Good DNSBLs not in standard spamassassin (Was Re: non-free Services)

2024-09-18 Thread Andy Smith
Hi, On Wed, Sep 18, 2024 at 10:18:18AM +, Laurent S. wrote: > Some good RBL are not in standard spamassassin. Out of interest, which DNSBLs do you use/recommend that are not in standard spamassassin? Thanks, Andy

Re: Dinged for .Date

2024-01-16 Thread Andy Smith
re different. Is the work worth it? Generally not; other options exist. Thanks, Andy -- https://bitfolk.com/ -- No-nonsense VPS hosting

Re: Question about forwarding email (not specifically SA, pointers greatly appreciated)

2024-01-04 Thread Andy Smith
Hello, On Wed, Jan 03, 2024 at 01:24:02PM -0600, Thomas Cameron via users wrote: > On 1/2/24 17:51, Andy Smith wrote: > > - Have your users collect their your-org email by some means other > >than SMTP, such as running an IMAP server and having them view > >both th

Re: Question about forwarding email (not specifically SA, pointers greatly appreciated)

2024-01-02 Thread Andy Smith
ers collect their your-org email by some means other than SMTP, such as running an IMAP server and having them view both their gmail mailbox and their your-org inbox in one place (I have no idea if that is feasible with gmail). Thanks, Andy -- https://bitfolk.com/ -- No-nonsense VPS hosting

Re: Correct way to allowlist an IP from DNSBL checks when it's not the final Received?

2023-09-30 Thread Andy Smith
Hello, On Sat, Sep 30, 2023 at 11:52:13AM -0400, Jared Hall wrote: > On 9/29/2023 10:59 AM, Andy Smith wrote: > > 3.4.2. I know, it's ancient. An upgrade is planned but I'd still > > like to know what the behaviour is. I understand if no one wants to > > help a

Re: Correct way to allowlist an IP from DNSBL checks when it's not the final Received?

2023-09-29 Thread Andy Smith
callback on key dns:A:73.233.187.66.zen.spamhaus.org Sep 29 14:36:57.378 [2611] dbg: dns: hit 127.0.0.3 So this is normal behaviour then, for v3.4.2 at least? Thanks, Andy

Re: Correct way to allowlist an IP from DNSBL checks when it's not the final Received?

2023-09-28 Thread Andy Smith
Spamhaus SBL-CSS. Is that expected? I guess I can allowlist from SPF as the envelope sender will be the mailing list in question (linux-lvm-boun...@redhat.com) and it did get a "SPF_PASS SPF: sender matches SPF record" so redhat.com must have mimecast's relays correctly in it. Thanks, Andy

Correct way to allowlist an IP from DNSBL checks when it's not the final Received?

2023-09-27 Thread Andy Smith
h all manner of addresses and the supplier also hosts mailing lists that are open to the public so I cannot predict any from address for allowlisting purposes. I expect they will be delisted by the time I work this out, but it would be good to know for the future! Thanks, Andy

Re: new rule for kam :)

2023-08-24 Thread Andy Smith
Hi, On Wed, Aug 23, 2023 at 06:14:45PM -0700, John Hardin wrote: > On Wed, 23 Aug 2023, Andy Smith wrote: > > On Wed, Aug 23, 2023 at 03:24:22PM +0200, Benny Pedersen wrote: > > > # test for empty src="" or empty href="" > > > rawbody __HREF_E

Re: new rule for kam :)

2023-08-23 Thread Andy Smith
nd it matched quite a lot of previously not found spam, but did also match on every auto response from one of my suppliers. It seems after every customer service interaction they send a "how did we do? fill in this survey" email from qualtrics.com which contains: It wouldn&#

Re: ip2location.com

2021-01-28 Thread Andy Smith
3 | 85.119.80.0/21 | GB | ripencc | 2010-03-03" So perhaps another plugin along the lines of Plugin::ASN could be used to get some of that info? Cymru database docs at: https://team-cymru.com/community-services/ip-asn-mapping/#dns Cheers, Andy

Re: The most efficient SPAM implementation ever

2020-10-11 Thread Andy Smith
endGrid as then it would become more feasible to block them entirely. They currently "provide legitimacy" only on the basis of them being "too big to block"; I am not sure if that is something to be encouraged by throwing them more business. Cheers, Andy -- https://bitfolk.com/ -- No-nonsense VPS hosting

