Re: More Sendgrid trouble?

2025-05-08 Thread John Levine
ake, at least for any mail system in this millenium. R's, John

Re: Deprecated Perl support from Maxmind

2025-03-12 Thread John Hardin
make it look like an abandoned module is available and in use when it is not isn't a precedent we want to set. That way lies madness. +1 Agree. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org

Re: French spam passed all SA tests with flying colors

2025-03-06 Thread John Hardin
out moment à ce traitement à des fins de marketing. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822

Re: Spam body template with diacritics and variants

2025-03-05 Thread John Hardin
amples are always welcome. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6

Re: bayes/txrep questions

2025-02-14 Thread John Hardin
t already hit bayes99 (and bayes999) but are still just shy of 5 points. I use local metarules that include BAYES_999 + other hits like URIBL to add extra points. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@

Re: off topic, Request for Whitelisting or Spam Score Adjustment for our TDL Domain

2025-02-13 Thread John Levine
It appears that John Hardin said: >> PS: If this leads to questions like "what exactly was the point of the >> thousand new TLDs?" >> you're not the only one asking. > >ICANN monetizing their product. Period. Actually, if you look at ICANN's financ

Re: AW: Request for Whitelisting or Spam Score Adjustment for our TDL Domain

2025-02-13 Thread John Hardin
ional damage from the abusers infesting the .online domain. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873

Re: Request for Whitelisting or Spam Score Adjustment for our TDL Domain

2025-02-13 Thread John Hardin
On Thu, 13 Feb 2025, John Levine wrote: It appears that wissen.online | Stefan Mehlhorn said: Are there any specific configurations or adjustments we can make to lower the high spam score of our emails? Or can you put us on one of your global whitelists for trusted .online domains? I doubt

Re: Request for Whitelisting or Spam Score Adjustment for our TDL Domain

2025-02-13 Thread John Levine
The .online TLD is full of garbage, and spamassassin is not the only spam filter to treat it as highly suspicious. If you want people to accept your mail, send it from a TLD that isn't awful. I'm guessing that wissen.online is the same company as wissenonline.de. That domain should

Re: zellepay now seeing forwarding phishing

2025-02-12 Thread John Hardin
On Tue, 11 Feb 2025, Kris Deugau wrote: John Hardin wrote: On Mon, 10 Feb 2025, John Hardin wrote: I just got a forwarded-via-outlook phish for zellepay that looks just like the paypal phishes... Ah, not *quite* the same. Zellepay doesn't have their own MTA infrastructure, so i

Re: zellepay now seeing forwarding phishing

2025-02-10 Thread John Hardin
On Mon, 10 Feb 2025, John Hardin wrote: I just got a forwarded-via-outlook phish for zellepay that looks just like the paypal phishes... Ah, not *quite* the same. Zellepay doesn't have their own MTA infrastructure, so it's a *little* less obvious. Initial rules checked in. -- J

zellepay now seeing forwarding phishing

2025-02-10 Thread John Hardin
I just got a forwarded-via-outlook phish for zellepay that looks just like the paypal phishes... "If you did not authorize this, please call us immediately at-I(888) 592-O36I to secure your account and recover your funds." Will add rules tonight. -- John Har

Re: Fake paypal email triggers -7.5 USER_IN_DEF_DKIM_WL From: address is in the default DKIM

2025-02-08 Thread John Hardin
to make a difference unless the scores are set manually, which increases their FP risk. I'd ask all who are doing masschecks to review their corpora of Paypal messages to see whether these messages, and Paypal messages with obfuscated phone numbers, are misclassified as ham.

