Re: Whitelist or BAYES?

2024-10-01 Thread Bill Cole
ble ones, but they don't result in many false positive *final scores* for most people. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: ATTENTION: DNSWL to be disabled by default.

2024-09-24 Thread Bill Cole
icted open DNS > server that returns to the client, in response to a query, the IP address of > the DNS host from where the query originated.  Sort of like the old, > never-used, TCP Echo service. > > Of course, the devil is in the details.  But I like your thinking Matus :)  > My mind is about as sharp as a cooked linguine noodle. I'm sure there are a > lot of people out there that can conjure up better solutions. As I said in a previous message: patches are welcomed. -- Bill Cole

Apology (was Re: ATTENTION: DNSWL to be disabled by default.)

2024-09-24 Thread Bill Cole
On 2024-09-24 at 09:13:16 UTC-0400 (Tue, 24 Sep 2024 09:13:16 -0400) Bill Cole is rumored to have said: > On 2024-09-24 at 04:18:06 UTC-0400 (Tue, 24 Sep 2024 10:18:06 +0200) > Matthias Leisi > is rumored to have said: > (Quoting me) >>> >>> people who don'

Re: ATTENTION: DNSWL to be disabled by default.

2024-09-24 Thread Bill Cole
obvious error. > > Tom > > On Tue, Sep 24, 2024 at 10:16 AM Peter Ajamian > wrote: > >> On 24/09/24 05:02, Bill Cole wrote: >>> Note >>> that as of 2024-03-01 (as documented at the DNSWL link above) they have >>> reduced the free limit to 10

Re: ATTENTION: DNSWL to be disabled by default.

2024-09-24 Thread Bill Cole
stently go above the >>> limits, sometimes for months and years after receiving the blocked response. > > On 24.09.24 09:13, Bill Cole wrote: >> I don't see how that's significant. The documented policy is directly and >> intentionally harmful to users. > >

Re: ATTENTION: DNSWL to be disabled by default.

2024-09-24 Thread Bill Cole
functioning MTA to accept external mail, SA strives to NOT enable dangerous 3rd-party tools by default. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: ATTENTION: DNSWL to be disabled by default.

2024-09-23 Thread Bill Cole
s. This is partly because we are considerate of the fact that we have users who build on top of the mostly-stable default rules. It is also because we are all volunteers, with lives and jobs that generally take priority over making SA better. Regards,G ____ From:

ATTENTION: DNSWL to be disabled by default.

2024-09-23 Thread Bill Cole
you want to use DNSWL is very much a local choice. At 10k queries/month, MOST sites will need to either register (and likely pay DNSWL) or leave the rules disabled. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses

Re: Disable validity rules

2024-09-23 Thread Bill Cole
://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. RCVD_IN_VALIDITY_SAFE_BLOCKED ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. Thanks! -- Bill Cole b

Re: Tips on training bayes?

2024-09-19 Thread Bill Cole
scored rules and sub-rules and multiple shared reputation tests. A single test (such as Bayes) being wrong is not a flaw, it is an inescapable attribute of SA's design. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Use of uninitialized value $response[0]

2024-09-17 Thread Bill Cole
ndicates that you are running an obsolete 3.4.x version. The likely root cause there is the lack of any reply from the Pyzor server, which is unlikely to be a per-user condition. -- Bill Cole

Noise Around This List (was Re: Bayes in V4 compared to V3)

2024-09-13 Thread Bill Cole
On 2024-09-13 at 09:13:58 UTC-0400 (Fri, 13 Sep 2024 15:13:58 +0200) Benny Pedersen is rumored to have said: Bill Cole skrev den 2024-09-13 15:03: Please send any replies to the list only. unsubscribe listarchivers ? and make archived on apache.org with bugzilla login don't know