Re: mark emails as being spam originating from an ip range owner

2020-09-29 Thread Andy Smith
X-ASN =~ /\b48031\b/ score LOCAL_SPAMMY_ASN_XSERVER5.0 describeLOCAL_SPAMMY_ASN_XSERVERToo much spam from xserver.ua (AS48031) Cheers, Andy -- https://bitfolk.com/ -- No-nonsense VPS hosting

SendGrid (Was: Re: Freshdesk (again))

2020-06-26 Thread Andy Smith
e SendGrid would do to prevent their other customers sending out phishing emails in their name. Cheers, Andy

Re: bayes_path ignored

2019-05-27 Thread Andy Howell
On 5/27/19 8:11 PM, Reindl Harald wrote: Am 28.05.19 um 02:38 schrieb Andy Howell: On 5/27/19 6:43 PM, Reindl Harald wrote: Am 28.05.19 um 01:05 schrieb Andy Howell: How do I get spamassassin to honor the setting of bayes_path in /etc/spamassassin/local.cf ? bayes_path /var/spool/postfix

Re: bayes_path ignored

2019-05-27 Thread Andy Howell
On 5/27/19 6:43 PM, Reindl Harald wrote: Am 28.05.19 um 01:05 schrieb Andy Howell: How do I get spamassassin to honor the setting of bayes_path in /etc/spamassassin/local.cf ? bayes_path    /var/spool/postfix/spamassassin/bayes_db It never gets used. I can get sa-learn to create the files

bayes_path ignored

2019-05-27 Thread Andy Howell
age: bayes: no dbs present, cannot tie DB R/O: /root/.spamassassin/bayes_toks I am using: postfix 3.3.0-1ubuntu0.2 amavisd-new 1:2.11.0-1ubuntu1.1 spamassassin 3.4.2-0ubuntu0.18.04.1 Thanks, Andy

ASN plugin matches IPv6 addresses against IPv4 DNS lists

2018-11-26 Thread Andy Smith
f set. I've never developed a plugin before but if that approach is acceptable then I can look into doing it. Cheers, Andy

Re: Scans and Invoice spam containg HREF to something bad

2018-06-19 Thread Andy Smith
This has literally just come through to me, zero BAYES and got passed my custom rule as the HREF URL has changed: https://pastebin.com/pBfhXd6B thanks, Andy. On 19-06-2018 17:33, Kevin A. McGrail wrote: > Well you are welcome to send me new Spamples to look at. As I noted, I've

Re: Scans and Invoice spam containg HREF to something bad

2018-06-19 Thread Andy Smith
Hi Kevin, I'm not really getting any joy with the RBLs. I have, for example, a sample from the 14th and, taking away my custom rule, Bayes and KAM scores, the default score would be "0" :( Content here: https://pastebin.com/dthDn8yb thanks, Andy. On 19-06-2018 17:12, K

Re: Scans and Invoice spam containg HREF to something bad

2018-06-19 Thread Andy Smith
Hi Kevin, No I wasn't. I just added it, I get a lot of errors like "meta test KAM_WARRANTY3 has dependency 'CBJ_GiveMeABreak' with a zero score", is this normal? Testing despite these errors the only rule I'm getting a hit on from KAM is JMQ_SPF_NEUTRAL_ALL th

Scans and Invoice spam containg HREF to something bad

2018-06-19 Thread Andy Smith
F My question is does anyone have any ideas/tips/rules for catching these. I've created a custom rule that checks for the subject and HREF, but ever time a new variant comes out I'll have to update this. Anyone got any better solutions? thanks in advance, Andy.

Re: Mail flagged as spam on command line getting passed through as ham

2018-01-18 Thread Andy Howell
Shanew, Checked my logs and modifcation time on the local.cf. I had restarted it. I initially had a single 7 in there, but that was not working so I added all 4. Thanks, Andy On 01/18/2018 02:24 PM, sha...@shanew.net wrote: > Most likely you've forgotten to restart spamd or maybe

Mail flagged as spam on command line getting passed through as ham

2018-01-18 Thread Andy Howell
gives confidence level above 50%     *  [cf: 100]    *  0.9 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/ *  0.0 T_REMOTE_IMAGE Message contains an external image X-Spam-Bayes: bayes=0.7650, N=176(88-0+3), ham=(), spam=(shark, Pill, craze) Any ideas what I'm doing wrong? Thanks, Andy

Re: what is triggering NO_DNS_FOR_FROM

2017-03-16 Thread Andy Smith
in. Not sure if this behaviour is typical in other SMTP servers. Thanks also RW for the tips about "-D" and envelope_sender_header documentation. Noted for future reference! many thanks, Andy.

what is triggering NO_DNS_FOR_FROM

2017-03-13 Thread Andy Smith
by Exim), so if I'm going to convince them to do more modifications I'd prefer to know what I was talking about, thanks, Andy.

