Re: [SidePost] Re: [TopPost] RE: [SA-LIST] RE: Subject line

2004-09-15 Thread mike
Since this thread is so wack... I was at volunteer call for the austin city limits festival and 6 or seven people said that the emails from the coordinators were getting caught in the isps spamfilters and they never recieved them. I asked if they werent just in the spam bucket or whatever and they

Re: Bayes question

2004-12-02 Thread Mike
#x27;t had a problem doing that, moving from one Sparc to another. Mike

Re: Bayes question

2004-12-03 Thread Mike
t; Never tried it, but it should be possible with sa-learn --backup and sa-learn --restore. Mike

Re: OT Boincing Spam

2004-12-20 Thread Mike
ly, this is the best solution, as what may be good for one person, may not be an option for another. It's not hard to create a rule to delete all email heading to your boss that is marked spam. Mike

mysql userpref not fetching whitelist_from

2008-02-23 Thread Mike
the option of enabling query logging on the mysql side of things. Spamd is being invoked as follows: running as root, spamd -D -p -x -q -u mike -C /home/mike/samysql/spamd spamc is being run as user mike A clue perhaps is that for some reason the default config file /etc/mail/spamassassin

Re: Spamassassin Learn

2006-02-07 Thread mike
200 of each to even make it start working on sa-learn email. I then feed it representative amounts of ham and spam. The ratio it comes in. [EMAIL PROTECTED] wrote: Can you just feed spamassassin spam or do you need to give it ham also? I read the docs and it didn't say you had to feed it ha

Re: Spamassassin Learn

2006-02-07 Thread mike
Probably would work if you were running Linux. Jim C. Nasby wrote: On Tue, Feb 07, 2006 at 05:47:36PM -0500, Matt Kettler wrote: Chupacabra

Re: Spamassassin Learn

2006-02-07 Thread mike
Jim C. Nasby wrote: On Tue, Feb 07, 2006 at 05:45:54PM -0600, mike wrote: Probably would work if you were running Linux. The problem isn't that it isn't working, the problem is that it's working too well. I guess maybe that's something you're not used to. :

Weird issues with SA

2006-04-02 Thread mike
are/spamassassin/60_whitelist_spf.cf debug: config: read file /usr/share/spamassassin/60_whitelist_subject.cf debug: using "/etc/mail/spamassassin" for site rules dir debug: config: read file /etc/mail/spamassassin/local.cf debug: using "/home/mike/.spamassassin" for user state

Re: Weird issues with SA

2006-04-02 Thread mike
t; wrote: > On Sun, Apr 02, 2006 at 05:15:09PM -0700, mike wrote: > > Can someone help me with trying to fix SA so it stops reporting these > > errors? > > > > I'm running CentOS 4.3, with SA downloaded and installed per > > instructions on the site (basically

Re: Lint problem with KAM.cf

2021-08-30 Thread Mike Grau
+1 Same issue here. On 8/30/21 14:31, Rick Cooper wrote: > This have been going on a while but I haven't had time to addresses. > When the KAM rules are updated I see the following lint warning > warn: rules: error: unknown eval 'short_url' for __KAM_SHORT > > Near as I can tell I am running th

SA From header checks

2016-08-10 Thread Mike Ray
t; to match the whole address with no success. Anyone see what I'm missing? Thanks, Mike Ray

Re: SA From header checks

2016-08-11 Thread Mike Ray
- Original Message - > On Wed, 2016-08-10 at 17:04 -0500, Mike Ray wrote: > > Hello all- > > > > Must be doing something stupid here, but could use a second set of > > eyes and persons more knowledgeable than myself. > > > > None of my header c

Re: SA From header checks

2016-08-11 Thread Mike Ray
- Original Message - > On 08/11/2016 06:03 PM, Mike Ray wrote: > <.snip.> > > > > > > > However, after I had sent that message, I decided to play around a > > bit. I had rearranged existing rules in the file yesterday to make > > su

Which Net::DSN for SpamAssassin-3.4.1

2016-12-09 Thread Mike Grau
Hello all I'm confused ... what is the "recommended" version of Net::DNS to use with an unpatched SpamAssassin-3.4.1? Or are there patches I ought to apply for, say, Net::DNS 1.06? Thanks! -- Mike G.