Re: Issue with Matching UTF-8 Anchor Text in URIDetail plugin

2025-02-02 Thread John Hardin
2}\x{E0}\x{B8}\x{B8}\x{E0}\x{B8}\x{97}\x{E0}\x{B8}\x{B1}\x{E0}\x{B8}\x{99}\x{E0}\x{B8}\x{97}\x{E0}\x{B8}\x{B5}' =~ /(?^aa:\x{E0}\x{B8}\x{95})/ (does not match) You should probably open a bug with your rule and attach the spample. -- John Hardin KA7OHZhttp://www.im

Re: Issue with Matching UTF-8 Anchor Text in URIDetail plugin

2025-02-01 Thread John Hardin
}\\x{B8}\\x{97}\\x{E0}\\x{B8}\\x{B1}\\x{E0}\\x{B8}\\x{99}\\x{E0}\\x{B8}\\x{97}\\x{E0}\\x{B8}\\x{B5}/ ...do you alwo need to escape the curlies? /\\x\{E0\}\\x\{B8\} etc... -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk

Re: mailspike dot net Minus 1?

2025-01-19 Thread John Hardin
and I can't really see why apart from it not appearing in 50_scores.cf, and at the moment I don't want to go spelunking in the code to verify that's the override... -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org

Re: [External] Patterns for list broker spam?

2025-01-17 Thread John Levine
It appears that Kevin A. McGrail said: >John, Are you using the KAM ruleset?  We have several list/data broker >rules and list them in the RBL quite regularly Hm, I thought I was but now I see I had spamd looking at an old version of spamassassin. Oops. >On 1/17/2025 1:58 PM, Jo

RE: Patterns for list broker spam?

2025-01-17 Thread John R Levine
is as -all Throwaway account == actual Gmail or Outlook account. Their SPF and DKIM all validate. Regards, John Levine, jo...@taugh.com, Taughannock Networks, Trumansburg NY Please consider the environment before reading this e-mail. https://jl.ly

Patterns for list broker spam?

2025-01-17 Thread John Levine
Every day I get a bunch of spam from fake list brokers, invariably from throwaway Gmail or Outlook accounts. The text in them seems fairly consistent. Anyone have patterns to catch them? They're quite annoying since they're hard to separate from the legit mail we get from giant mail systems.

Re: [External] SA 4.0.1 - util_rb_3tld

2025-01-11 Thread John Hardin
ardless of subdomain is an excessively broad response. FYI, ct.sendgrid.net has been in the base ruleset util_rb_3tld since April 2021. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB87

Re: SA 4.0.1 Bayes in SQL: MYSQL_OPT_RECONNECT is deprecated

2025-01-10 Thread John Wilcock
Le 10/01/2025 à 15:35, Bill Cole a écrit : On 2025-01-10 at 08:49:04 UTC-0500 (Fri, 10 Jan 2025 14:49:04 +0100) John Wilcock is rumored to have said: Hi all, I'm using Spamassassin 4.0.1 on Gentoo and I've recently switched to using MySQL (actually Mariadb 10.6) for Bayes stor

SA 4.0.1 Bayes in SQL: MYSQL_OPT_RECONNECT is deprecated

2025-01-10 Thread John Wilcock
ished Jan 10 14:45:02.884 [15474] dbg: bayes: found bayes db version 3 I see no sign of a reconnect option being used in BayesStore/MySQL.pm I know it's only a warning; everything appears to work anyway. Any ideas? -- John

Re: Google url redirect ?

2024-12-26 Thread John Hardin
le mailbox file containing multiple messages - that's 46 individual email files in one zip or gz archive), but that's not a requirement. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key

Re: Google url redirect ?

2024-12-25 Thread John Hardin
to me directly for review, if we're missing new variants or some Google domains that would help us improve our coverage. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 --

Re: Patch to improve detection of offering SEO spam

2024-12-14 Thread John Hardin
ll be happy to back out those changes if consensus is they aren't reasonable. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org

Re: Patch to improve detection of offering SEO spam

2024-12-13 Thread John Hardin
PNTLD && (__PDS_SEO1 + __PDS_SEO2 >= 1) tflags SEO_SUSP_NTLD publish I don't know whether Paul is still actively maintaining his rule sandbox, his last commit there was four years ago. The changes seems reasonable, I'll apply them. -- John Hardin KA7OHZ

Re: moderately personalized spam sneaking past my SA. general approaches to fix it?

