Re: More fake order spam

2021-04-27 Thread John Hardin
On Tue, 27 Apr 2021, @lbutlr wrote: On 27 Apr 2021, at 11:57, Steve Dondley wrote: On 2021-04-27 01:19 PM, Dave Wreski wrote: Invalid List-ID. You can then use that with other weirdness in a meta. header__LIST_ID_DOMAIN_IN_BRACKETS List-id =~ /<([\w-]+)(\.[\w-]+)+>/ meta LIST_ID_IMPROPE

Re: Bad entries in HOSTKARMA_W

2021-04-27 Thread John Hardin
On Tue, 27 Apr 2021, Ted Mittelstaedt wrote: My guess is if you contact the admin of hostkarma directly and offer to host a honeypot he might take you up on it. But that still won't give you the ability to change anything in the database. I cannot imagine trusting a RBL that allowed any huma

Re: More fake order spam

2021-04-27 Thread @lbutlr
On 27 Apr 2021, at 11:57, Steve Dondley wrote: > On 2021-04-27 01:19 PM, Dave Wreski wrote: >> Invalid List-ID. You can then use that with other weirdness in a meta. >> header__LIST_ID_DOMAIN_IN_BRACKETS List-id =~ /<([\w-]+)(\.[\w-]+)+>/ >> meta LIST_ID_IMPROPER_FORMAT __HAS_LIST_ID && !__L

Re: Bad entries in HOSTKARMA_W

2021-04-27 Thread Ted Mittelstaedt
My guess is if you contact the admin of hostkarma directly and offer to host a honeypot he might take you up on it. But that still won't give you the ability to change anything in the database. I cannot imagine trusting a RBL that allowed any humans to blacklist something. Whitelisting is dif

Bad entries in HOSTKARMA_W

2021-04-27 Thread Greg Troxel
I have generally been a fan of the HOSTKARMA DNSBL over the long term. Fuzzy memeory is that the operator was responsive and reaasonable. Long ago (2014) I complained somewhat generally about spamassassin's DNSBL inclusion policy, and was (quite reasonably) asked for specifics. This report is te

Re: More fake order spam

2021-04-27 Thread Steve Dondley
On 2021-04-27 03:03 PM, Dave Wreski wrote: Invalid List-ID. You can then use that with other weirdness in a meta. header    __LIST_ID_DOMAIN_IN_BRACKETS List-id =~ /<([\w-]+)(\.[\w-]+)+>/ meta   LIST_ID_IMPROPER_FORMAT __HAS_LIST_ID && !__LIST_ID_DOMAIN_IN_BRACKETS score  LIST_ID_IMPROPER_FORM

Re: More fake order spam

2021-04-27 Thread Dave Wreski
Invalid List-ID. You can then use that with other weirdness in a meta. header    __LIST_ID_DOMAIN_IN_BRACKETS List-id =~ /<([\w-]+)(\.[\w-]+)+>/ meta   LIST_ID_IMPROPER_FORMAT __HAS_LIST_ID && !__LIST_ID_DOMAIN_IN_BRACKETS score  LIST_ID_IMPROPER_FORMAT 0.001 describe LIST_ID_IMPROPER_FORMAT

Re: More fake order spam

2021-04-27 Thread Dave Wreski
Hi, Investigate adding the SEM_FRESH rules - this domain was created less than five days ago. https://spameatingmonkey.com/services OK, how do I get those rules installed? I've only installed KAM rules using a channel. I don't see anything similar for SEM rules. I see the page you linked to

Re: More fake order spam

2021-04-27 Thread Steve Dondley
On 2021-04-27 02:23 PM, Reindl Harald wrote: Am 27.04.21 um 19:57 schrieb Steve Dondley: On 2021-04-27 01:19 PM, Dave Wreski wrote: Investigate adding the SEM_FRESH rules - this domain was created less than five days ago. https://spameatingmonkey.com/services OK, how do I get those rules inst

Re: More fake order spam

2021-04-27 Thread Steve Dondley
On 2021-04-27 01:19 PM, Dave Wreski wrote: -2.5 RCVD_IN_HOSTKARMA_W    RBL: Sender listed in HOSTKARMA-WHITE [185.41.28.7 listed in hostkarma.junkemailfilter.com] We've reduced this score to -1 locally. -1.0 BAYES_00   BODY: Bayes spam probability is 0 t

Re: More fake order spam

2021-04-27 Thread Greg Troxel
Steve Dondley writes: > On 2021-04-27 01:12 PM, Greg Troxel wrote: >> As always, if you have a problem stemming from a dns-based or similar >> reputation list, you need to report problems to those lists. >> >> If you aren't running greylisting with aggressive delays for SBL/XBL >> and >> moderat

Re: data-saferedirecturl WTF?

2021-04-27 Thread Bill Cole
On 21 Apr 2021, at 11:45, Kris Deugau wrote: Can anyone point me to a reference document describing what the "data-saferedirecturl" attribute on an tag is supposed to be useful for, and for bonus points any hints why it can't be trivially and horribly abused by scammers? Most of the search

Re: More fake order spam

2021-04-27 Thread Steve Dondley
On 2021-04-27 01:12 PM, Greg Troxel wrote: As always, if you have a problem stemming from a dns-based or similar reputation list, you need to report problems to those lists. If you aren't running greylisting with aggressive delays for SBL/XBL and moderate for dialup, do that too. What does "

Re: More fake order spam

2021-04-27 Thread Dave Wreski
-2.5 RCVD_IN_HOSTKARMA_W    RBL: Sender listed in HOSTKARMA-WHITE [185.41.28.7 listed in hostkarma.junkemailfilter.com] We've reduced this score to -1 locally. -1.0 BAYES_00   BODY: Bayes spam probability is 0 to 1% Needs to be trained, obviously. Ba

Re: More fake order spam

2021-04-27 Thread Benny Pedersen
On 2021-04-27 18:51, Steve Dondley wrote: Got this: https://pastebin.com/Gfz951dh Spam report: Content analysis details: (-2.3 points, 5.0 required) pts rule name description -- -- -2.5 RCVD_IN_HOSTKARMA

Re: More fake order spam

2021-04-27 Thread Greg Troxel
As always, if you have a problem stemming from a dns-based or similar reputation list, you need to report problems to those lists. If you aren't running greylisting with aggressive delays for SBL/XBL and moderate for dialup, do that too. signature.asc Description: PGP signature

More fake order spam

2021-04-27 Thread Steve Dondley
Got this: https://pastebin.com/Gfz951dh Spam report: Content analysis details: (-2.3 points, 5.0 required) pts rule name description -- -- -2.5 RCVD_IN_HOSTKARMA_WRBL: Sender listed in HOSTKARMA-WHITE