trust SMTP authenticated users

2009-04-25 Thread Arthur Kerpician
Hi, I'm facing the following problem lately. Some of my users are connecting to the mail server (qmail) through mobile phones and the leased IPs from the GSM operator are blacklisted in spamhaus and spamcop. So, they are using the smtp server with spamassassin 3.2.5 but their messages are mark

Re: bayes learn best practice

2009-04-14 Thread Arthur Kerpician
Kai Schaetzl wrote: Arthur Kerpician wrote on Thu, 09 Apr 2009 20:25:42 +0300: . So from time to time I should feed ham manually to sa-learn, until it reaches the spam level again. Is this correct? If it is, I think it's rather time-consuming to always check the trained ham/spam and

Re: bayes learn best practice

2009-04-09 Thread Arthur Kerpician
Kai Schaetzl wrote: Arthur Kerpician wrote on Thu, 09 Apr 2009 09:41:22 +0300: The docs mention that after 5000 spam and ham learned, spamassassin doesn't improve spam detection much. do they? What is meant is that once you reach some threshold the detection rate doesn't

bayes learn best practice

2009-04-08 Thread Arthur Kerpician
Hi, I recently upgraded to 3.2.5 and re-trained bayes db from scratch. The auto-learn is on so now I have about 6000 mails trained as spam and 3000 as ham. I tried to manually keep both spam and ham at the same level in the bayes db but it seems that spamassassin is learning spam twice as fast

Re: New kind of spam part 2

2009-04-01 Thread Arthur Kerpician
Chris wrote: Scored as this on my home box: pts rule name description -- -- 2.0 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net [Blocked - see

New kind of spam part 2

2009-03-31 Thread Arthur Kerpician
Hi, I've been following the latest messages on this list regarding new types of spam but, unfortunately, couldn't find the answer for the kind i'm dealing with. The raw mesage can be found here: http://www.bluechip.ro/spam.txt This type of spam has always 3 parts: plain text, html and a PNG at

Local domains

2008-05-14 Thread Arthur Kerpician
e hosting server which returns SPF_FAIL. Thanks for any suggestions. -- Arthur Kerpician BlueChip Computers Srl Constanta - Romania tel/fax +40 241 554.122 [EMAIL PROTECTED] www.bluechip.ro

Re: Attachement name test

2005-09-09 Thread Arthur Kerpician
Loren Wilton wrote: This is completely untested, but something along these lines might work for you. header __BOGUS_SENDERFrom =~ /[EMAIL PROTECTED]/i full__ATTACH_HDR/\nContent-Type\:.{0,100}\sname=\".{1,50}\.pps\"/is metaBLOCK_STUPID_PPS__BOGUS_SENDER && __ATTACH_HDR score

Re: Attachement name test

2005-09-08 Thread Arthur Kerpician
Matt Kettler wrote: Arthur Kerpician wrote: Realistically it will be significantly easier to do this in qmail-scanner. Blocking a specific filename is just as easy as blocking an extension. Just edit your quarantine-attachments.txt. There's examples in there of blocking by com

Re: Attachement name test

2005-09-08 Thread Arthur Kerpician
Matt Kettler wrote: At 06:27 AM 9/8/2005, Arthur Kerpician wrote: Hi, I'm pretty new in writing custom SA rules and I was wondering how can I check if a message has an attachement with a specific extension (eg .pps). What I'm trying to do is to tag as spam messages that

Attachement name test

2005-09-08 Thread Arthur Kerpician
Hi, I'm pretty new in writing custom SA rules and I was wondering how can I check if a message has an attachement with a specific extension (eg .pps). What I'm trying to do is to tag as spam messages that have .pps attachements and are coming from one e-mail address. I don't want to block all