2024-11-21 Thread John Hardin
usual TLDs there as well... I will see about adding that to my sandbox tonight or tomorrow, but no guarantees on how it will do in masschecks. It might also be time to update my phishing phrases rules... Feel free to send me an archive of spamples if you like. -- John Hardin KA7OHZ

Re: docusign fraud using docusign

2024-11-10 Thread John Hardin
stead informational score 0.0001, ALL_TRUSTED is used in metas. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873

Re: blocking compute-1.amazonaws.com

2024-10-11 Thread John Hardin
reverse lookup of the sender's IP and whitelist/blacklist for domain names from that so you block the sender at SMTP time. Don't get tunnel vision about SpamAssassin being the only tool available for this sort of thing... :) -- John Hardin KA7OHZhttp://www.

Re: Whitelist or BAYES?

2024-09-26 Thread John Hardin
On Thu, 26 Sep 2024, joe a wrote: So, on the one hand I can add them to whitelist and be done with it, or I can add them to missed HAM for re-learning. Which is the best approach? Do both. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org

Re: Bayes in V4 compared to V3

2024-09-13 Thread John Hardin
On Fri, 13 Sep 2024, Bill Cole wrote: Please send any replies to the list only. ...or to Harald only. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C

Re: CC: address matches To: address

2024-07-13 Thread John Hardin
e the links directly rather than providing the pastebin links publicly here on the list. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873

Re: ChatGPT > Spamassassin? :)

2024-06-25 Thread John Hardin
illing to bring that code up-to-date and figure out what was needed and corpora providers were available. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4

Re: Where are your test definitions?

2024-06-14 Thread John Hardin
a look at config "report_safe 0". -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76

Re: Warning: Your Pyzor may be broken.

2024-06-09 Thread John Hardin
ffectively maintained"? -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822

Re: DKIM length 'l=' tag

2024-06-03 Thread John Levine
l validate. Other than that I don't think it's a strong spam indicator but there's no reason to try and guess whether a message with a length that doesn't cover the full body has been modified maliciously. R's, John

Re: Score 0.001

2024-05-10 Thread John Hardin
time based on the corpora. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873 2E79 ---

Re: Reporting Spam to csa-complai...@eco.de

2024-03-01 Thread John Levine
ts: csa-complai...@eco.de header, which looks legit. > >Has anyone had success with reporting mail to this address?  Does it get >results? ECO is real and I've found it worthwhile to report spam to them. R's, John

Re: Question about forwarding email (not specifically SA, pointers greatly appreciated)

2024-01-19 Thread John Hardin
explain to the board members I'm helping out is... painful. Very simply worded step by step instructions, with screenshots amended with arrows, outlines, highlights and so forth as needed. ...the .sigmonster agrees. -- John Hardin KA7OHZhttp://www.impsec.org/~jh

Re: Dinged for .Date

2024-01-15 Thread John Hardin
7;t suffer the TLD reputational hit. (If you do that, avoid setting "ReplyTo: supp...@play.date", as that would also take a reputation hit.) -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec

Re: Too many dots?

2023-11-16 Thread John Hardin
that all that rule does, vs. hitting *specific* SendGrid accounts? -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6

Re: when whitelisting, do what with marked SPAM?

2023-11-15 Thread John Hardin
, learning as few mail as one should fix BAYES issues. Move previously tagged SPAM into HAM folder and "relearn"? Right. Train on misclassifications. Also if there was a ham in your spam corpus review why it got misclassified in the first place. -- John Hardin KA7OHZ

Re: when whitelisting, do what with marked SPAM?