ASN plugin and IPv6 addresses

2017-02-25 Thread Andy Smith
t one gets included together with the (correct) answer from origin6.asn.cymru.com. What is the correct way of configuring this? Doesn't the plugin need two different asn_lookup directives, one for IPv4 and one for IPv6, with only the relevant queries being directed at each? Cheers, Andy

Re: DNS again

2016-06-03 Thread Andy Balholm
isunderstood the question > ==John ff > On 3 Jun 2016, at 17:23, Andy Balholm <mailto:a...@balholm.com>> wrote: > Where is your mail server hosted. URIBL blocks queries from some cloud > providers (including DigitalOcean) unless you have a subscription. For a > while I h

Re: DNS again

2016-06-03 Thread Andy Balholm
I was using unbound as a local resolver. All queries were going to 127.0.0.1, and there was no forwarding set up. Andy

Re: DNS again

2016-06-03 Thread Andy Balholm
Where is your mail server hosted. URIBL blocks queries from some cloud providers (including DigitalOcean) unless you have a subscription. For a while I had a mail server hosted on DO, and I was paying more for my URIBL subscription than for my hosting. Andy

Re: spamass-milter: orphaned?

2016-06-01 Thread Andy Balholm
-milter project member takes an interest, changes can be merged back into the official CVS repository. Andy

Re: spamass-milter: orphaned?

2016-05-26 Thread Andy Balholm
Yes, I eventually discovered -a in the help text. But it’s not in the man page. I sent a mail to the spamass-milt mailing list (and the maintainers) first, and got no response. It was the first post to that list since September 2014. Andy

Re: spamass-milter: orphaned?

2016-05-26 Thread Andy Balholm
were being maintained, I would just file a bug or submit a patch. But looking at the condition of the issue trackers, I don’t think that would do any good. Andy

Re: spamass-milter: orphaned?

2016-05-26 Thread Andy Balholm
Where are those updates? There is nothing less than 20 months old at http://cvs.savannah.gnu.org/viewvc/spamass-milt/?root=spamass-milt Is this the Fedora changelog? It talks about upstream, and mentions Fedora 22. Andy

Re: spamass-milter: orphaned?

2016-05-26 Thread Andy Balholm
> ...some other headers to be pushed to mail SA generates What do you mean? Andy

spamass-milter: orphaned?

2016-05-26 Thread Andy Balholm
, and trying to maintain it there. Is anyone else here interested in seeing that happen? Or do you have other ideas about what should be done? Andy

Re: DBL and SBL checks on from address domain

2015-03-25 Thread Andy Wright
ers > That would be a nice feature for development if it is absolutely not possible (gut feeling not). In addition to URIBL checks, it would be useful to do a reverse DNS on the from address domain name and run it through any preferred DNSBL. > > > Thanks > > Ram &g

Re: Spam Assassin - does it work or not?

2014-08-11 Thread Andy
Sheesh. Sorry to offend. As far as it goes, I'm a leech for using Spam Assassin right now as it is. Ok I can see my welcome is over here. I'm outta here. Thanks everyone (else). On Mon, August 11, 2014 7:00 am, David F. Skoll wrote: > On Mon, 11 Aug 2014 06:45:24 -0700 &g

Re: Spam Assassin - does it work or not?

2014-08-11 Thread Andy
7;m sounding like a leech, that's because in this case I would very much like to be. :o) Andy On Mon, August 11, 2014 6:35 am, Axb wrote: > On 08/11/2014 03:23 PM, Andy wrote: > >> ok so if i understand things the only way that is feasible for any >> person/business t

Re: Spam Assassin - does it work or not?