Re: Which Net::DSN for SpamAssassin-3.4.1

2016-12-12 Thread Mike Grau
>udppacketsize; > my $udp_payload_size = $self->{conf}->{dns_options}->{edns}; > if ($udp_payload_size && $udp_payload_size > 512) { Okay, thanks for the info! -- Mike

Re: Calling SpamAssassin from a Perl Web Form

2010-08-12 Thread Mike Tonks
these components. Any suggestions how to achieve this either via SA or otherwise (existing CPAN modules?) would be much appreciated, if anyone here is knowledgeable in this area. Yes, there will be some captcha stuff too but I see that as separate to the actual 'identifying spam content&#x

Checking envelope sender

2010-09-07 Thread Mike Bro
sh words" <>> That results in my qf... file as line: S<"some rubbish words" <>> Any idea how I could write a rule in spamassassin to test this line? Thanks in advance, Mike

Re: Checking envelope sender

2010-09-08 Thread Mike Bro
Thanks for your interest in this topic. The part of mail.log and the qf file is at: http://pastebin.com/0QzqLxs1 This particular example has been marked as spam, but the sender's information didn't play a role in this classification. Re: Joseph Brennan: > Why doesn't sendmail reject it like it do

Re: Checking envelope sender

2010-09-08 Thread Mike Bro
Hi Bowie, You wrote: > The .qf file is not visible to SpamAssassin.  SA only looks at the email > and headers.  If you want to reject/score based on the envelope sender, > you will need to either do it at the MTA level or find out if sendmail > puts the information into a header that SA can see.

some custom rules query

2010-11-16 Thread Mike Bro
, Mike

Excessive junk mail even after upgrade/update

2011-01-04 Thread Mike Gibson
inistration; so, any help is greatly appreciated. Thank you, Mike Gibson Sr. Network Engineer Select Tel Systems, Inc. 229.434.0540 Select Tel Systems On Time, Done Right, Guaranteed! (229) 434-0540

Re: RP_MATCHES_RCVD

2011-07-28 Thread Mike Grau
On 07/28/2011 09:28 AM the voices made RW write: There seems to be a consensus that SPF and DKIM passes aren't worth significant scores. So how is it that RP_MATCHES_RCVD, scores -1.2 when it just a circumstantial version of what SPF does explicitly. For me it's hitting more spam that ham, and w

How to get spam score by Windows command-line

2011-11-14 Thread Mike Koleszar
ne. I appreciate any advice or suggestions. Thank you. - Mike

KB_FAKED_THE_BAT

2012-05-03 Thread Mike Grau
RS | od -a 000 D a t e : sp ht T h u , sp 3 sp M a 020 y sp 2 0 1 2 sp 1 6 : 5 3 : 5 9 sp 040 + 0 7 0 0 nl 046vi H* This has been Russian language spam (charset koi8-r) with various flavors of X-Mailer: The Bat! -- Mike G.

Re: KB_FAKED_THE_BAT

2012-05-14 Thread Mike Grau
>> >> # grep Date: HEADERS | od -a >> 000 D a t e : sp ht T h u , sp 3 sp M a >> 020 y sp 2 0 1 2 sp 1 6 : 5 3 : 5 9 sp >> 040 + 0 7 0 0 nl >> 046vi H* >> >> This has been Russian language spam (charset koi8-r) wit

Question about TRACKER_ID

2013-02-08 Thread Mike Grau
Hello folks. In 20_body_tests.cf (SA 3.3.2) there is this rule: body TRACKER_ID /^[a-z0-9]{6,24}[-_a-z0-9]{12,36}[a-z0-9{6,24}\s*\z/is What is the "\z" in the regex? This rule matches "". Is that as intended? Thanks! -- Mike

