Re: [exim] Ratelimiting recipients per sender_address

2023-03-10 Thread Olaf Hopp (SCC) via Exim-users
On 3/9/23 21:08, Jeremy Harris via Exim-users wrote: On 09/03/2023 19:30, Slavko via Exim-users wrote: Dňa 9. marca 2023 16:08:08 UTC používateľ Jeremy Harris via Exim-users napísal: On 09/03/2023 15:47, Olaf Hopp (SCC) via Exim-users wrote:    "x recipients per distinct sender per time 

Re: [exim] Ratelimiting recipients per sender_address

2023-03-09 Thread Jeremy Harris via Exim-users
On 09/03/2023 19:30, Slavko via Exim-users wrote: Dňa 9. marca 2023 16:08:08 UTC používateľ Jeremy Harris via Exim-users napísal: On 09/03/2023 15:47, Olaf Hopp (SCC) via Exim-users wrote:  "x recipients per distinct sender per time period y  > z" ? If yoe used

Re: [exim] Ratelimiting recipients per sender_address

2023-03-09 Thread Slavko via Exim-users
Dňa 9. marca 2023 16:08:08 UTC používateľ Jeremy Harris via Exim-users napísal: >On 09/03/2023 15:47, Olaf Hopp (SCC) via Exim-users wrote: >>  "x recipients per distinct sender per time period y  > z" ? > >If yoe used $sender_address@$recipient as the key, would >it do what you want? Are

Re: [exim] Ratelimiting recipients per sender_address

2023-03-09 Thread Evgeniy Berdnikov via Exim-users
On Thu, Mar 09, 2023 at 04:47:32PM +0100, Olaf Hopp (SCC) via Exim-users wrote: > Dear list, > we want to ratelimit incomming mail bursts (e.g. due > to phishing attacks). > To get an idea of reasonable values I have > > warn > ratelimit = 100 / 60s / strict / $sender_address >

Re: [exim] Ratelimiting recipients per sender_address

2023-03-09 Thread Jeremy Harris via Exim-users
On 09/03/2023 15:47, Olaf Hopp (SCC) via Exim-users wrote:  "x recipients per distinct sender per time period y  > z" ? If yoe used $sender_address@$recipient as the key, would it do what you want? -- Cheers, Jeremy -- ## List details at

[exim] Ratelimiting recipients per sender_address

2023-03-09 Thread Olaf Hopp (SCC) via Exim-users
Dear list, we want to ratelimit incomming mail bursts (e.g. due to phishing attacks). To get an idea of reasonable values I have warn ratelimit = 100 / 60s / strict / $sender_address log_message = RATELIMIT EXCEEDED for $sender_address $sender_rate messages / $sender_rate_period