2014-08-11 Thread Andy
:34:34 -0700 > Andy wrote: > > >> I've copied a few of your responses (without including any names) and >> sent them to support at lunarpages. And maybe it's due to that that after >> six+ months of battling with them, I now get this from their support. >

Re: Spam Assassin - does it work or not?

2014-08-11 Thread Andy
now I guess they've thrown the problem back to me. As I've mentioned before I really dont have the time or desire to learn what it takes to tweak Spam Assassin. Is there any sort of file online that I can download and use, one that might be more up to date to deal with current spam tricks? Andy

Re: Spam Assassin - does it work or not?

2014-08-10 Thread Andy
On Sun, August 10, 2014 9:08 am, David F. Skoll wrote: > > Maintaining an effective spam filter is a lot of work. If LunarPages > does not specialize in that (or at least have a group who specializes in > it) it's almost certainly not cost-effective for them to bother. It's > much cheaper to outs

Re: Spam Assassin - does it work or not?

2014-08-10 Thread Andy
ng to do so. On Sun, August 10, 2014 7:53 am, John Hardin wrote: > On Sun, 10 Aug 2014, Andy wrote: > > >> And then here is the response I received from Lunarpages >> > > {snip} > > >> it's pretty clear that we have no control over such issues and apart

Spam Assassin - does it work or not?

2014-08-10 Thread Andy
've heard from them about "harvestable email" any number of times already) and get the gist of it. The second paragraph in particular offers their policy in regards to the management of Spam Assassin. - Hello Andy, Thank you for your update in this case. I have reviewed your f

Re: Spam Assassin - does it work or not?

2014-08-07 Thread Andy
I think my best option at this point is to just go back to the "old" way of using my own client software on my computer. And find one with a strong filter of its own. Anyone have any good results with Firefox Thunderbird? Andy

Re: rule for repeated tracking numbers

2014-08-07 Thread Andy Balholm
On Aug 7, 2014, at 10:28 AM, Philip Prindeville wrote: > (1) putting that many domains on a single host is just begging for that host > to have a catastrophic failure (as opposed to putting that many domains on a > local (re)director which servers as a proxy, a la mod_proxy_html mode…) Judgi

Re: Spam Assassin - does it work or not? - LONG HEADERS URL

2014-08-07 Thread Andy
On Thu, August 7, 2014 9:38 am, Andy Balholm wrote: > Looking at Lunarpages pricing page, it looks like shell access is a $2.00 > per month add-on. Since you don’t know what it is, I expect you didn’t > think it was worth paying extra for it, so you probably don’t have it. i wouldnt kno

Re: rule for repeated tracking numbers

2014-08-07 Thread Andy Balholm
This particular spammer just re-did the format of their emails, probably to get around the rules that we’re working on. Do they read the spamassassin-users list? (I can tell it’s the same spammer, since the return address in Dundrum, Ireland, is the same as some of the earlier ones, and the styl

Re: Spam Assassin - does it work or not? - LONG HEADERS URL

2014-08-07 Thread Andy Balholm
On Aug 7, 2014, at 9:30 AM, Andy wrote: > I have no idea whether I have shell access. I don't even know what that > is. Sorry. Shell access means being able to log into their server and get a command prompt, so that you can do configuration that isn’t supported by their con

Re: Spam Assassin - does it work or not? - LONG HEADERS URL

2014-08-07 Thread Andy
h anyway. Maybe it will push them into doing something. Andy On Thu, August 7, 2014 9:24 am, Bowie Bailey wrote: > On 8/7/2014 12:05 PM, Andy wrote: > >> As requested, here are 5 long headers, just taken at random. I can >> provide more if needed. >> >> http://pasteb

Spam Assassin - does it work or not? - LONG HEADERS URL

2014-08-07 Thread Andy
n the matter. As I say, I have not seen any false deletions of legitimate emails except when Lunarpages was sending me sample spam, or their replies had sample headers in them. Andy

Spam Assassin - does it work or not?

2014-08-07 Thread Andy
- equal to or greater per day than what is getting called "spam". I would appreciate any insights anyone can offer to me, or for that matter to Lunarpages because I'm not clear that even they understand what is going on, nor how to fix this very nagging problem. Sincerely, Andy

Re: rule for repeated tracking numbers

2014-08-06 Thread Andy Balholm
On Aug 6, 2014, at 2:00 PM, Axb wrote: > Suggest you use a local DNS resolver instead of some third party which is > getting in your way. Good idea. I installed unbound, and configured it to not use Google’s nameservers (which were the ones that were blocked). Now uribl seems to be working.

