[Declude.JunkMail] Actions
I just want to clarify the way to set 2 actions in junk mail. This is how I understand it to warn and tag subject line with *spam*: AHBLWARN AHBLSUBJECT[*spam*] BLITZEDALL WARN BLITZEDALL SUBJECT[*spam*] CBL WARN CBL SUBJECT[*spam*] Would this be correct? -jeff --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.JunkMail mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.JunkMail. The archives can be found at http://www.mail-archive.com.
Re: [Declude.JunkMail] Actions
BLITZEDALL WARN BLITZEDALL SUBJECT[*spam*] This will NOT work you need to define 2 tests in Global.cfg BLITZEDALLw ip4r .. BLITZEDALLs ip4r . then use BLITZEDALLw WARN BLITZEDALLs SUBJECT[*spam*] - Original Message - From: Jeffrey M Donley [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Sunday, August 15, 2004 4:48 PM Subject: [Declude.JunkMail] Actions I just want to clarify the way to set 2 actions in junk mail. This is how I understand it to warn and tag subject line with *spam*: AHBL WARN AHBL SUBJECT[*spam*] BLITZEDALL WARN BLITZEDALL SUBJECT[*spam*] BL WARN CBL SUBJECT[*spam*] Would this be correct? -jeff --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.JunkMail mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.JunkMail. The archives can be found at http://www.mail-archive.com. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.JunkMail mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.JunkMail. The archives can be found at http://www.mail-archive.com.
[Declude.JunkMail] Possible new scam or undetected virus
We may have a new scam or virus going on. Just got about twenty emails with zips (subject line: Subject: Your login information has been updated). Supposedly from USdBill Support (sender address and sending server keep changing -- surprise, surprise). Attached zip is call panel_v1.7. The D*.SMD file is about 38kb. My virus checker isn't finding anything as of 3:20pm, Aug. 15th. Since I don't plan to open up the zip, that's all I've got. John Partial headers from one: Received: from 69-160-110-199.chvlva.adelphia.net [69.160.110.199] by bobcat.jcjc.edu (SMTPD32-8.12) id ADD63540110; Sun, 15 Aug 2004 14:47:34 -0500 Date: Sun, 15 Aug 2004 19:39:48 + From: USdBILL Support [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: Your login information has been updated MIME-Version: 1.0 Content-Type: multipart/related; boundary=--6BB0EAFCAF5716EEAD55FB100 Message-Id: [EMAIL PROTECTED] X-Declude-Sender: [EMAIL PROTECTED] [69.160.110.199] X-Declude-Spoolname: Dbdd4035401109344.SMD X-Note: This E-mail was scanned by Declude JunkMail (www.declude.com) for spam. X-Spam-Tests-Failed: None [0] X-Note: This E-mail was sent from ([69.160.110.199]). --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.JunkMail mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.JunkMail. The archives can be found at http://www.mail-archive.com.
[Declude.JunkMail] SpamCop Listed
Hi all DNSStuff shows my server listed in spamcop: SPAMCOP LISTED (127.0.0.2) TXT= Blocked - see http://www.spamcop.net/bl.shtml?208.154.200.6; 1745 seconds 0 ms But spamcop.net showing it as not listed: 208.154.200.6 not listed in bl.spamcop.net What is going on ? --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.JunkMail mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.JunkMail. The archives can be found at http://www.mail-archive.com.
Re: [Declude.JunkMail] Quick SPAMDOMAINS Questuion
Well, maybe not so quick after all... A follow-on question: What is the logic involved with these entries? INCLUDES? IS? ENDSWITH? something else? For example, if I include the following line in my SPAMDOMAINS file... msn.com hotmail.com ...which ofthe following messages would pass the test: from: [EMAIL PROTECTED] rdns: yadayada.scammsn.com (fail?) rdns: yadayada.scamhotmail.com (fail?)rdns: yadayada.scam.msn.com (pass?) rdns: yadayada.scam.hotmail.com (pass?) rdns: yadayada.msn.com.phish.com (???) rdns: yadayada.hotmail.com.phish.com (???) -Dave Doherty Skywaves, Inc. - Original Message - From: "R. Scott Perry" [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Friday, June 04, 2004 10:42 AM Subject: Re: [Declude.JunkMail] Quick SPAMDOMAINS Questuion If I want to allow mail from [EMAIL PROTECTED] to pass SPAMDOMAINS, knwoing that at least some msn.com mail is actually transmitted by hotmail.com servers, how should I set up SPAMDOMAINS to allow both domains? msn.com msn.com hotmail.com If you just use the second line, you'll be fine (do not use both, though, as an E-mail that fails the first one would fail the test, even if it passes the second line). -Scott --- Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000. Declude Virus: Ultra reliable virus detection and the leader in mailserver vulnerability detection. Find out what you've been missing: Ask for a free 30-day evaluation. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.JunkMail mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.JunkMail". The archives can be found at http://www.mail-archive.com.