Re: Question about TRACKER_ID

2013-02-08 Thread Mike Grau
Martin Gregorie wrote: > On Fri, 2013-02-08 at 13:26 -0600, Mike Grau wrote: >> Hello folks. >> >> In 20_body_tests.cf (SA 3.3.2) there is this rule: >> >> body TRACKER_ID /^[a-z0-9]{6,24}[-_a-z0-9]{12,36}[a-z0-9{6,24}\s*\z/is >> >> What is the &quo

Re: X-Relay-Countries

2013-02-12 Thread Mike Grau
> > Hmm I would do something like this (untested): > > header RELAY_NOT_US X-Relay-Countries =~ /\b(?!US)[A-Z]{2}\b/ > I've had to use, IIRC. X-Relay-Countries =~ /\b(?!US|XX)([A-Z]{2})\b/

sa-update: MIRRORED.BY is 404 for any channel

2013-06-11 Thread Mike Brown
I'm running 3.3.2 on two FreeBSD 8.3 systems on different networks. Both systems are configured roughly identically with regard to SpamAssassin. One system runs Perl 5.16 (not sure if that matters) and can run sa-update without error, but the other runs Perl 5.12 and gets 404s when it tries to u

Re: sa-update: MIRRORED.BY is 404 for any channel

2013-06-11 Thread Mike Brown
John Wilcock wrote: > > Jun 11 00:05:07.327 [43091] dbg: http: GET > > http://spamassassin.apache.org/updates/MIRRORED.BY"; request failed, > > retrying: 404 Not Found: > > 404 Not Found Not Found > > The requested URL /updates/MIRRORED.BY" was not found on this > > server. Apache/2.4.4 (U

Re: sa-update: MIRRORED.BY is 404 for any channel

2013-06-12 Thread Mike Brown
Martin wrote: > Do you have a MIRRORED.BY file in you spamassassin update directory? It > looks like it doesn't have the file with the mirrors in and instead is using > the file name. > > If so you could copy it over from your other box that's working. > Thanks; your suggestion worked. The wa

Help eliminate false positive for Google Code notifications

2013-07-11 Thread Mike Brown
Google Code sends out notifications from @googlecode.com. These notifications have Message-ID headers that start with two digits and a dash, triggering this rule: SARE_MSGID_DDDASH Message-ID has ratware pattern (9-, 9$, 99-) The rule was proposed in 2004: https://mail-archives.apache.org/mod_m

Re: Help eliminate false positive for Google Code notifications

2013-07-11 Thread Mike Brown
Axb wrote: > SARE rules are obsolete/unsupported/ancient/history/etc and shouldn't be > used. > Do yourself a favour and remove those files - will save you CPU cycles, > memory and lots of headaches. Heh, even easier than I thought. I think I had assumed that if I stopped fetching them, I would

Re: Site Training via Redirect to a spam and/or ham mailbox

2013-07-11 Thread Mike Brown
W T Riker wrote: > I suspect someone has already done this somewhere but I can't seem to > come up with the right key words in my search. I'd like to set up spam > and ham mailboxes to which all my users can redirect/bounce errors for > Bayes training for the site. Then I can run sa-learn via cron

Re: Help eliminate false positive for Google Code notifications

2013-07-17 Thread Mike Brown
Benny Pedersen wrote: > its was good since to many still use it :) In my case it was that the old rulesets were left behind long after the updates stopped; they kept getting transferred over through upgrades of SpamAssassin and Perl. Once I deleted them, all was well. Well, except that more spa

Huh? Variable length lookbehind?

2013-12-27 Thread Mike Grau
I have a problem with a rule on a newly installed relay on which --lint throws a warning on an old local rule, squawking about "Variable length lookbehind not implemented". I simplified the rule trying to discover the problem and it seems to be with the /i modifier: This rule does _not_ provoke

Re: Huh? Variable length lookbehind?