Re: rule for repeated tracking numbers

2014-08-06 Thread Andy Balholm
On Aug 6, 2014, at 12:00 PM, John Hardin wrote: > Can some fresh samples be posted to pastebin? http://pastebin.com/DWiTYmPN is my complete collection of 24 spams with this pattern received this week. Collect them all!

Re: rule for repeated tracking numbers

2014-08-05 Thread Andy Balholm
On Aug 5, 2014, at 11:16 AM, John Hardin wrote: > It can hit on embedded phone numbers, which are, strictly speaking, valid > hexadecimal strings... > I suspect it's hitting on all those dates as well, and needs some more > tightening. In the spams I’m looking at, all the hex strings are 32 c

Re: rule for repeated tracking numbers

2014-08-05 Thread Andy Balholm
On Aug 5, 2014, at 10:48 AM, John Hardin wrote: > Unfortunately the masscheck pages' links to SVN got broken in the recent > rebuild. > > That rule lives here: > > https://svn.apache.org/viewvc/spamassassin/trunk/rulesrc/sandbox/jhardin/20_misc_testing.cf?view=log > > It should be part of th

Re: rule for repeated tracking numbers

2014-08-05 Thread Andy Balholm
On Aug 5, 2014, at 10:31 AM, John Hardin wrote: > > There's already a rule for this sort of thing in the sandbox. > > http://ruleqa.spamassassin.org/20140804-r1615505-n/HEXHASH_WORD/detail How do I find the actual rule that the page is about?

Re: Pattern SPAM seen today with full-name ending with dot-digits.

2014-08-05 Thread Andy Balholm
On Aug 5, 2014, at 10:16 AM, Philip Prindeville wrote: > Saw the following SPAM: > > http://pastebin.com/eLm1iRpN That’s the same group of spams that I just posted a rule for, but I’m looking at the repeated numbers in the last paragraph.

rule for repeated tracking numbers

2014-08-05 Thread Andy Balholm
The last few days, I’ve been getting a lot of spams that have a similar pattern. They are plain-text messages, and each one ends with a paragraph from a restaurant review (apparently to confuse bayesian filters), with some numbers inserted. There is an 8-digit decimal number and a 32-digit hex o

Increase in Image Spam

2014-02-11 Thread Andy Jezierski
to try and catch them? They don't really hit on any rules X-Spam-Status: No, score=3.5 required=5.0 tests=BAYES_99,HTML_MESSAGE, SPF_HELO_PASS,SPF_PASS autolearn=no autolearn_force=no version=3.4.0-rc5 Thanks Andy

Re: Help with a regex to catch spam with gibberish html tags

2014-01-30 Thread Andy Jezierski
Amir Caspi wrote on 01/30/2014 11:39:51 AM: > From: Amir Caspi > To: "Kevin A. McGrail" , > Cc: Andy Jezierski , > "users@spamassassin.apache.org" > Date: 01/30/2014 11:40 AM > Subject: Re: Help with a regex to catch spam with gibberish html tags >

Re: Help with a regex to catch spam with gibberish html tags

2014-01-30 Thread Andy Jezierski
Amir Caspi wrote on 01/29/2014 11:08:18 AM: > From: Amir Caspi > To: Andy Jezierski , > Cc: "users@spamassassin.apache.org" > Date: 01/29/2014 11:08 AM > Subject: Re: Help with a regex to catch spam with gibberish html tags > > On Jan 29, 2014, at 9:53 AM, &q

Re: Help with a regex to catch spam with gibberish html tags

2014-01-29 Thread Andy Jezierski
John Hardin wrote on 01/29/2014 12:34:29 PM: > From: John Hardin > To: users@spamassassin.apache.org, > Date: 01/29/2014 12:35 PM > Subject: Re: Help with a regex to catch spam with gibberish html tags > > On Wed, 29 Jan 2014, Joe Quinn wrote: > > > On 1/29/20

Help with a regex to catch spam with gibberish html tags

2014-01-29 Thread Andy Jezierski
I've been noticing a lot of spam getting through with the same traits, a bunch of random words within brackets. They all seem to come after the or the tag. Anyone much more knowledgeable than me care to assist with a rule to detect them? Thanks Andy Example:

Re: sa-learn error

2014-01-21 Thread Andy Jezierski
Must have had a brain fart, I could have sworn I've done it that way for years. Thanks Andy From: Mark Martinec To: users@spamassassin.apache.org, Date: 01/21/2014 10:17 AM Subject:Re: sa-learn error > $ sa-learn --help > -f file Read list of files/direc

Re: sa-learn error

2014-01-21 Thread Andy Jezierski
That contains the mailbox file with about 30 spam messages I'm trying to learn. Andy From: Mark Martinec To: users@spamassassin.apache.org, Date: 01/21/2014 10:02 AM Subject:Re: sa-learn error > Inkove it the same as I've done for years: > sa-learn -

Re: sa-learn error

2014-01-21 Thread Andy Jezierski
Mark Martinec wrote on 01/20/2014 09:20:51 PM: > From: Mark Martinec > To: users@spamassassin.apache.org, > Date: 01/20/2014 09:21 PM > Subject: Re: sa-learn error > > Andy Jezierski wrote: > > Tried doing an sa-learn on some spam messages that didn't get fl

sa-learn error

2014-01-20 Thread Andy Jezierski
age(s) examined) Is this something new the spammers are doing to try and beat bayes? Thanks Andy

Re: SA 3.4.0rc5 Redis DB Help

2014-01-16 Thread Andy Jezierski
t; 0.000 0 3 0 non-token data: bayes db version > 0.000 0 16481050 0 non-token data: nspam > 0.000 05690858 0 non-token data: nham > > > bayes_token_ttl 864000 > bayes_seen_ttl 2d > > > >

SA 3.4.0rc5 Redis DB Help

2014-01-16 Thread Andy Jezierski
Are there any instructions in setting up the Bayes DB using a Redis server? I've installed the server, took the sample config options and added them to local.cf bayes_store_module Mail::SpamAssassin::BayesStore::Redis bayes_store_module_additional Mail::SpamAssassin::Util::TinyRedis bayes_sql_

Re: HK_LOTTO hitting ham from the UK national lottery

2012-10-31 Thread Andy Jezierski
> -- > Best regards, > Niamh mailto:ni...@fullbore.co.uk > [attachment "attyxplb.dat" deleted by Andy Jezierski/Stepan/US] Your message scored a 7.1 on my system. All the same rules hit except I don't use AWL which subtracted 2.1 on your system. I

syswrite() to parent failed:

2012-05-24 Thread Andy Jezierski
perl5/site_perl/5.14.2/Mail/SpamAssassin/SpamdForkScaling.pm line 579. FreeBSD 8.2 perl 5.14.2_2 SA 3.3.2_6 Any ideas? Thanks Andy

Bayes R/W Lock problem

2012-04-12 Thread Andy Jezierski
Started happening a month or so ago. Every now and then out of the blue I'll get the following error: spamd[61494]: bayes: cannot open bayes databases /usr/local/spamd/bayes_* R/W: lock failed: Interrupted system call This causes scans to take 40-60 seconds to complete as they seem to wait t

Re: sa users list down due to irene?

2011-08-29 Thread Andy Jezierski
one post on the 27th and this post. Last post on the 26th was about 4:30CDT. Andy

Re: Test port for SpamAssassin for Freebsd

2011-06-24 Thread Andy Jezierski
; I have uploaded a test port for anyone who wants to try it. > http://www.secnap.com/downloads/sa332_unofficial.tgz > Running fine on FreeBSD 8.2 i386 Perl 5.10.1 Andy

Additional sa-update channels

2010-12-15 Thread Andy Jezierski
be used. I know a lot of them have been merged into SA and some are outdated and recommended not to be used. Thanks Andy

Re: Should Spamhaus default to disabled?

2010-06-12 Thread Andy Dills
On Sat, 12 Jun 2010, Yet Another Ninja wrote: > On 2010-06-12 15:20, Andy Dills wrote: > > 300,000 queries per day...per server? per CIDR? What is the delimiter? > > > > Because there is certainly no single IP generating 300,000 queries per day. > > That is pro

Re: Should Spamhaus default to disabled?