Re: Bayes in V4 compared to V3

2024-09-13 Thread Bill Cole
9-13 at 05:00:17 UTC-0400 (Fri, 13 Sep 2024 09:00:17 +) Grega is rumored to have said: Do you have V3 or V4 SA? From: Reindl Harald (privat) Sent: Friday, 13 September 2024 10:57 To: Grega; Bill Cole; Grega via users Subject: Re: Bayes in V4 compared to V3

Re: Bayes in V4 compared to V3

2024-09-12 Thread Bill Cole
d lack adequate ham and spam counts, you get no BAYES hits. Also, if you have any rules set to "shortcircuit" they can cause SA to stop checking before Bayes is done. I *think* I've also seen Bayes skip on excess load, with too much lock contention on a file-based mechanism like

Re: M365 phish with USER_IN_DKIM_WHITELIST

2024-08-30 Thread Bill Cole
lives and of history. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: QR phish missed

2024-08-16 Thread Bill Cole
itten by systems you don't control or have some sort of explicit relaying arrangement with. Because the initial submission of messages CANNOT be subjected to SPF tests, you don't want to test transactions that are not following an MX record. -- Bill Cole b...@scconsult.com or bill

Re: Blocking Malformed "From" Headers

2024-07-18 Thread Bill Cole
reject it entirely. Thanks, Kirk Remove FEATURE(always_add_domain) from your .mc and remake sendmail.cf. Consult the Ops guide and/or cf/README for all of the effects of that. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: X-Amavis-Alert: BANNED, message contains x.com

2024-07-16 Thread Bill Cole
? ask on amavis maillist are spamassassin using extractext ? asking to be sure That is NOT a SpamAssassin message, as SA does nothing so silly. It is clearly and strictly an Amavis issue. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many

Re: Requesting help, sa-update, cron, gpg, unsafe ownership on homedir

2024-07-12 Thread Bill Cole
those keys belong to someone else. I cannot recall now, why I set owner to spamd. maybe spamd could not read the gpg keys when trying an update before? Why would a program run as root need that? -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@bi

Re: whitelist_auth return_path / from

2024-07-03 Thread Bill Cole
, Simon, quote the text you are replying to.   I have been - was that directed at Benny?   No, it is because your mail is multipart/alternative with a text/plain part that lacks any indicators of quoting. Looks like your MUA is broken. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA

Re: ChatGPT > Spamassassin? :)

2024-06-25 Thread Bill Cole
m for feeding FPs into both a sitewide Bayes DB and into the AWL/TxRep DB by using the blocklist/welcomelist options of the spamassassin script. On 6/25/2024 11:21 AM, Bill Cole wrote: Mark London is rumored to have said: I received a spam email with the text below, that wasn't

Re: ChatGPT > Spamassassin? :)

2024-06-25 Thread Bill Cole
o way to remove any particular ingested data. There's no way to know where any particular LLM will have problems and no way to fix those problems. This all puts them outside of the boundaries we have as an ASF project. However, we do have a plugin architecture, so it is possible for 3rd parties

Re: Questions about spamassassin

2024-06-21 Thread Bill Cole
Message-ID > bayes_ignore_header Resent-Subject > bayes_ignore_header Resent-To > > I think that first line looks problematic. I agree. The spurious # would generate precisely the error message you got. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.soci

Re: Questions about spamassassin

2024-06-20 Thread Bill Cole
do with permissions or ownership. There's an error in local.cf. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Docs confusion and missing dependency on EL9

2024-06-19 Thread Bill Cole
age should have a link for INSTALL like it already has for the Upgrade. And I would say "Where to download" and "How to install" are pretty common FAQs, too. Indeed. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: BayesStore MariaDB on EL9

2024-06-18 Thread Bill Cole
nt(11) NOT NULL DEFAULT 0,   `atime` int(11) NOT NULL DEFAULT 0,   PRIMARY KEY (`id`,`token`),   KEY `bayes_token_idx1` (`id`,`atime`) ) ENGINE=InnoDB DEFAULT CHARSET=latin1 COLLATE=latin1_swedish_ci 1 row in set (0.000 sec) Any idea what goes wrong here? Thanks, Gerald -- Bill Cole

Re: Where are your test definitions?