2023-11-14 Thread John Hardin
uot;Missed SPAM"?, thinking along lines of keeping BAYES "clean and sharp". So to speak. Leave as is? Delete and re learn? For a low volume home office user, I would simply NOT autolearn. Set up a hambox and a spambox and manually feed them and train from them. -- John Hardin

Re: external API request

2023-10-27 Thread John Hardin
ven't even seen the email at this stage) or indeed doing something they do not want. It doesn't sound like it will *visit* the link, just ask some service if the like has a reputation. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org

Re: STY_INVIS_DIRECT

2023-10-02 Thread John Hardin
is pushing a lot of Email into "Junk folders", for now I'ma change that score to 0.25 2.5 points by itself shouldn't be enough to quarantine/junk messages. What else is spammy about those messages? -- John Hardin KA7OHZhttp://www.

Re: Stealth HREF= (missed by SA)

2023-09-17 Thread John Hardin
/<[a-z]{1,10}\s[^>]{1,80}\/(src|href)\s*\=/ -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F50

Re: new rule for kam :)

2023-08-24 Thread John Hardin
also hit __HAS_X_AUTHED_SENDER; 19% of __HAS_X_AUTHED_SENDER hits also hit __HREF_EMPTY (ham 1%) I'll add a few of those to see how they do. F'ing legit emailers that generate crap HTML {fume} -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@i

Re: new rule for kam :)

2023-08-23 Thread John Hardin
SRC_EMPTY score LOCAL_BADLY_HTML 3 3 3 3 too much spams in hotmail I'll put the subrules in my sandbox so they can be evaluated by masscheck. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key:

Re: new rule for kam :)

2023-08-23 Thread John Hardin
It wouldn't be much of a loss, but it's not spam either. How did they perform individually? -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8

Re: My apologies

2023-08-03 Thread John Hardin
like that, as a newbie mailing list member, looking for help, I humbly submit that he's not someone you want being the first interaction a new list member has. Sadly, we cannot control that. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org

Re: Welcome/unwelcome list not working correctly.

2023-07-20 Thread John Hardin
olumn headers would aid analysis. Can you swap the numbers in the 4th column and see if that changes the behavior? -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411

Re: Help with rule

2023-06-06 Thread John Hardin
fic senders coming from specific IP addresses, there's already built-in features for that. Look into whitelist_from_rcvd, it may do exactly what you want. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...

Re: 0 score not voiding rule

2023-05-27 Thread John Hardin
u also add: USER_IN_WHITELIST 0 They are synonyms, might need to kill both explicitly. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6

RE: comparing sender domain against recipient domain

2023-05-13 Thread John Hardin
a more general solution, but this might be quite useful. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822

Re: comparing sender domain against recipient domain

2023-05-13 Thread John Hardin
On Sat, 13 May 2023, Matus UHLAR - fantomas wrote: But I was more interested if SA already has something like that? It does not. On Fri, 12 May 2023, Loren Wilton wrote: Weren't there a whole set of "FUZZY" rules once? On 12.05.23 20:01, John Hardin wrote: There still

Re: comparing sender domain against recipient domain

2023-05-12 Thread John Hardin
On Fri, 12 May 2023, Loren Wilton wrote: But I was more interested if SA already has something like that? It does not. Weren't there a whole set of "FUZZY" rules once? There still are. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jha

Re: comparing sender domain against recipient domain

2023-05-12 Thread John Hardin
On Fri, 12 May 2023, Matija Nalis wrote: I wonder if someone has already done it, and something sufficiently similar to be used to that purpose? There are a lot of ReplaceTags rules in the base ruleset. I don't know if offhand that works with header rules. -- John Hardin K

Re: parameters: use_pyzor and use_razor2

2023-04-29 Thread John Hardin
: config: failed to parse line in (sql config) (line 9): use_pyzor\t0 info: config: not parsing, administrator setting: use_razor2\t0 info: config: failed to parse line in (sql config) (line 10): use_razor2\t0 ... in SQL config? perhaps the lines are misplaced? -- John Hardin KA7OHZ

Re: replay RBL queries one hour later

2023-02-25 Thread John Hardin
me, for example commercial accounts where you don't want a delay in receiving communications from customers or potential customers. There are ways to tune it that may mitigate these concerns somewhat. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/

