On 1/11/2012 11:51 AM, Dave Funk wrote:
On Wed, 11 Jan 2012, --[ UxBoD ]-- wrote:

The type of SPAM we are seeing is where legit companies are having
their adverts cloned and the hyperlinks changed to spammy sites.

sanesecurity hits many of these.
uri filters can also assist.. surbl, uribl

Bayes
is being by-passed due to the content looking valid so it is coming
down to the IPs and domains. Had one yesterday where at 06:39 it was
received by one of our clients and at 06:42 it appeared on one of the
RBLs. I am guessing that it must have been a huge spam mailing that
hit a lot of honeypots and people all at once. Downside is not a happy
client ;(


Graylisting would be one answer to this particular senario.
However it has the downside of delaying legit messages.
Some clients seem to think that e-mail == IM and get PO'ed
if messages don't arrive with seconds of sending.

Actually had a faculty ask me how to set his T-bird to check for
new messages every -second-, didn't want to wait a minute. ;(


imap?

--
Ken Anderson

Reply via email to