RE: Q about mail proxy servers and setups

2007-09-23 Thread David B Funk
On Sun, 23 Sep 2007, Michael Scheidell wrote: > For the purposes of this discussion, the biggest reason I can't be on > the edge where Id like to be is that there is a massive proxy/load > balancer/failover device that does more than email. > > Many firewalls 'proxy' the email also, so its not lik

Marc: use SPF to prevent backscatter? Was RE: [AMaViS-user] Q about mail proxy servers and setups

2007-09-23 Thread Michael Scheidell
One thing I would like to see (and this is a different subject: Marc: take note: Id like to NOT BOUNCE an email back to the victim of backscatter if they bothered to publish SPF or SENDER ID records that don't match the incoming. (and, yes, this would NOT work behind a proxy) I would like the pr

RE: Q about mail proxy servers and setups

2007-09-23 Thread Michael Scheidell
Thanks, I hadn't thought about the backscatter problem. If there is a proxy involved, then they HAVE to set (in amavisd) all final destinations as 'DISCARD' and not BOUNCE. I also think I will try to look at adding it to trusted networks in SA, but excluding it from the internal networks in amav

RE: [AMaViS-user] Q about mail proxy servers and setups

2007-09-23 Thread Michael Scheidell
Anyone have an answer that isn't obvious? I already said I can't put it on the proxy. -- Michael Scheidell, CTO Office: 561-999-5000 x 1259 Direct: 561-939-7259 Real time security alerts: http://www.secnap.com/news _ This em

Re: bayes_seen = 256GB

2007-09-23 Thread Magnus Holmgren
On Thursday 20 September 2007 07:59, Graham Murray wrote: > "Loren Wilton" <[EMAIL PROTECTED]> writes: > > If tokens are expired from the DB based on time, and assuming *all* > > tokens older than some date are expired, wouldn't it be reasonable to > > prune bayes_seen to the expiry date after the

Re: [AMaViS-user] Q about mail proxy servers and setups

2007-09-23 Thread Clifton Royston
On Sun, Sep 23, 2007 at 01:50:43PM -0400, Michael Scheidell wrote: > Sometimes a large company will have a proxy server set up in the DMZ and > then send it to their internal mail server. ... > #1, SPF. SPF helo, SENDERID > The proxy will be adding a received header, and announcing 'HELO/EHLO' >

Re: Confusing issue regarding SPF_FAIL and local delivery

2007-09-23 Thread Magnus Holmgren
On Sunday 23 September 2007 18:50, John D. Hardin wrote: > On Sun, 23 Sep 2007, Jari Fredriksson wrote: > > > SpamAssassin's trusted_network configuration caught my > > > eye. What exactly does this do, and should I put my box's > > > ip address in there? > > > > Absolutely. You put all your intern

Re: OT - massive newsletter

2007-09-23 Thread mouss
Kris Deugau wrote: > Ralf Hildebrandt wrote: >> * Randal, Phil <[EMAIL PROTECTED]>: >>> If you don't want to annoy a lot of people your spamming (oops, >>> newsletter sending) software needs to deal with NDRs back from >>> recipient's domains and either put their subscription on hold after a >>> sm

Re: OT - massive newsletter

2007-09-23 Thread mouss
mizzio wrote: > hello everybody, > > I apologize to ask an off-topic question, and feel free to point me to > any other resources on the net. > > I'm setting up an SMTP server (centos + qmail) on a dell quad core > machine for sending out a periodic newsletter (10 millions a month). > > In order to

Re: Forwarding and spamassassin...

2007-09-23 Thread mouss
James Lay wrote: > > On 9/23/07 8:53 AM, "mel goldberg" <[EMAIL PROTECTED]> wrote: > > >> I¹m new to the list, apologize in advance if I should be posting this >> somewhere else. >> >> I am attempting to SPAM filter and forward from my server to another. >> Spamassassin filters but the server wi

Re: Q about mail proxy servers and setups

2007-09-23 Thread mouss
Michael Scheidell wrote: > Sometimes a large company will have a proxy server set up in the DMZ and > then send it to their internal mail server. > I understand that ideally, the proxy server would be replaces with a > SpamAssassin/MTA setup. > > However, sometimes, client, security and company pol

Re: [AMaViS-user] Q about mail proxy servers and setups

2007-09-23 Thread Jo Rhett
Every problem you've named here is solved by putting Amavis/SA on the proxy instead of the internal system. If the proxy doesn't do the spam-checking, and the internal system does I can name a dozen other problems that will occur, the most important of which will be backscatter. 2-step relay

Q about mail proxy servers and setups

2007-09-23 Thread Michael Scheidell
Sometimes a large company will have a proxy server set up in the DMZ and then send it to their internal mail server. I understand that ideally, the proxy server would be replaces with a SpamAssassin/MTA setup. However, sometimes, client, security and company policy needs outweigh logic. I can thin

Re: OT - massive newsletter

2007-09-23 Thread mizzio
The service is not new - it should be just moved to a new platform. cheers maurizio On sab, 2007-09-22 at 07:40 -0400, Dave Koontz wrote: > If I might ask, where are you getting the list "SEED" addresses from? > It's hard for me to imagine you have such a large number of users that > have alrea

Re: Confusing issue regarding SPF_FAIL and local delivery

2007-09-23 Thread John D. Hardin
On Sun, 23 Sep 2007, Jari Fredriksson wrote: > > SpamAssassin's trusted_network configuration caught my > > eye. What exactly does this do, and should I put my box's > > ip address in there? > > Absolutely. You put all your internal servers and possible ISP > servers there too. Trusted networks a

Re: Forwarding and spamassassin...

2007-09-23 Thread maillist
mel goldberg wrote: I’m new to the list, apologize in advance if I should be posting this somewhere else. I am attempting to SPAM filter and forward from my server to another. Spamassassin filters but the server will not forward. Has anyone found a way to do this? You can use mimedefang. h

Re: Forwarding and spamassassin...

2007-09-23 Thread James Lay
On 9/23/07 8:53 AM, "mel goldberg" <[EMAIL PROTECTED]> wrote: > I¹m new to the list, apologize in advance if I should be posting this > somewhere else. > > I am attempting to SPAM filter and forward from my server to another. > Spamassassin filters but the server will not forward. Has anyone f

Re: Forwarding and spamassassin...

2007-09-23 Thread Evan Platt
Spamassassin will not forward. You need to do this with your MTA or some other method. At 07:53 AM 9/23/2007, mel goldberg wrote: I'm new to the list, apologize in advance if I should be posting this somewhere else. I am attempting to SPAM filter and forward from my server to another. Spamas

Re: Forwarding and spamassassin...

2007-09-23 Thread Matt Kettler
mel goldberg wrote: > I’m new to the list, apologize in advance if I should be posting this > somewhere else. > > I am attempting to SPAM filter and forward from my server to another. > Spamassassin filters but the server will not forward. Has anyone found > a way to do this? That depends on what s

Forwarding and spamassassin...

2007-09-23 Thread mel goldberg
I¹m new to the list, apologize in advance if I should be posting this somewhere else. I am attempting to SPAM filter and forward from my server to another. Spamassassin filters but the server will not forward. Has anyone found a way to do this?

Re: Confusing issue regarding SPF_FAIL and local delivery

2007-09-23 Thread Jari Fredriksson
> SpamAssassin's trusted_network configuration caught my > eye. What exactly does this do, and should I put my box's > ip address in there? Absolutely. You put all your internal servers and possible ISP servers there too. Trusted networks are networks and hosts that you trust are not generating