The type of SPAM we are seeing is where legit companies are having their adverts cloned and the hyperlinks changed to spammy sites. Bayes is being by-passed due to the content looking valid so it is coming down to the IPs and domains. Had one yesterday where at 06:39 it was received by one of our clients and at 06:42 it appeared on one of the RBLs. I am guessing that it must have been a huge spam mailing that hit a lot of honeypots and people all at once. Downside is not a happy client ;( -- Thanks, Phil
----- Original Message ----- > Am 11.01.2012 12:28, schrieb --[ UxBoD ]--: > > Hi, > > > > we have seen a recent upsurge in SPAM and would like to ask the > > community for recommendations on both free and commercial RBL > > offerings. > > We are currently using: > > > > Barracuda > > SpamRats > > JunkEmailFilter > > SpamEatingMonkey > > never used this > > > > > Plus the standard ones that are checked with SpamAssassin. We are > > also > > about to trial Invaluement. > > > > Any help is gratefully appreciated. > > -- > > Thanks, Phil > > > > beside spamassassin > > i use this rbls with postfix > > reject_rbl_client zen.spamhaus.org, > reject_rbl_client ix.dnsbl.manitu.net > > mostly in with some selective > setup, clamav milter with sanesecurity, greylist, and some postscreen > configs > > ix.dnsbl.manitu.net perhaps is more in interest for german/euro > region > > that was enough ever, for most global spam, for sure > you need analyse your logs an make special setups related to ips > ,domains etc sometimes > > -- > Best Regards > > MfG Robert Schetterer > > Germany/Munich/Bavaria >