2013-12-27 Thread Mike Grau
ules. > Search for "Character set modifiers" in the perlre man page. > > So something like: > /(? should do with perl >= 5.14 . > > Better yet, avoid lookbehinds. > > Mark > Many thanks Marc - both suggestions solve my problem. -- Mike

refusing to untaint

2014-02-26 Thread Mike Grau
cious path: "${exec_prefix}/lib" This is perl 5, version 18, subversion 1 (v5.18.1) built for x86_64-linux-thread-multi I'm guessing that the variable ${exec_prefix} should already have been evaluated? Can someone tell me what might be the problem? Thanks! -- Mike

Re: refusing to untaint

2014-02-26 Thread Mike Grau
> Any chance you can try the very small patch in > https://issues.apache.org/SpamAssassin/show_bug.cgi?id=7015 and see if > it's related? Still the same error after patching: Feb 26 15:24:07.130 [20964] warn: util: refusing to untaint suspicious path: "${exec_prefix}/lib"

Re: refusing to untaint

2014-02-27 Thread Mike Grau
> Please open a new bug. I'll try and make it a blocker for 3.4.1 if you > open it ASAP. Done.

Re: refusing to untaint

2014-02-27 Thread Mike Grau
in /etc/mail/spamassassin. Removing the .pre files and re-installing SA eliminated the warning. No bug. A configuration issue here. -- Mike G.

Re: Hacked Wordpress sites & Cryptolocker

2014-09-05 Thread Mike Grau
> I'm testing versions that insist on .php and am getting very good > results. Thanks to the OP for pointing this out! I'm also getting WP phishing urls that end in "/", like so: ... /wp-includes/logs/ Presumably, this is the equivalent of /wp-includes/logs/index.php? -- Mike G

Re: Hacked Wordpress sites & Cryptolocker

2014-09-05 Thread Mike Grau
>> I'm also getting WP phishing urls that end in "/", like so: >> >> ... /wp-includes/logs/ > > spample plz? > http://pastebin.com/yBLqTrYP

Re: ancient perl versions

2014-12-05 Thread Mike Grau
On 12/05/2014 09:38 AM, Noel Butler wrote: > pffft > > I see no problem, as like most developers if you cant reproduce it, then > its nothing to bother about, after all this time 2 ppl dont like a font > or whatever, your pissing up the wrong tree if you think I have a care > factor about changing

RBL/SPF if header exists

2015-03-31 Thread Mike Cardwell
on a hardcoded per user or IP setting. -- Mike Cardwell https://grepular.com https://emailprivacytester.com OpenPGP Key35BC AF1D 3AA2 1F84 3DC3 B0CF 70A5 F512 0018 461F XMPP OTR Key 8924 B06A 7917 AAF3 DBB1 BF1B 295C 3C78 3EF1 46B4 signature.asc Description: Digital signature

Re: RBL/SPF if header exists

2015-03-31 Thread Mike Cardwell
the score, that would be sufficient. > You can fairly easily write a meta that reverses the score of each RBL > and SPF rule if your condition fires. Any chance you could point me to an example of how to do this? -- Mike Cardwell https://grepular.com https://emailprivacytester.com OpenPGP Ke

Re: RBL/SPF if header exists

2015-03-31 Thread Mike Cardwell
is that I believe I would have to write a rule for every single RBL and keep those rules up to date whenever a new RBL is added or score updated by upstream. Is there any way of avoiding that? -- Mike Cardwell https://grepular.com https://emailprivacytester.com OpenPGP Key35BC AF1D 3AA2 1F84

Spam rule for HTTP/HTTPS request to sender's root domain

2019-02-27 Thread Mike Marynowski
Hi everyone, I haven't been able to find any existing spam rules or checks that do this, but from my analysis of ham/spam I'm getting I think this would be a really great addition. Almost all of the spam emails that are coming through do not have a working website at the room domain of the sen

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-02-28 Thread Mike Marynowski
I've tested this with good results and I'm actually not creating any HTTPS connections - what I've found is a single HTTP request with zero redirections is enough. If it returns a status code >= 400 then you treat it like no valid website, and if you get a < 400 result (i.e. a 301/302 redirect

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-02-28 Thread Mike Marynowski
Just one more note - I've excluded .email domains from the check as I've noticed several organizations using that as email only domains. Right now the test plugin I've built makes a single HTTP request for each email while I evaluate this but I'll be building a DNS query endpoint or a local do