2010-06-12 Thread Andy Dills
On Sat, 12 Jun 2010, Karsten Br�ckelmann wrote: > On Sat, 2010-06-12 at 00:19 -0400, Andy Dills wrote: > > On Fri, 11 Jun 2010, Karsten Bräckelmann wrote: > > > The most important argument for me to keep it enabled by default is > > > simple. Small organizations and

Re: Should Spamhaus default to disabled?

2010-06-11 Thread Andy Dills
On Fri, 11 Jun 2010, Karsten Br?ckelmann wrote: > On Fri, 2010-06-11 at 10:42 -0400, Andy Dills wrote: > > score URIBL_DBL_SPAM 0 > > score URIBL_DBL_ERROR 0 > > score RCVD_IN_ZEN 0 > > > > I think those are the only queries that generate lookups against Sp

Should Spamhaus default to disabled?

2010-06-11 Thread Andy Dills
y have the right to charge for their data, but I question whether it's appropriate for an open-source project to generate sales leads in this manner. Andy --- Andy Dills Xecunet, Inc. www.xecu.net 301-682-9972 ---

Re: A few questions

2010-06-10 Thread Andy Dills
ad'; $sysret = system("$update"); if (!$sysret) { print "New rules!\n"; $compret = system("$compile"); if (!$compret) { print "Compiled Correctly!\n"; system("$amavis"); } } Andy --- Andy Dills Xecunet, Inc. www.xecu.net 301-682-9972 ---

Re: Spamassasin as a gateway filter for Exchange

2010-05-19 Thread Andy Dorman
addresses? I know Postfix is very flexible in that regard. No clue about Exchange. Good luck. -- Andy Dorman Ironic Design, Inc. AnteSpam.com, HomeFreeMail.com, ComeHome.net

Re: SMTP REJECT after DATA

2010-03-09 Thread Andy Dorman
spheric scores. So even if we can decide an email is spam before the DATA stage, it makes no difference since we have to store the thing for a while anyway in case the user wants to look for something caught that shouldn't be. Cheers, -- Andy Dorman Ironic Design, Inc. AnteSpam.com, HomeFreeMail.com, ComeHome.net

Re: new spam image with random body message

2009-06-17 Thread Andy Dorman
rries if this group can not find a pattern to check for. Sometimes the ONLY way to catch a spam is to deal with it based on the MTA sender characteristics. -- Andy Dorman Ironic Design, Inc. AnteSpam.com, HomeFreeMail.com, ComeHome.net

Re: Suggested Change For FS_TEEN_BAD

2009-06-16 Thread Andy Dorman
|ass(?:es|fuck(?:ing|ed)?|whip(?:ping|ped)?|spank(?:ing|ed)?)?|fuck(?:ing|ed)?|rap(?:e|ed|ing)+)\b/i describe FS_TEEN_BAD Subject says something bad about girls or boys ##} FS_TEEN_BAD -- Andy Dorman Ironic Design, Inc. AnteSpam.com, HomeFreeMail.com, ComeHome.net

Re: Suggested Change For FS_TEEN_BAD

2009-06-16 Thread Andy Dorman
s|fuck(?:ing|ed)?|whip(?:ing|ped)?|spank(?:ing|ed)?)?|fuck(?:ing|ed)?|rap(?:e|ed|ing)+)\b/i describe FS_TEEN_BAD Subject says something bad about teens, girls, boys, others ##} FS_TEEN_BAD Thank you again. -- Andy Dorman Ironic Design, Inc. AnteSpam.com, HomeFreeMail.com, ComeHome.net

Re: Suggested Change For FS_TEEN_BAD

2009-06-16 Thread Andy Dorman
quot; and cover as many variations as I could think of. :-) As written above, this still triggers on the original email that set off this quest. And I think with the most recent changes it will be very unlikely to FPs. But those could always be "famous last words". Did I

Re: Suggested Change For FS_TEEN_BAD

2009-06-15 Thread Andy Dorman
e in 72_active.cf that detects this. That's all Andy was talking about. There's an existing rule and he proposed an update that would make it more effective to do *what it is already designed to do* Exactly. I should have started with that point. I apologize for starting off on a tangent w

Re: Barracuda Blacklist

2009-06-05 Thread Andy Dorman
BUZZHOST_STINGER wrote: On Sun, 2009-05-31 at 14:39 -0600, LuKreme wrote: On 29-May-2009, at 07:32, Andy Dorman wrote: 1. I could not find out WHY our IPs (we have a block of 32 for the cluster of servers that my email was being sent from) were being listed I do have to add this would be

