable way where to deliver a message. Regards, -sm

Re: bogusmx [Was: DNS restrictions for a mail server]

2008-10-23 Thread SM
as we are not arguing about the same thing. Regards, -sm

Re: DNS_FROM_SECURITYSAGE broken?

2008-10-07 Thread SM
At 14:22 07-10-2008, David B Funk wrote: I recently noticed that DNS_FROM_SECURITYSAGE was hitting everything. http://issues.apache.org/SpamAssassin/show_bug.cgi?id=5672 Regards, -sm

Re: DOB blocklist seems to have very old domains

2008-10-05 Thread SM
. Regards, -sm

Re: New free blacklist: BRBL - Barracuda Reputation Block List

2008-09-23 Thread SM
.) There was a mailing list for a well-known open source project originating legitimate SMTP traffic for a few days from a host without reverse DNS. The reason was not sysadmin or ISP incompetence. Regards, -sm

Re: sa-update with proxy

2008-09-22 Thread SM
the proxy. ie: export http_proxy='http://proxy.example.com:8080/' Regards, -sm

RE: New free blacklist: BRBL - Barracuda Reputation Block List

2008-09-22 Thread SM
works. Regards, -sm

Re: New free blacklist: BRBL - Barracuda Reputation Block List

2008-09-22 Thread SM
At 08:58 22-09-2008, Matt wrote: Everyone should block/defer ALL email with no reverse DNS. Then maybe those email admins would get a clue. Assuming you have signed up for that service, would you whitelist the sending host or wait for the postmaster to get a clue? Regards, -sm

Re: Trying out a new concept

2008-09-22 Thread SM
it is because the test is so far after everything else though. Even if your traffic patterns are different, the hit rates shouldn't be that low. There would be a difference if your MTA uses a DNSBL to reject or if you apply other pre-content filtering techniques. Regards, -sm

Re: Trobles with spamassassin

2008-09-19 Thread SM
whether there are any errors. Regards, -sm

RE: spamassassin can't rewrite subject in cpanel 11?

2008-09-18 Thread SM
At 06:19 18-09-2008, Bowie Bailey wrote: This works on Outlook, but header tests were not available in Outlook Express the last time I checked. In Outlook Express, you can have a rule for the Subject line. Regards, -sm

Re: FM_FAKE_HELO_VERIZON

2008-09-14 Thread SM
the hostname as a botnet client. A bug reported has been posted for the second rule. Regards, -sm

Re: MagicSpam

2008-09-12 Thread SM
benefit. SpamAssassin, the software, is a mail filter to identify spam. It is designed for easy integration into any email system. The cost to develop such a software is estimated to be around US $1.1 million. Regards, -sm

  1   2   3   4   >