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-02-28 Thread Mike Marynowski
Question though - what is your reply-to address set to in the emails coming from your email-only domain? The domain checking I'm doing grabs the first available address in this order: reply-to, from, sender. It's not using the domain of the SMTP server. I did come across some email-only domain

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-02-28 Thread Mike Marynowski
I would not do it at all, caching or no caching. Personally, I don't see a benefit trying to correlate email with a website, as mentioned before, based on how we utilise email-only-domains. -Ralph Fair enough. Based on the sampling I've done and the way I intend to use this, I still see thi

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-02-28 Thread Mike Marynowski
And the cat and mouse game continues :) That said, all the big obvious "email-only domains" that send out newsletters and notifications and such that I've come across in my sampling already have placeholder websites or redirects to their main websites configured. I'm sure that's not always the

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-02-28 Thread Mike Marynowski
Why even use a test for something that is so easily compromised? -Ralph Everything we test for is easily compromised on its own.

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-02-28 Thread Mike Marynowski
'm not going to cry about it...more spam catching for me and whoever decides to install the plugin on their own servers. If it does become widespread and some spammers adapt then I'll take solace in knowing I helped a lot of people stop at least some of their spam. * Mike Marynowsk

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-02-28 Thread Mike Marynowski
On 2/28/2019 12:41 PM, Bill Cole wrote: You should probably put the envelope sender (i.e. the SA "EnvelopeFrom" pseudo-header) into that list, maybe even first. That will make many messages sent via discussion mailing lists (such as this one) pass your test where a test of real header domains w

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-02-28 Thread Mike Marynowski
On 2/28/2019 12:41 PM, Bill Cole wrote: You should probably put the envelope sender (i.e. the SA "EnvelopeFrom" pseudo-header) into that list, maybe even first. That will make many messages sent via discussion mailing lists (such as this one) pass your test where a test of real header domains w

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-02-28 Thread Mike Marynowski
Reply-To header. I don't ever need 2 copies of a message posted to a mailing list, and ignoring that header is rude. On 28 Feb 2019, at 13:28, Mike Marynowski wrote: On 2/28/2019 12:41 PM, Bill Cole wrote: You should probably put the envelope sender (i.e. the SA "EnvelopeFrom"

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-02-28 Thread Mike Marynowski
o they are no risk of being blocked even if a non-website domain triggers this particular rule. On 2/28/2019 2:25 PM, Bill Cole wrote: On 28 Feb 2019, at 13:43, Mike Marynowski wrote: On 2/28/2019 12:41 PM, Bill Cole wrote: You should probably put the envelope sender (i.e. the SA "Envel

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-02-28 Thread Mike Marynowski
lding this as a cached DNS service is just walk up the subdomains until I hit the root domain and if any of them have a website then it's fine. On 2/28/2019 2:39 PM, Antony Stone wrote: On Thursday 28 February 2019 at 20:33:42, Mike Marynowski wrote: But scconsult.com does in fact have

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-02-28 Thread Mike Marynowski
Thunderbird normally shows reply-to in normal messages...is this something that some MUAs ignore just on mailing list emails or all emails? Because I see reply-to on plenty of other emails. On 2/28/2019 3:44 PM, Bill Cole wrote: On 28 Feb 2019, at 14:29, Mike Marynowski wrote: Unfortunately

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-02-28 Thread Mike Marynowski
I'm pretty sure the way I ended up implementing it everything is working fine and it's nice and simple and clean but maybe there's some edge case that doesn't work properly. If there is I haven't found it yet, so if you can think of one let me know. Since I'm sending an HTTP request to all sub

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-02-28 Thread Mike Marynowski
I modified it so it checks the root domain and all subdomains up to the email domain. As for your question - if afraid.org has a website then you are correct, all subdomains of afraid.org will not flag this rule, but if lots of afraid.org subdomains are sending spam then I imagine other spam

