RE: Re[8]: rule based on domain age

2023-05-11 Thread Marc
> IP ranges and country connections are of no help. These criminals use > outlook, gmail, vps servers and everything under the sun. So they register new domains, link them to gmail (outlook) and send spam with envelope of the domain via the google network, and google does nothing and keeps givi

Re[8]: rule based on domain age

2023-05-10 Thread Tracy Greggs via users
uot; To "Tracy Greggs" ; "users@spamassassin.apache.org" Date 5/10/2023 4:57:21 PM Subject RE: Re[6]: rule based on domain age What I am targeting will not be on an abusive domains on any RBL anywhere as they buy these domains for the sole purpose of targeting our company

RE: Re[6]: rule based on domain age

2023-05-10 Thread Marc
> What I am targeting will not be on an abusive domains on any RBL > anywhere as they buy these domains for the sole purpose of targeting our > company and our clients. They only have to succeed once where I have to > succeed every time to keep them from stealing large sums. What about the ip r

Re[6]: rule based on domain age

2023-05-10 Thread Tracy Greggs via users
eggs" ; "users@spamassassin.apache.org" Date 5/10/2023 3:50:06 PM Subject RE: Re[4]: rule based on domain age Yes some already block/timeout with the 2nd lookup. But there is a flip side. There are dns blacklists that have domainnames that are currently being abused. I hadn

RE: Re[4]: rule based on domain age

2023-05-10 Thread Marc
Yes some already block/timeout with the 2nd lookup. But there is a flip side. There are dns blacklists that have domainnames that are currently being abused. > > I hadn't considered being blocked by the TLD's from doing the lookups. > Good point. We probably do about 2K per day so not sure tha

Re[4]: rule based on domain age

2023-05-10 Thread Tracy Greggs via users
23 3:32:05 PM Subject RE: Re[2]: rule based on domain age Why would it have to have to be specific per TLD? Why I have in mind is looking at the creation date of the sending domain and scoring it up if it is newer than 12 months, no matter what the TLD is. I totally get it. I was think

RE: rule based on domain age

2023-05-10 Thread Marc
> > My apologies if that has been asked and or answered previously. > > I would love to have a rule to score up messages from domains registered > in the past X configurable days. > > We rarely receive legit email from domains newer than 1 year old, but we > get spoofs daily from domains that a

rule based on domain age

2023-05-10 Thread Tracy Greggs via users
My apologies if that has been asked and or answered previously. I would love to have a rule to score up messages from domains registered in the past X configurable days. We rarely receive legit email from domains newer than 1 year old, but we get spoofs daily from domains that are less than 1

Re: Today's Google Docs phish (domain age)

2017-05-04 Thread Benny Pedersen
Noel Butler skrev den 2017-05-04 12:45: The SEM fresh* uri lists I dare say. it could be core part of spamassassin, why ?, since spammers avoid sending it to sem, and not all new domains come to sem before its depricatd spam campains :/ who will make it to sa core ? sad to see your mail

Re: Today's Google Docs phish (domain age)

2017-05-04 Thread Noel Butler
On 04/05/2017 17:38, Merijn van den Kroonenberg wrote: >> On Wed, 3 May 2017, Alex wrote: >> That target domain "g-docs . pro" was registered 12 days ago via >> namecheap.com >> which was enough to earn it a few extra points at our site. > > How do you

Re: Today's Google Docs phish (domain age)

2017-05-04 Thread Merijn van den Kroonenberg
time? > > That target domain "g-docs . pro" was registered 12 days ago via > namecheap.com > which was enough to earn it a few extra points at our site. How do you detect the domain age in SA? I am really interested in a domain age solution if its out there. > > It&#

Re: Domain Age

2014-06-05 Thread Axb
On 06/05/2014 03:22 PM, Andreas Schulze wrote: Hello, today we came up with the idea to look at the domain age. It may be a criteria for otherwise perfect messages. Is there something I could ask with a domainname and receive the age as answer? We've been there a few days ago See t

Re: Domain Age

2014-06-05 Thread Kevin A. McGrail
On 6/5/2014 9:22 AM, Andreas Schulze wrote: today we came up with the idea to look at the domain age. It may be a criteria for otherwise perfect messages. Is there something I could ask with a domainname and receive the age as answer? Hi Andreas, I believe you should look at RCVD_IN_DOB

Re: Domain Age

2014-06-05 Thread Matthias Leisi
On Thu, Jun 5, 2014 at 3:22 PM, Andreas Schulze wrote: > Is there something I could ask with a domainname and receive the age as > answer? http://support-intelligence.com/dob/ Which domain would you be interested in? MAIL FROM, From:, Body URL-domain, ...? -- Matthias

Domain Age

2014-06-05 Thread Andreas Schulze
Hello, today we came up with the idea to look at the domain age. It may be a criteria for otherwise perfect messages. Is there something I could ask with a domainname and receive the age as answer? Andreas

Re: .cn domain age query?