Re: DecodeShortURL fails with postgresql

2023-01-29 Thread John Hardin
, i just report it This bit: WHERE short_url $1 = AND ...should probably be: WHERE short_url = $1 AND The basic expression syntax of SQL is the same as other (infix!) languages.. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org

Re: bz 8116

2023-01-28 Thread John Hardin
trashed. Poof, gone. We don't sit watching our MUAs 24/7 -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873

Re: Rule Help - not sure what is wrong with my syntax

2023-01-12 Thread John Hardin
On Thu, 12 Jan 2023, John Hardin wrote: On Thu, 12 Jan 2023, Martin Gregorie wrote: On Wed, 2023-01-11 at 18:39 -0500, Joey J wrote: Hello All, I created this rule to check for email addresses matching a list to get added some negative value. I also tried it with just domains so it

Re: Rule Help - not sure what is wrong with my syntax

2023-01-12 Thread John Hardin
There are instructions for setting such up for local blacklists, that works equally well for a local whitelist. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507

Re: Refused by block lists

2023-01-06 Thread John Hardin
e gateway to its external address." I think you're getting distracted by the word "resolve" there... This sounds like a DNS issue. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org

Re: Re: Re: Re: Re: DNSWL_HI testing wrong Received header?

2022-12-28 Thread John Hardin
On Wed, 28 Dec 2022, Matus UHLAR - fantomas wrote: On 28.12.22 12:55, John Stimson via users wrote: The machine has bind9 running locally to provide DNS for its own domain, and uses it for name resolution.  This is the problem: Bind9 is configured to use OpenDNS and Google as forwarders

RE: Re: Re: Re: Re: DNSWL_HI testing wrong Received header?

2022-12-28 Thread John Stimson via users
On 2022/12/28 15:09:36 Matus UHLAR - fantomas wrote: > spamassassin service is not needed when you use amavis, you can stop and > disable it. Good to know. On 2022/12/28 15:09:36 Matus UHLAR - fantomas wrote: > >~amavis/.spamassassin contains a file user.prefs that has only comment > >lines.  Co

RE: Re: Re: Re: DNSWL_HI testing wrong Received header?

2022-12-28 Thread John Stimson via users
Updates: On 2022/12/28 12:45:48 Matus UHLAR - fantomas wrote: > have you reloaded amavisd? I restarted the amavisd-new.service and spamassassin.service after editing /etc/spamassassin/local.cf > do you have anything set in amavis' home directory? > usually ~amavis/.spamassassin ~amavis/.spa

RE: Re: Re: DNSWL_HI testing wrong Received header?

2022-12-27 Thread John Stimson via users
; On 27.12.22 13:04, John Stimson via users wrote: > >Thanks -- I found a mechanism that empties the list of headers used to > >determine the originating IP.  I added this line to my local.cf: > > > >clear_originating_ip_headers > > I recommend checki

RE: Re: DNSWL_HI testing wrong Received header?

2022-12-27 Thread John Stimson via users
On 2022/12/26 23:47:41 Benny Pedersen wrote: > X-Originating-Ip should not be used for whitelists, only for blacklist > rbl, even on only blacklist its unsafe to use, rules maintainers can > remove it, now that spamassassin 4.0.0 is out :) > > read "perldoc Mail::SpamAssassin::Conf" to see how th

RE: Re: DNSWL_HI testing wrong Received header?

2022-12-27 Thread John Stimson via users
the error and perhaps even figure out why the standard ubuntu package doesn't do this correctly. On 2022/12/26 23:02:30 Benny Pedersen wrote: > John Stimson via users skrev den 2022-12-26 21:44: > > > My second question is where to report an SMTP server that passes SPF, >

DNSWL_HI testing wrong Received header?

2022-12-26 Thread John Stimson via users
Hello, I have lately seen an increase in the number of spam messages passing spamassassin.  Checking the X-Spam-Status header, I see that the common reason they are all passing is that they hit the DNSWL_HI test to get a -5 adjustment to their spam score. However, when I check the IP address

Re: Whitelist or add negative values for score

2022-12-22 Thread John Hardin
blacklist -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873 2E79

unsubscribe

2022-12-06 Thread John Ferguson via users
Micron Confidential Micron Confidential

Re: phishtank api usage from spamassassin ?

