SA both at external and internal servers

2013-08-01 Thread N. Raghavendra
I work in a setup where the external mail server (say, extmail.example.com) in a DMZ runs Spamassassin as soon as mail arrives from the Internet, and then passes the mail to an internal mail server (say, intmail.example.com) which has user maildirs. The trouble is that the Spamassassin filtering a

Re: Creating new rules

2013-08-01 Thread RW
On Thu, 01 Aug 2013 19:08:12 +0200 Benny Pedersen wrote: > RW skrev den 2013-08-01 18:00: > > > If you use /32 and the sender has a different IP address each time > > there's no score averaging. > > servers changeing sender ip daily ?, its not a real problem clients > does, there would be one

Re: Creating new rules

2013-08-01 Thread Benny Pedersen
RW skrev den 2013-08-01 18:00: If you use /32 and the sender has a different IP address each time there's no score averaging. servers changeing sender ip daily ?, its not a real problem clients does, there would be one static ip first

Re: Creating new rules

2013-08-01 Thread RW
On Thu, 01 Aug 2013 16:36:22 +0200 Benny Pedersen wrote: > RW skrev den 2013-08-01 14:39: > > > This would make sense if the IP address were the the first trusted > > address or last external, but AWL uses the first routable address > > which > > is commonly dynamic. > > why is this in error ?

Re: Creating new rules

2013-08-01 Thread Benny Pedersen
RW skrev den 2013-08-01 14:39: This would make sense if the IP address were the the first trusted address or last external, but AWL uses the first routable address which is commonly dynamic. why is this in error ?

Re: Creating new rules

2013-08-01 Thread RW
On Thu, 01 Aug 2013 12:34:26 +0200 Benny Pedersen wrote: > Jari Fredriksson skrev den 2013-07-31 22:04: > > AWL plugin does it anyway, if enabled. But it does not use any > > external > > backlists for it... > > if its runs with default /16 is just a joke > > change it to /24 or /32 then its m

Re: Creating new rules

2013-08-01 Thread Franck Martin
On Aug 1, 2013, at 12:44 PM, Benny Pedersen wrote: > Franck Martin skrev den 2013-07-31 23:06: > >> Now as we move to IPv6, reputation will shift from an IP based type >> reputation, to a domain based type reputation. Unfortunately, spam >> assassin seems to be lacking some rules. > > still mi

Re: Spam trap email lists

2013-08-01 Thread Axb
On 08/01/2013 06:17 AM, Blason rock wrote: Hi Guys, Any luck? Does any one aware of any good spam trap email list? On Wed, Jul 31, 2013 at 12:03 PM, Blason rock wrote: Hey Fellas, I would like to have spam trap IDs built. So any one aware of such id spamassassin support where I can ask users

Re: Spam trap email lists

2013-08-01 Thread Benny Pedersen
Blason rock skrev den 2013-08-01 06:17: Any luck? Does any one aware of any good spam trap email list? use policyd v1 its simple, add recipient email that have never existed, and let policyd do the rest, grep never existed emails from logs, could be done if syslog is done to sql, then its ju

Re: Creating new rules

2013-08-01 Thread Benny Pedersen
Franck Martin skrev den 2013-07-31 23:06: Why would they use a forged domain which is on a blacklist? I think they would tend to use a domain which is well known with good reputation. As well known domains are getting protected, then they have to move to use their own domain, which happens to ap

Re: Creating new rules

2013-08-01 Thread Benny Pedersen
Jari Fredriksson skrev den 2013-07-31 22:04: 31.07.2013 21:05, Franck Martin kirjoitti: Ah yes, I saw these rules, but this is to check the domains of urls in the messages, not to check for instance that the domain used in the From: header is on the DBL. Address in From: is usually always forge