2024-06-14 Thread Bill Cole
ell checks in another. However, I can see in the journal that every mail is checked against blocklists, may be not completly? This difference is now irritating me. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Where are your test definitions?

2024-06-14 Thread Bill Cole
through the current files in the repo: https://svn.apache.org/viewvc/spamassassin/trunk/rules/ and https://svn.apache.org/viewvc/spamassassin/trunk/rulesrc/sandbox/ -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses

Re: Warning: Your Pyzor may be broken.

2024-06-08 Thread Bill Cole
On 2024-06-08 at 15:35:01 UTC-0400 (Sat, 08 Jun 2024 21:35:01 +0200) Benny Pedersen is rumored to have said: > Bill Cole skrev den 2024-06-08 20:45: > >> I've chosen #3 for myself, but it's not great. > > is why cpanel provided a perl pyzor client ? I had forgotten

Warning: Your Pyzor may be broken.

2024-06-08 Thread Bill Cole
k with Python 3. 3. Install the head of the development tree from GitHub, whatever that happens to be at the moment. I've chosen #3 for myself, but it's not great. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: [mailop] SORBS Closing.

2024-06-07 Thread Bill Cole
amasssassin.org rules channel earlier this week. Scanning the latest deployed (by sa-update) version r1918114 I see no surviving references to SORBS. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: RCVD_IN_RP_CERTIFIED always -3

2024-06-07 Thread Bill Cole
iently. This is especially true if you use rulesets from that era, which have known (and fixed in trunk) runaway problems and obsolete DNSBL configs. There may also be a problem running sa-update from 3.4.4 because we have abandoned SHA1 signatures. I'm not sure if 3.4.4 included the changes

Re: DKIM length 'l=' tag

2024-06-03 Thread Bill Cole
BIMI should be broken now and with every opportunity available. It is an indicator that a MUA author puts the interests of marketers ahead of the interests of users. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Lots of FN because of VALIDITY* rules

2024-06-03 Thread Bill Cole
It is irrelevant to an operational deployment. I have no idea why Debian installs that file at all. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Lots of FN because of VALIDITY* rules

2024-06-03 Thread Bill Cole
SA updates include the active rules list in the form of the 72.active.cf file. The active.list file is not part of normal operations. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: TxRep does not read setting|default value

2024-05-30 Thread Bill Cole
On 2024-05-30 at 03:58:18 UTC-0400 (Thu, 30 May 2024 16:58:18 +0900) Tomohiro Hosaka is rumored to have said: > Hello. > > The code seems to be wrong. I do not believe that to be so. See lines 340-347 in TxRep.pm. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @g

Re: "deadline shrunk" in logs ?

2024-05-27 Thread Bill Cole
l pending DNS queries were complete and before the fixed timeout deadline was reached. The most common cause is a DNS-based rule configured to shortcircuit while other queries are outstanding. -- Bill Cole

Re: Extract Local-part from To: Adress to use in spamassassin rule

2024-05-23 Thread Bill Cole
in one rule and use it in another. I don't have a working rule for you, but that's the mechanism I would use. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: double backslash in the log messages

2024-05-21 Thread Bill Cole
have all common meta-characters escaped. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Difference between spamc -L and sa-learn

2024-05-18 Thread Bill Cole
expensive to execute perl and have it load the many SpamAssassin modules needed to learn a message. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Error parsing sql configuration

2024-05-18 Thread Bill Cole
e = CONCAT('%',_DOMAIN_) ORDER BY username ASC Is there a bug when parsing the preferences from sql? It's not really a parsing error, it's a configuration error. You cannot set "use_pyzor" or "use_razor" in user preferences, as they are both res

Re: SA treats percentage spaces wording as uri

2024-05-14 Thread Bill Cole
It shouldn't be assuming there's a TLD after it. I agree. That's a step too far. The days when appending .com was a reasonable tactic for qualifying hostnames are long gone. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@bil