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-02-28 Thread Mike Marynowski
You'll be able to decide how you want to prioritize the fields - I've implemented it as a DNS server, so which domain you decide to send to the DNS server is entirely up to you. On 2/28/2019 10:23 PM, Grant Taylor wrote: On 2/28/19 9:33 AM, Mike Marynowski wrote: I'm doing

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-02-28 Thread Mike Marynowski
For anyone who wants to play around with this, the DNS service has been posted. You can test the existence of a website on a domain or any of its parent domains by making DNS queries as follows: subdomain.domain.com.httpcheck.singulink.com So, if you wanted to check if mail1.mx.google.com or a

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-03-01 Thread Mike Marynowski
Changing up the algorithm a bit. Once a domain has been added to the cache, the DNS service will perform HTTP checks in the background automatically on a much more aggressive schedule for invalid domains so that temporary website problems are much less of an issue and invalid domains don't dela

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-03-01 Thread Mike Marynowski
sumed SpamAssassin was already doing simple checks like that. On 3/1/2019 10:23 AM, RW wrote: On Wed, 27 Feb 2019 12:16:20 -0500 Mike Marynowski wrote: Almost all of the spam emails that are coming through do not have a working website at the room domain of the sender. Did you establish what fracti

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-03-01 Thread Mike Marynowski
MTA. On 3/1/2019 2:26 PM, Antony Stone wrote: On Friday 01 March 2019 at 17:37:18, Mike Marynowski wrote: Quick sampling of 10 emails: 8 of them have valid A records on the email domain. I presumed SpamAssassin was already doing simple checks like that. That doesn't sound like a good id

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-03-01 Thread Mike Marynowski
On 3/1/2019 1:07 PM, RW wrote: Sure, but had it turned-out that most of these domains didn't have the A record necessary for your HTTP test, it wouldn't have been worth doing anything more complicated. I've noticed a lot of the spam domains appear to point to actual web servers but throw 403 o

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-03-01 Thread Mike Marynowski
On 3/1/2019 4:31 PM, Grant Taylor wrote: afraid.org is much like DynDNS in that one entity (afaid.org themselves or DynDNS) provide DNS services for other entities. I don't see a good way to differentiate between the sets of entities. I haven't come across any notable amount of spam that's

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-03-01 Thread Mike Marynowski
Taylor <mailto:gtay...@tnetconsulting.net>> wrote: On 02/28/2019 09:39 PM, Mike Marynowski wrote: > I modified it so it checks the root domain and all subdomains up to the > email domain. :-) > As for your question - if afraid.org has a website then you are correct, > all subdomains of a

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-03-13 Thread Mike Marynowski
Back up after some extensive modifications. Setting the DNS request timeout to 30 seconds is no longer necessary - the service instantly responds to queries. In order to prevent mail delivery issues if the website is having technical issues the first time a domain is seen by the service, it w

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-03-13 Thread Mike Marynowski
Any HTTP status code 400 or higher is treated as no valid website on the domain. I see a considerable amount of spam that returns 5xx codes so at this point I don't plan on changing that behavior. 503 is supposed to indicate a temporary condition so this seems like an abuse of the error code.

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-03-13 Thread Mike Marynowski
Can someone help me form the correct SOA record in my DNS responses to ensure the NXDOMAIN responses get cached properly? Based on the logs I don't think downstream DNS servers are caching it as requests for the same valid HTTP domains keep hitting the service instead of being cached for 4 days

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-03-15 Thread Mike Marynowski
Thank you! I have no idea how I missed that... On 3/13/2019 7:11 PM, RW wrote: On Wed, 13 Mar 2019 17:40:57 -0400 Mike Marynowski wrote: Can someone help me form the correct SOA record in my DNS responses to ensure the NXDOMAIN responses get cached properly? Based on the logs I don't

Re: Spam rule for HTTP/HTTPS request to sender's root domain

2019-03-20 Thread Mike Marynowski
Continuing to fine-tune this service - thank you to everyone testing it. Some updates were pushed out yesterday:  * Initial new domain "grace period" reduced to 8 minutes (down from 15 mins) - 4 attempts are made within this time to get a valid HTTP response  * Mozilla browser spoofing is imple