Re: Barracuda Blacklist

2009-06-02 Thread Andy Dorman
is at all typical of this community, that will be useful time-saving information for us indeed. Bob, I can not speak for anyone else, but rest assured his juvenile response did NOT represent me. Cheers, -- Andy Dorman Ironic Design, Inc. AnteSpam.com, HomeFreeMail.com, ComeHome.net

Re: Barracuda Blacklist

2009-05-29 Thread Andy Dorman
place). But happy about it none the less. However, I do still feel it is a little self-serving to block someone and then "offer" to unblock them for money. Thank you Neil for pointing out what I missed. -- Andy Dorman Ironic Design, Inc. AnteSpam.com, HomeFreeMail.com, ComeHome.net

Re: Barracuda Blacklist

2009-05-29 Thread Andy Dorman
ts. And NOBODY wins when it gets to that point. Just wanted you to have ALL the facts when considering emailreg.org. -- Andy Dorman Ironic Design, Inc. AnteSpam.com, HomeFreeMail.com, ComeHome.net

Re: Image spam and failing rule

2009-04-27 Thread Andy Spiegl
ried without success: mimeheader NAMELESSGIF_ATTACHMENT Content-Type =~ /image\/gif;\n[^a-z]+name=""/ But this seems to work: mimeheader NAMELESSGIF_ATTACHMENT Content-Type =~ /image\/gif;\s*(\n\s+)?name=""/ Whadya think? Thx, Andy.

Re: Bot spam increasing?

2009-04-24 Thread Andy Dorman
Marc Perkel wrote: Has anyone else noticed an increase in bot spam? My black list has grown by about 1/3 in the last month. We have seen an increase of over 50% in spam volume this month. A lot of it does seem to be coming from bots. -- Andy Dorman Ironic Design, Inc. AnteSpam.com

Re: Botnet FPs from Webmail Senders

2009-01-28 Thread Andy Dorman
ived: from rbn1s-216-180-93-118.adsl.hiwaay.net (rbn1s-216-180-93-118.adsl.hiwaay.net [216.180.93.118]) by mail.homefreemail.com (Horde Framework) with HTTP; Fri, 23 Jan 2009 16:03:43 -0600 Message-ID: <20090123160343.74244lrgx7cvq...@mail.homefreemail.com> Date: Fri, 23 Jan 2009 16:03:43

Botnet FPs from Webmail Senders

2009-01-28 Thread Andy Dorman
Botnet to do is recognize that this is an HTTP transaction, not smtp, and hence not hit on it. We were first wondering if anyone else has encountered this issue and possibly there is a fix we are not aware of? Otherwise, we would be willing to give a shot at a patch to handle this issue. J

Re: Getting hammered by backscatter - possible solution: vbounce ?

2008-11-03 Thread Andy Spiegl
nbetween somehow... Thanks, Andy. -- No matter how long or how hard you shop for an item, after you've bought it, it will be on sale somewhere cheaper.

Re: Getting hammered by backscatter - possible solution: vbounce ?

2008-11-03 Thread Andy Spiegl
gree with Karsten (or Guenther?) that we shouldn't raise the score. But my problem is that I cannot explain to all of my users how to setup a filter for this SA-tag in their MUA or in smartsieve. They either can't or don't want to know such deeply technical things. :-( Thx, Andy.

Re: Getting hammered by backscatter - possible solution: vbounce ?

2008-11-03 Thread Andy Spiegl
t's a good idea or not. How is your experience with vbounce? Is it safe enough? (the ML archives don't show too many complaints...) Anyone out there who raised the score of ANY_BOUNCE_MESSAGE and did not drown in user complaints? :-) Thanks, Andy. -- There are so many ways to descri

Re: Any other tuning tricks or is this it?

2008-10-17 Thread Andy Sutton
On Fri, 2008-10-17 at 08:44 -0500, Len Conrad wrote: > "Swap: " is a blank line Is swap enabled? (swapon -a) It should have something on the line if nothing is used like: Swap: 4000176k total,0k used, 4000176k free, 415556k cached -- -Andy But remember, the brick wa

  1   2   3   4   5   >