Re: dkim https://16years.secvuln.info/

2024-05-13 Thread Bill Cole
ncompetent system administration, not bad code or distribution config. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Score 0.001

2024-05-11 Thread Bill Cole
more active site-specific rule management (and FP avoidance) than most systems ever receive. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Score 0.001

2024-05-10 Thread Bill Cole
On 2024-05-10 at 14:15:56 UTC-0400 (Fri, 10 May 2024 14:15:56 -0400) Bill Cole is rumored to have said: > On 2024-05-09 at 18:19:14 UTC-0400 (Thu, 9 May 2024 15:19:14 -0700) > jdow > is rumored to have said: > >> On 20240509 15:05:46, Thomas Barth wrote: >>> Am 2024

Re: Score 0.001

2024-05-10 Thread Bill Cole
enough performers to get included in the daily active list will still be pulled into the active list with a trivial score if derivative meta rules which are good enough for real scores depend on them. -- Bill Cole

Re: Score 0.001

2024-05-10 Thread Bill Cole
other meta rules that have more significant scores, but are not significantly spam or ham signs on their own. -- Bill Cole

Re: Rule: "1.0 R_DCD 90% of .com. is spam"

2024-05-10 Thread Bill Cole
ell enough to in the active list. If your system generated that hit, it is one of your own local rules. If it came from elsewhere, ask them. -- Bill Cole

Re: Whitelist rules should never pass on SPF fail

2024-05-10 Thread Bill Cole
sparent forwarding to adopt SRS or any other mechanisms to avoid SPF breakage to ever change. There is no ROI in trying to fix such cases individually but users still want their college email addresses to work decades after graduating and some colleges have pandered to them. So have some professional

Re: Using -t to test rule changes

2024-05-09 Thread Bill Cole
ine changes and redo the pre-check prep. It may be relevant what you have set report_type to in your local config. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo@toad.social and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Whitelist rules should never pass on SPF fail

2024-05-09 Thread Bill Cole
On 2024-05-09 at 08:37:06 UTC-0400 (Thu, 09 May 2024 14:37:06 +0200) Benny Pedersen is rumored to have said: Bill Cole skrev den 2024-05-09 14:22: In fact, I can't think of any whitelist test that should pass if SPF fails. If you operate on the theory that a SPF failure is always a si

Re: Whitelist rules should never pass on SPF fail

2024-05-09 Thread Bill Cole
ive to make SA stop processing later rules if a specific rule hits. This will also skip any other 'late' checks, so you have to set priorities with care to avoid shortcircuiting rules that you want checked. Consult the docs for details. -- Bill Cole b...@scconsult.com or billc...@ap

Re: Tips for improving bounce message deliverability?

2024-04-24 Thread Bill Cole
ge which matches BOUNCE_MESSAGE (and hence also ANY_BOUNCE_MESSAGE) is fairly unlikely to be spam, but we have pegged the scores for all the *BOUNCE_MESSAGE rules at 0.1 just to make sure that they are always published and visible as control points that can be used by sites that have a particular need to accept (or shun) some or all bounces. -- Bill Cole

Re: Defining what the default welcomelist means

2024-04-14 Thread Bill Cole
I believe we are in solid agreement, a few notes below explaining how... On 2024-04-14 at 08:00:19 UTC-0400 (Sun, 14 Apr 2024 08:00:19 -0400) Greg Troxel is rumored to have said: > Bill Cole writes: > >> On 2024-04-12 at 18:56:15 UTC-0400 (Fri, 12 Apr 2024 18:56:15 -0400) &g

Re: Defining what the default welcomelist means

2024-04-13 Thread Bill Cole
you pull the "spammer" trigger. YMMV and YAMV (Attitude). FWIW, we can't maintain SA to accommodate the obstinacy of gated BITNET LISTSERV nodes in '89. The only reasons for unsub difficulties in 2024 are technical failures and spammer excuses. Modern SpamAssassin is only suppo