2009-09-14 Thread Blaine Fleming
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Let's try this again with sending to the list. Sorry Mike! Mike Cardwell wrote: > That wouldn't help in this particular case: > > "All domains registered in the last 5 days under the .BIZ, .COM, .INFO, > .NAME, .NET and .US TLDs" > > Doesn't work f

Re: .cn domain age query?

2009-09-14 Thread Karsten Bräckelmann
On Mon, 2009-09-14 at 19:51 +0100, UxBoD wrote: > - "Karsten Bräckelmann" wrote: > | grep _DOB *.cf# Part of the stock rule-set. > > How dumb me be ;) Thanks Karsten :D Heh, no problem. :) Just figured I should spare you the time of adding it, and prevent you from scoring twice. -- c

Re: .cn domain age query?

2009-09-14 Thread --[ UxBoD ]--
- "Karsten Bräckelmann" wrote: | On Mon, 2009-09-14 at 18:55 +0100, --[ UxBoD ]-- wrote: | > | Still working fine for me here, 51 hits so far today against DOB. | > | > Not come across that RBL before! Thanks :) | | grep _DOB *.cf# Part of the stock rule-set. | | | -- | char | *t="\1

Re: .cn domain age query?

2009-09-14 Thread Karsten Bräckelmann
On Mon, 2009-09-14 at 18:55 +0100, --[ UxBoD ]-- wrote: > | Still working fine for me here, 51 hits so far today against DOB. > > Not come across that RBL before! Thanks :) grep _DOB *.cf# Part of the stock rule-set. -- char *t="\10pse\0r\0dtu...@ghno\x4e\xc8\x79\xf4\xab\x51\x8a\x10\xf4\xf

Re: .cn domain age query?

2009-09-14 Thread John Hardin
On Mon, 14 Sep 2009, Mike Cardwell wrote: Chris Owen wrote: http://spameatingmonkey.com/lists.html They will tell you domains that are 5, 10 and 15 days old. That wouldn't help in this particular case: "All domains registered in the last 5 days under the .BIZ, .COM, .INFO, .NAME, .NET a

Re: .cn domain age query?

2009-09-14 Thread Mike Cardwell
Chris Owen wrote: One thing they all have in common is their registration dates are very young according to whois lookups. It seems in general if we had a reliable way to lookup domain age we might be able to differentiate spam. What's the current status of the Day Old Bread BL? H

Re: .cn domain age query?

2009-09-14 Thread --[ UxBoD ]--
- "Bill Landry" wrote: | > On Mon, 14 Sep 2009, Warren Togami wrote: | > | >> One thing they all have in common is their registration dates are | very | >> young according to whois lookups. It seems in general if we had a | >> reliable way to loo

Re: .cn domain age query?

2009-09-14 Thread Chris Owen
On Sep 14, 2009, at 12:41 PM, John Hardin wrote: On Mon, 14 Sep 2009, Warren Togami wrote: One thing they all have in common is their registration dates are very young according to whois lookups. It seems in general if we had a reliable way to lookup domain age we might be able to

Re: .cn domain age query?

2009-09-14 Thread Bill Landry
> On Mon, 14 Sep 2009, Warren Togami wrote: > >> One thing they all have in common is their registration dates are very >> young according to whois lookups. It seems in general if we had a >> reliable way to lookup domain age we might be able to differentiate >>

Re: .cn domain age query?

2009-09-14 Thread John Hardin
On Mon, 14 Sep 2009, Warren Togami wrote: One thing they all have in common is their registration dates are very young according to whois lookups. It seems in general if we had a reliable way to lookup domain age we might be able to differentiate spam. What's the current status of th

.cn domain age query?

2009-09-14 Thread Warren Togami
ry rarely see them repeat from one spam to the next. One thing they all have in common is their registration dates are very young according to whois lookups. It seems in general if we had a reliable way to lookup domain age we might be able to differentiate spam. Is there any good way to quer