[exim] heads-up: some spam bots started RCPT flooding

2023-05-14 Thread Markus Reschke via Exim-users
Hi! Maybe you've already noticed some spam bots trying to deliver spam to exactly 100 recipients in one wash up. They take a list of common user names, add your domain name, and then loop through 100 RCPT TOs per mail. To slow them down you could use the settings smtp_ratelimit_hosts and smtp

[exim] Re: heads-up: some spam bots started RCPT flooding

2023-05-15 Thread Markus Reschke via Exim-users
On Sun, 14 May 2023, Jeremy Harris via Exim-users wrote: Hi! On 14/05/2023 18:56, Markus Reschke via Exim-users wrote: They take a list of common user names, add your domain name, and then loop through 100 RCPT TOs per mail. An escalating delay per RCPT *reject* isn't hard. I was ab

[exim] Re: heads-up: some spam bots started RCPT flooding

2023-05-22 Thread Markus Reschke via Exim-users
Hi! On 2023-05-20 01:20, James via Exim-users wrote: I use:     condition = ${if and {{>{$rcpt_count}{2}}{>{${eval:$rcpt_count-$recipients_count}}{2}}}{yes}{no}} Nice refinement! On Sun, 21 May 2023, Alexander Carver via Exim-users wrote: Which of the ACLs should this actually be in? I tr

[exim] Re: Unexpected 're-routed to' in require verify = recipient?

2023-05-24 Thread Markus Reschke via Exim-users
On Wed, 24 May 2023, Sander Smeenk via Exim-users wrote: Hi! Indeed it seems to be related to CNAME chains like in your situation and the ones discussed before this. Same here: $ exim -bt i...@email.postcodeloterij.nl i...@postcodeloterij.slgnt.eu <-- i...@email.postcodeloterij.nl rout

[exim] Re: Completely remove any name in From: header for inbound email?

2023-05-26 Thread Markus Reschke via Exim-users
Hello Sebastian! On Fri, 26 May 2023, Sebastian Arcus via Exim-users wrote: Hello. As so many scams around are based on impersonating someone inside the company, I am wondering if anyone here has considered the more extreme solution of completely removing any name in the From: header for incom

[exim] Re: Tackling Bot Blasts

2023-05-29 Thread Markus Reschke via Exim-users
Hi Slavko! On Mon, 29 May 2023, Slavko via Exim-users wrote:A Anyway, that must be enough: condition = $host_lookup_failed or: !verify = reverse_host_lookup ciao Markus -- / Markus Reschke \ \ madi...@theca-tabellaria.de / -- ## subscription configuration (requires acc

[exim] Re: tainted uux transport

2023-07-31 Thread Markus Reschke via Exim-users
Hi Randy! On Mon, 31 Jul 2023, Randy Bush via Exim-users wrote: force_uucp: driver = manualroute domains = ! +local_domains route_data = ${lookup{$domain}partial-lsearch{/usr/local/etc/exim/ro.uucp}} In case you can't create a list of known domains, e.g. when routing to a UUCP smarthost,

[exim] Re: List headers [Was: DKIM does not work]

2023-10-23 Thread Markus Reschke via Exim-users
Hi! I'm also looking into optimizing my DKIM configuration, especially which headers to sign. Unfortunately, DMARC reports tell you only that the DKIM verification failed but not why. The default for dkim_sign_headers doesn't work well for me. On Mon, 23 Oct 2023, Andreas Metzler via Exim-us

[exim] Re: List headers [Was: DKIM does not work]

2023-10-23 Thread Markus Reschke via Exim-users
Hi! On Mon, 23 Oct 2023, Andrew C Aitchison via Exim-users wrote: I believe that the default for dkim_sign_headers should have '=' at least for each of the List-* headers, as Andreas has done. Yes, that would be reasonable. BTW, RFC6376 comes with inconsistencies about the headers to sign.

[exim] Re: List headers [Was: DKIM does not work]

2023-10-23 Thread Markus Reschke via Exim-users
Hi! On Mon, 23 Oct 2023, Ian Z via Exim-users wrote: On Mon, Oct 23, 2023 at 11:51:21AM +0200, Andreas Metzler via Exim-users wrote: Kind of. The RFC has big fat disclaimer that it only provides very rough guidance ("The choice of which header fields to sign is non-obvious.") and is very ve

[exim] Re: Destination address in a transport

2023-10-26 Thread Markus Reschke via Exim-users
Hi! On Thu, 26 Oct 2023, Thomas Andrews via Exim-users wrote: The destination address could be g...@wimzail.org or anything - ie I have no way to de-taint it as it is not a local address. Therefore using $local_part and $domain is not an option. What are my other options? (By the way, it does

[exim] Re: detainting a sender address in a router/transport

2023-12-29 Thread Markus Reschke via Exim-users
Hello Jürgen! On Fri, 29 Dec 2023, Jürgen Edner via Exim-users wrote: I've now spent several hours to read through all kind of Exim documentation and mailing list postings, to find-out how to fix my specific router/transport configuration to get rid of tainted data, without success. print_t