2022-08-26 Thread John Hardin
h. "Go away and stop bothering us." It's not the only place Google won't let you report problems from outside their ecosystem either - you can't report spam coming through Google Groups with the link in the messages without logging in to a Google account. I gave up tryi

Re: phishtank api usage from spamassassin ?

2022-08-25 Thread John Hardin
block all page.link, whois says its hosted by google :/ go ahead.. There are legitimate sites using that domain. I added it as a 2tld for URIBL, so please report such domains to URIBL. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org

Re: subscribe to blacklist for domains

2022-08-23 Thread John Hardin
tion tools available that would return much the same information, and that would give something helpful to discuss with the site admin when trying to resolve the situation. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org

Re: subscribe to blacklist for domains

2022-08-14 Thread John Hardin
On Sat, 13 Aug 2022, joe a wrote: Why waste your own system resources to help a scoundrel? Drop them and be done. I personally perfer to TCP tarpit repeat offenders. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk

Re: Matching on missing To field?

2022-07-20 Thread John Hardin
that is "headers misspelled" (not "headers missing") MISSP = misspaced and it is checking for any of the listed words at the start of a line, followed by a colon, and NOT followed by a space. -- John Hardin KA7OHZhttp://www.impsec.org/~jha

Re: shit from serverion

2022-06-29 Thread John Hardin
about posting it here so you do not need to do this work. If you do some random checks, you can see this looks weird[2]. Do as you please with this info. FYI, I'm rejecting them at the postfix level. *cough* TCP Tarpit *cough* -- John Hardin KA7OHZhttp://www.impsec.or

Re: Rule to detect non-standard headers that aren't X- prefixed

2022-05-11 Thread John Hardin
ba3e69a MIME-Version: 1.0 Capitalizations-Grievously: oilers Content-type: multipart/mixed; boundary="--=_1649731129-716331-86" Obviously, the following bogus header names are present: Minicomputers-Exhume Malthus-Films Parasitic-Homogeneity Capitalizations-Grievously Take

Re: OT - Hotmail/Outlook.com marking most of our email as Junk

2022-02-19 Thread John Hardin
naged by your provider and if a more than a few of them are listed (particularly by multiple DNSBLs) then your provider is probably problematic and you should look elsewhere. [Ooo, look, the .sigmonster is listening...] -- John Hardin KA7OHZhttp://www.impsec.org

Re: Regex error in most recent update

2022-02-18 Thread John Hardin
;s not universal, either. It passed lint here or I wouldn't have checked it in. It passed the masscheck lint or it wouldn't have been published. I've checked in a fix, there may be one more bad update tonight before it goes out. -- John Hardin KA7OHZ

Re: REMOVE

2022-02-18 Thread John Hardin
On Fri, 18 Feb 2022, da...@grmcompany.com wrote: Dan: The SA users mailing list is self-managed. list-unsubscribe: <mailto:users-unsubscr...@spamassassin.apache.org> -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@imps

Re: CONTENT_AFTER_HTML: better not discuss formatting!!

2022-02-08 Thread John Hardin
m matching delimiters from SA. I suspect there are at least hundreds of rules like that in the release database. I have about a hundred local rules of my own that use that. Indeed. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org

Re: CONTENT_AFTER_HTML: better not discuss formatting!!

2022-02-07 Thread John Hardin
No, I added that after observing multiple spams with random garbage after the closing HTML tag in the HTML body part. Presumably it was an attempt at Bayes poison, checksum avoidance, or some other filter evasion technique. I'll tighten it up. -- John Hardin KA7OHZ

Re: CONTENT_AFTER_HTML: better not discuss formatting!!