Re: Open source (WAS: Spam rule for HTTP/HTTPS request to sender's root domain)

2019-03-21 Thread Mike Marynowski
e, though people are obviously free to do with the code as they wish. Cheers! Mike On 3/21/2019 5:42 AM, Tom Hendrikx wrote: On 20-03-19 19:56, Mike Marynowski wrote: A couple people asked about me posting the code/service so they could run it on their own systems but I'm currently le

Re: Open source (WAS: Spam rule for HTTP/HTTPS request to sender's root domain)

2019-03-21 Thread Mike Marynowski
Here ya go ;) https://github.com/mikernet/HttpCheckDnsServer On 3/21/2019 5:42 AM, Tom Hendrikx wrote: On 20-03-19 19:56, Mike Marynowski wrote: A couple people asked about me posting the code/service so they could run it on their own systems but I'm currently leaning away from that. I

How to verify specific commits are in current ruleset?

2019-05-30 Thread Mike Ray
s change (https://svn.apache.org/viewvc/spamassassin/trunk/rulesrc/sandbox/jhardin/20_misc_testing.cf?r1=1857655&r2=1857654&pathrev=1857655) and comparing that to the code currently running on my mail servers. Is there any easier way to verify that a specific commit is in my currently running rule set? Mike Ray

Re: not deleting

2004-09-07 Thread Mike Burger
SpamAssassin doesn't delete mail...just tags it. Enabling/disabling delivery to a spam box is nothing more than enabling/disabling a procmail recipe. It's probable that cpanel is doing just this. It's highly unlikely that cpanel is going to put in a different recipe that send

Re: spamassassin 2.60 to 2.64 initial nonspam test fails

2004-09-08 Thread Mike Burger
On Wed, 8 Sep 2004, Obantec Support wrote: > Hi > > I have upgraded from 2.60 to 2.64 but the test > spamassassin -t < sample-nonspam.txt > nonspam.out locks up. > spamassassin -t < sample-spam.txt > spam.out works as expected. Disk corruption, file corruption, l

RE: Catching Windows executables as attachments

2004-09-09 Thread Mike Kercher
d a rule for them. > > Is there one? How can I catch them otherwise? > > Rob MailScanner does this by default. Mike

Re: SPF and spammers

2004-09-11 Thread Mike Burger
uot;v=spf1 a mx -all" Essentially saying that all my MX records are valid senders, as well. All the spammer has to do is list those servers as MX records (whether or not they'll accept inbound mail is irrelevant for the discussion at hand), set up their SPF record like above, and essential

Running spamd on different server and user profiles

2004-09-12 Thread Mike Loiterman
If I run spamd on a different server, how are the user profiles for my local users handled? -- Mike Loiterman grantADLER Tel: 630-302-4944 Fax: 773-442-0992 Email: [EMAIL PROTECTED] PGP Key: 0xD1B9D18E GPG Key: 0x661D0518

RE: Running spamd on different server and user profiles

2004-09-12 Thread Mike Loiterman
> They would not be used, unless you did a lot of fancy > configuration so that spamd could find them. Where would I do this fancy configuration? -- Mike Loiterman grantADLER Tel: 630-302-4944 Fax: 773-442-0992 Email: [EMAIL PROTECTED] PGP Key: 0xD1B9D18E G

Spamd running on a different server

2004-09-12 Thread Mike Loiterman
ot. 2. I can't figure out how to get the spamd running on the other machine to read the user pref files located on the machine running spamc. Any ideas? ------ Mike Loiterman grantADLER Tel: 630-302-4944 Fax: 773-442-0992 Email: [EMAIL PROTECTED] PGP Key: 0xD1B9D18E GPG Key: 0x661D0518

RE: Spamd running on a different server

2004-09-13 Thread Mike Loiterman
; different then the user running spamd. > > It shouldn't be.. Perhaps it might happen if the user running > spamc doesn't > exist on the machine spamd runs on, but otherwise you should be OK The user names are the same, but the ids are different. Any workaround for this?

