Writing custom plugins

2008-05-06 Thread ram
http://wiki.apache.org/spamassassin/PluginWritingTips Gives plugin writing tips. But is there a beginners plugin-writing-howto. What are requisites. I am fairly comfortable writing in perl, will that be enough. I want to call a web api for a third party scanner within SA Thanks Ram

Re: Spoofed Email But Different User Name

2008-05-06 Thread Matt Kettler
mhildebr wrote: Is there a way to have Spamassassin look for spoofed email addresses being used as the sender's address ([EMAIL PROTECTED]) but using a different user name (Viagra instead of myname)? It seems like it would be simple to check the user name and filter results from that. Thanks fo

Spoofed Email But Different User Name

2008-05-06 Thread mhildebr
Is there a way to have Spamassassin look for spoofed email addresses being used as the sender's address ([EMAIL PROTECTED]) but using a different user name (Viagra instead of myname)? It seems like it would be simple to check the user name and filter results from that. Thanks for any help. -- V

Re: typo in 20_vbounce.cf?

2008-05-06 Thread Justin Mason
=?ISO-8859-15?Q?Robert_M=FCller?= writes: > Hi all, > as I'm facing raising amount of bounces on my mailserver in the last 2 > months, I tried to use the vbounce ruleset to identify the ones caused > by UBE faking the sender address. > This was generally successful, but surprisingly there are a

typo in 20_vbounce.cf?

2008-05-06 Thread Robert Müller
Hi all, as I'm facing raising amount of bounces on my mailserver in the last 2 months, I tried to use the vbounce ruleset to identify the ones caused by UBE faking the sender address. This was generally successful, but surprisingly there are a lot of UBE-bounces which are not recognized by vbou

Re: whitelist mail from own host

2008-05-06 Thread Benny Pedersen
On Tue, May 6, 2008 23:02, Stefan Jakobs wrote: > Yes, that's a possibility, but I can not do that. At least not in the near > future. Any other ideas? depends, but i like to know why spf can't work for you ? Benny Pedersen Need more webspace ? http://www.servage.net/?coupon=cust37098

Re: whitelist mail from own host

2008-05-06 Thread Benny Pedersen
On Tue, May 6, 2008 23:06, mouss wrote: > you rely on the sender address, make sure to reject it in your smtpd > (you don't want to give spammers an open road). that was why i sugested spf Benny Pedersen Need more webspace ? http://www.servage.net/?coupon=cust37098

Re: whitelist mail from own host

2008-05-06 Thread mouss
Stefan Jakobs wrote: Hello list, here is a part of the header from a mail I like to whitelist: X-Spam-Status: Yes, score=6.958 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, NO_RELAYS=-0.001, SPOOF_COM2COM=2.272, SPOOF_COM2OTH=2.044, URIBL_BLACK=1.955, URIBL_PH_SURBL=1.787

Re: whitelist mail from own host

2008-05-06 Thread Stefan Jakobs
On Tuesday 06 May 2008 22:00, Benny Pedersen wrote: > On Tue, May 6, 2008 21:32, Stefan Jakobs wrote: > > From: [EMAIL PROTECTED] > > add a spf record for this domain incl the subdomain :-) Yes, that's a possibility, but I can not do that. At least not in the near future. Any other ideas? > > >

Re: whitelist mail from own host

2008-05-06 Thread Benny Pedersen
On Tue, May 6, 2008 21:32, Stefan Jakobs wrote: > From: [EMAIL PROTECTED] add a spf record for this domain incl the subdomain :-) then whitelist_auth [EMAIL PROTECTED] adjust the whitelist score so it not default -100 but enough to get the mail through def_whitelist_auth [EMAIL PROTECTED] whi

IE Parse bug olso in SpamAssassin ?

2008-05-06 Thread Benny Pedersen
-- html code -- Hi!http://{MACCCLINK=3Dtestmaclink,3,http= ://67.228.184.50/links1.txt,www.easyaddedvivacecreation.com}/?srrjrrlt2qx= fpm7DuzjjB82iEozsAEajsqbE">. Sick and tired of disaster in bed? Bright up now! Leave monotonous experience behind! urgent rescue is is not far! Flood of feelings

whitelist mail from own host

2008-05-06 Thread Stefan Jakobs
Hello list, here is a part of the header from a mail I like to whitelist: X-Spam-Status: Yes, score=6.958 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, NO_RELAYS=-0.001, SPOOF_COM2COM=2.272, SPOOF_COM2OTH=2.044, URIBL_BLACK=1.955, URIBL_PH_SURBL=1.787, URIBL_WS_SURB

Re: whitelisting webmail application

2008-05-06 Thread Kris Deugau
Benny Pedersen wrote: does users us smtp auth ? Not the OP, but he *did* say this is from webmail. Presumably it's a little hard to send mail from his webmail setup unless you're logged in... (IIRC SA includes rules to look for Horde/IMP and Squirrelmail [at least] Received: headers and co

RE: joe jobbed or hacked?

2008-05-06 Thread Jason Esman
What are people doing about joe jobs at this point? What custom rules, and or pluggins? I use qmail with spamassassin and I'm seeing a increase in these over the last few weeks on some of my domains. Jason > -Original Message- > From: Rubin Bennett [mailto:[EMAIL PROTECTED] > Sent: Mond

Re: Bayes database

2008-05-06 Thread Theo Van Dinter
On Tue, May 06, 2008 at 04:16:06PM +0200, polloxx wrote: > Your Bayesian database has become dirty: too mush ham mails get a > score of BAYES_99, certainly for one of your customer domains. > > Is there a way to sanitize the database without clear the whole thing? > What are the best practices to k

Re: Bayes database

2008-05-06 Thread Matus UHLAR - fantomas
On 06.05.08 16:16, polloxx wrote: > Your Bayesian database has become dirty: too mush ham mails get a > score of BAYES_99, certainly for one of your customer domains. > Is there a way to sanitize the database without clear the whole thing? do you keep all mail you've user to learn? If so, re-check

Bayes database

2008-05-06 Thread polloxx
Hi, Your Bayesian database has become dirty: too mush ham mails get a score of BAYES_99, certainly for one of your customer domains. Is there a way to sanitize the database without clear the whole thing? What are the best practices to keep your Bayes database clean? Thanks, P.

All VBounce rules generate warnings

2008-05-06 Thread Alex Kiernan
I'm sure I'm missing something obvious, but I can't for the life of me spot it. Whenever the VBounce rules fire, I'm getting loads of warnings of this ilk: May 6 11:59:11 spamassistant.internal.thus.net spamd[24000]: no meta_dependencies defined for __BOUNCE_AUTO_GENERATED at /usr/perl5/site_perl