Re: Defining what the default welcomelist means

2024-04-13 Thread Bill Cole
how the default welcomelist has lost alignment with its origins. The original was a tactical mitigation against heavy phishing in a largely unauthenticated-sender world, deployed in part to forestall extreme responses to the problem of everyone claiming to send Paypal notifications to everyone. --

Re: Defining what the default welcomelist means

2024-04-13 Thread Bill Cole
On 2024-04-12 at 18:56:15 UTC-0400 (Fri, 12 Apr 2024 18:56:15 -0400) Greg Troxel is rumored to have said: > I see it very slightly differently, but mostly agree > > Bill Cole writes: > >> 1. We serve our users: receivers, not senders. Senders claiming FPs >> need the su

Re: Dynamic blacklist ?

2024-04-12 Thread Bill Cole
so that everyone uses the same AWL DB, you could do this if you have a directory full of fresh spam whose senders you want to shun: cd $spamdirectory spamassassin --add-to-blocklist * And if you have a bunch of mail you value in a directory, use "-W" instead. -- Bill Co

Defining what the default welcomelist means

2024-04-12 Thread Bill Cole
RuleQA testing of sender-specific rules before being added to the default welcomelist. As with everything SpamAssassin: input from users and other contributors is eagerly desired..., -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

WARNING: Microsoft has earned removal from SA default welcomelist

2024-04-12 Thread Bill Cole
for inclusion have never been promulgated and accepted by the PMC or the user community. More to follow in a separate thread. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: problems with Plugin::ASN and spam

2024-04-11 Thread Bill Cole
ang' have appropriate configs? > Both sa0 & sa1 run the same spamassassin/spamd configurations, neither of > them add the X-Spam-ASN headers. All other add_header entries work fine. Validate that configs on both machines match. In this sort of setup, only the SA config on the spamd hosts of the user spamd is run as makes any difference. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: problems with Plugin::ASN and spam

2024-04-10 Thread Bill Cole
e debug channel for config and etermine which config files are actually being used by spamd and by spamassassin. (spamc knows nothing of SA configs...) -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: OT: Trigger words in email addresses?

2024-04-09 Thread Bill Cole
t messages instead of complex multipart/alternative messages with HTML or (WORSE) pure HMTL. Modern MUAs recognize URLs in plaintext and for basic confirmations like this, you should keep the message as simple, clear, and unadorned as possible. -- Bill Cole b...@scconsult.com or billc...@apa

Re: Multiple test failures

2024-04-03 Thread Bill Cole
g the port spamd uses for testing. That is rare because it selects an unused high port on the loopback interface for the test run, but if you have a very tight network security policy in place, that can fail. SELinux and AppArmor can also interfere. Thanks Tuc On Wed, Apr 3, 2024 at 10:46 AM

Re: Syslog local3

2024-04-03 Thread Bill Cole
amd, the facility is set with the "-s" option, as documented in the man page. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Multiple test failures

2024-04-03 Thread Bill Cole
in database = 0 0 non-token data: nspam at t/spamd_client.t line 186. # Failed test at t/SATest.pm line 926. t/spamd_client.t .. 52/52 # Looks like you failed 14 tests of 52. t/spamd_client.t .. Dubious, test returned 14 (wstat 3584, 0xe00) Failed 14/52 subtes

Re: Doesn't spamc/spamd need block/welcomeliist support???

2024-03-21 Thread Bill Cole
On 2024-03-21 at 13:21:54 UTC-0400 (Thu, 21 Mar 2024 18:21:54 +0100) is rumored to have said: > On 3/20/24 21:58, Bill Cole wrote: >> I'm not sure how I've not noticed before, but unless I'm missing something, >> there is no way to replicate the [block,welco

Re: Doesn't spamc/spamd need block/welcomeliist support???