2022-02-07 Thread John Hardin
"htmlbody" rule type... -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873 2E79

Re: XM_RANDOM hits for Qi Mail Connector

2022-01-20 Thread John Hardin
Will update, thanks for the report. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873

Re: Managing long welcome_senders list

2021-12-02 Thread John Hardin
but that does have the downside of accepting spam from them if their account gets hacked, for example. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C A

Re: MIME_BASE64_TEXT only on us-ascii

2021-11-30 Thread John Hardin
correctness. Isn't that exactly what we're discussing here? "Technical correctness"? The way I generally put it is: SpamAssassin is not an RFC-compliance audit tool. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org

Re: SHOPIFY_IMG_NOT_RCVD_SFY but from Shopify

2021-11-18 Thread John Hardin
On Thu, 18 Nov 2021, Matt Corallo wrote: On 11/18/21 16:49, John Hardin wrote: On Thu, 18 Nov 2021, Matt Corallo wrote: I followed up on the exim-users list on this - Exim *did* verify the FcRDNS here and the above header line is what it generates by default for FcRDNS. The RFC quote they

Re: SHOPIFY_IMG_NOT_RCVD_SFY but from Shopify

2021-11-18 Thread John Hardin
ified that rule a bit to also look at the HELO and envelope From address to see if they are from Shopify. Granted that's less reliable than rDNS, but it's probably Good Enough. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org

Re: SHOPIFY_IMG_NOT_RCVD_SFY but from Shopify

2021-11-16 Thread John Hardin
NS is causing their mail to be considered spam. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507

Re: SHOPIFY_IMG_NOT_RCVD_SFY but from Shopify

2021-11-16 Thread John Hardin
On Mon, 15 Nov 2021, Matt Corallo wrote: Full headers follow, but it seems the shopify detection in the above isn't quite correct; Thanks for the report, will fix. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pg

Re: Seeing "check: exceeded time limit in ..." and need to resolve it

2021-11-16 Thread John Hardin
On Mon, 15 Nov 2021, Philip Prindeville wrote: On Nov 12, 2021, at 8:49 PM, John Hardin wrote: On Fri, 12 Nov 2021, Philip Prindeville wrote: I got the message, saved it to a flat file, and ran "spamassassin -t -D rules < netdev.eml" and saw: ... Nov 12 11:45:38.048 [3636

Re: Seeing "check: exceeded time limit in ..." and need to resolve it

2021-11-13 Thread John Hardin
ication to the timeout message could display the name of the rule and even how long it took to that point. That's what I was thinking when I said "capture and log". -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org

Re: Seeing "check: exceeded time limit in ..." and need to resolve it

2021-11-13 Thread John Hardin
On Sat, 13 Nov 2021, Henrik K wrote: On Fri, Nov 12, 2021 at 07:49:00PM -0800, John Hardin wrote: What would be helpful here would be logging of when a rule *starts* evaluation. Normally that would be painful, but for tracking a runaway it would be useful. Perhaps I can code up something to

Re: Seeing "check: exceeded time limit in ..." and need to resolve it

2021-11-12 Thread John Hardin
ode up something to capture that and log it on a timeout... If you want to send me that message zipped up I can try it here with those changes and see if it's a base rule running away. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org

Re: Unicode considered harmful again

2021-11-05 Thread John Hardin
=== And what of the BIDI sequence that actually causes the problem? All Of Unicode is not the problem. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 1

Re: timeouts on processing some messages, started October 24

2021-11-03 Thread John Hardin
can find a problematic rule by comparing that debug output from a bad message to that of a message which doesn't hang SA. There's also the HitFreqsRuleTiming plugin if you're running in a dev environment and can let it scan for a potentially long time (until completion). --

Re: Starting Clean with Bayes

2021-10-23 Thread John Hardin
On Sat, 23 Oct 2021, Benny Pedersen wrote: On 2021-10-20 16:58, John Hardin wrote: On Wed, 20 Oct 2021, Axb wrote: On 10/19/21 8:06 PM, Jerry Malcolm wrote: Where do I find a starter toks file? You don't need a "starter" file. Your Bayes starter is your training cor

  1   2   3   4   5   6   7   8   9   10   >