Re: Honeypot email addresses

2015-01-07 Thread Noel Butler
On 08/01/2015 05:23, Alex wrote: I have an old domain with a number of dormant accounts that I'd like to use. The domain also uses several RBLs, so a majority of the spam is rejected before it's ever received, so it's less than effective. You need to whitelist at least the trap addresses to b

Re: Honeypot email addresses

2015-01-07 Thread Reindl Harald
Am 07.01.2015 um 20:23 schrieb Alex: I'm also wondering what exactly you're taking from these messages that are received? Are you blocking based on IP? Creating header/body rules? Those are usually transferable to other systems, but what about bayes? How can you use it for bayes when that doesn'

Re: Honeypot email addresses

2015-01-07 Thread Alex
Hi, I was hoping it was okay to resurrect a thread from a few months ago and ask a few questions regarding creating some type of honeypot for spammers. > Just search your /var/log/maillog for user unknown messages, and > create email addresses for the unknown users which are showing up > multiple

Re: SPF_HELO_PASS,SPF_NONE

2015-01-07 Thread Reindl Harald
Am 07.01.2015 um 16:27 schrieb RW: On Wed, 07 Jan 2015 15:01:56 +0100 Reindl Harald wrote: Am 07.01.2015 um 14:47 schrieb Matus UHLAR - fantomas: what if there would be SPF_HELO_FAIL? SA would not be called at all Maybe you could disable checking SPF_HELO, but some of us don't want that.

Re: SPF_HELO_PASS,SPF_NONE

2015-01-07 Thread RW
On Wed, 07 Jan 2015 15:01:56 +0100 Reindl Harald wrote: > > Am 07.01.2015 um 14:47 schrieb Matus UHLAR - fantomas: > > what if there would be SPF_HELO_FAIL? > > SA would not be called at all > > > Maybe you could disable checking SPF_HELO, but some of us don't > > want that. > > the question i

Re: SPF_HELO_PASS,SPF_NONE

2015-01-07 Thread Reindl Harald
Am 07.01.2015 um 14:47 schrieb Matus UHLAR - fantomas: what if there would be SPF_HELO_FAIL? SA would not be called at all Maybe you could disable checking SPF_HELO, but some of us don't want that. the question is who are "some" and who are the majority you can even socre "SPF_HELO_SOFTFAI

Re: SPF_HELO_PASS,SPF_NONE

2015-01-07 Thread Matus UHLAR - fantomas
Am 06.01.2015 um 21:31 schrieb Marieke Janssen: policyd-spf[11818]: None; identity=mailfrom; client-ip=213.145.228.32; helo=host5.ssl-gesichert.at; envelope-from=kundeninfo-return-1-***@domaintechnik.at; receiver=*** $ dig txt +short host5.ssl-gesichert.at "v=spf1 mx a ~all" Seems it works as