RE: Running spamd on different server and user profiles

2004-09-14 Thread Mike Loiterman
getting a failed sanity check error after the message has been scanned and sent back to the machine running spamc. I think its because the user ids are different. How are you getting around this? -- Mike Loiterman grantADLER Tel: 630-302-4944 Fax: 773-442-0992 Email: [

Re: Two logs for each daemon?

2004-09-19 Thread Mike Burger
s with previous versions and was wondering if I might have > done something in the upgrade to cause this. > > Ed Kasky > . . . . . . . . . . . . . . . > Randomly generated quote: > Success usually comes to those who are too busy to be looking for it. > - Henry David Thor

Re: SA 3.0 and Bigevil

2004-09-22 Thread Mike Jackson
Hmm..silver lake? Wouldnt it be hacked to pieces by a guy in a hockey mask? That's CRYSTAL Lake, not Silver Lake :) Mike Jackson

timeout waiting for input from local during Draining Input

2004-09-23 Thread Mike Loiterman
I periodically get these errors in my log and when I do the messages are not scanned. What's going on and how do I stop it? -- Mike Loiterman grantADLER Tel: 630-302-4944 Fax: 773-442-0992 Email: [EMAIL PROTECTED] PGP Key: 0xD1B9D18E GPG Key: 0x661D0518

Re: Migrating Configs/Bayes into SQL

2004-09-23 Thread Mike Jackson
http://www.squirrelmail.org/plugin_view.php?id=167 Mike Jackson CMC Tech Support

Re: SlashDotting spammers

2004-09-23 Thread Mike Hogsett
ts of resources of the target. Hmmm... Damn, its too bad because I like the idea. They use zombies and spambots against us, why can't we use similar systems against them! - Mike

Re: [sa-list] spamd won't shut down cleanly on FreeBSD

2004-09-27 Thread Mike Jackson
4.8.5, but only with the beta versions of SA-3. When I installed the release version of SA-3, it worked fine. Mike Jackson Editor & Web Developer, DVD Verdict www.dvdverdict.com

Re: unsubscribe problems :(

2004-09-29 Thread Mike Burger
PROTECTED]>: > Sorry, no mailbox here by that name. (#5.1.1) > > > And as per the admin start message: > > To remove your address from the list, send a message to: >    <[EMAIL PROTECTED]> > > This doesn't work :( > > Cheers, SMES > > Elwyn

Re: unsubscribe problems :(

2004-09-29 Thread Mike Burger
day, I sent out the correct address to use for unsubscribing; instructions that are in the headers of the messages coming through the list. I don't think I understand how my not posting to the list is going to help either of you. On Wed, 29 Sep 2004, Declan Moriarty wrote: > On Tue, Se

Re: unsubscribe problems :(

2004-09-29 Thread Mike Burger
On Wed, 29 Sep 2004, SME Server Admin wrote: > On Wednesday 29 Sep 2004 13:19, Mike Burger wrote: > > [EMAIL PROTECTED] > > > > Thank you :) You're quite welcome. -- Mike Burger http://www.bubbanfriends.org Visit the Dog Pound II BBS telnet://dogpound2.citad

Re: 2.6 -> 3.0 migration questions

2004-10-01 Thread Mike Burger
them in a test environment...even stage the upgrade to the release version, in test, prior to throwing it out there for general consumption. -- Mike Burger http://www.bubbanfriends.org Visit the Dog Pound II BBS telnet://dogpound2.citadel.org or http://dogpound2.citadel.org To be notified of

RE: What's the POINT?

2004-10-03 Thread Mike Kercher
inks. No URL's. No > HREF's. No phone numbers. No nothing. This is as it appears in > "raw" mode in pine. I even tail'd my mailbox to be sure there was > nothing the mailer was hiding. They forged my address so there's not > even something to imply a site from there. > > WHAT THE HECK IS THE POINT TO EVEN SENDING THE EMAIL OUT? > > *sighs and sends it to spamassassin -r* Bayes poisoning possibly? Mike

  1   2   3   4   5   6   7   >