2024-03-21 Thread Bill Cole
On 2024-03-21 at 12:08:48 UTC-0400 (Thu, 21 Mar 2024 17:08:48 +0100) Matus UHLAR - fantomas is rumored to have said: On 20.03.24 16:58, Bill Cole wrote: I'm not sure how I've not noticed before, but unless I'm missing something, there is no way to replicate the [blo

Re: Doesn't spamc/spamd need block/welcomeliist support???

2024-03-21 Thread Bill Cole
On 2024-03-21 at 11:57:43 UTC-0400 (Thu, 21 Mar 2024 11:57:43 -0400) Kris Deugau is rumored to have said: Bill Cole wrote: I'm not sure how I've not noticed before, but unless I'm missing something, there is no way to replicate the [block,welcome]list functionalities of t

Doesn't spamc/spamd need block/welcomeliist support???

2024-03-20 Thread Bill Cole
e have any rationale for this missing functionality? I don't expect that it would be difficult to add. (Something I've believed every time I've taken on a coding task...) -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com add

Re: OT: Microsoft Breech

2024-03-19 Thread Bill Cole
ucture breech. >> >> Curiously, NOBODY has received any breach notifications from Microsoft, >> despite personal information being compromised. >> >> What has anyone else experienced? >> >> Thanks, >> >> -- Jared Hall >> -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Callout verification with SpamAssassin ?

2024-02-19 Thread Bill Cole
look at solving your real problem. All set then. SA is not the right tool for you. Try something like Exim, MailMunge, or MIMEDefang that let you write arbitrary code for the mail-handling flow. I suppose you may be able do it in sendmail.cf too, if you're into self-torture. -- Bill C

Re: Plugin fo content modification

2024-02-19 Thread Bill Cole
e tactic that proved its utter uselessness in the '90s. Aside from the fact that this would do active damage to the comprehensibility of some perfectly legitimate messages, it would invalidate any sort of authenticating signature (DKIM, PGP, S/MIME, whatever) -- Bill Cole b...@sccons

Re: SpamAssassin4 + DCC not populating "X-Spam-DCC: : " header ?

2024-02-18 Thread Bill Cole
em to have dns_available set to 'no' -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Bayes "corpus" - how old?

2024-01-31 Thread Bill Cole
15:31, Bill Cole wrote: If spammers can 'abuse' ALL_TRUSTED you have a major problem. Either a serious misconfiguration or compromised machines in trusted_networks. Can't ALL_TRUSTED happen if spammer delivers mail directly to my network, or, if last mail server removes Receive

Re: Bayes "corpus" - how old?

2024-01-30 Thread Bill Cole
sed machines in trusted_networks. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Bayes "corpus" - how old?

2024-01-30 Thread Bill Cole
tive rules. There are non-obvious fingerprints in some spam that imply decades-long spamming operations. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: install SA p a i n f u l l

2024-01-30 Thread Bill Cole
ng on the fricken machine in the fricken first place. I am not going to run cpan with force because that may hide *real* errors. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Dinged for .Date

2024-01-17 Thread Bill Cole
g independently based on a TLD is not so big. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: symlinking config files

2024-01-05 Thread Bill Cole
am puzzled by this. -- Written by Thomas Krichel http://openlib.org/home/krichel on his 21399th day. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Question about forwarding email (not specifically SA, pointers greatly appreciated)

2024-01-03 Thread Bill Cole
ing service because it is forwarding spam. If users POP their mail instead of having it forwarded via SMTP, that does not happen. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: MS-relayed spam

2024-01-02 Thread Bill Cole
nder how often that happens? I'm always interested in anonymous auth (either 'auth') X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: CO6PR20MB3698 And there's that correlating nonce again... I don't know if any of those thoughts wi

Re: Spreadsheet::Excel ?

2023-12-29 Thread Bill Cole
tupidity is non-critical. In my experience it has been workable to just reject mail with .xls and .xlsx attachments by default at any Internet-facing MX. 20+ years of warnings about how reckless it is to share MS documents ought to suffice for anyone. -- Bill Cole b...@scconsult.com or bill

Re: Bayes always reject.

2023-12-13 Thread Bill Cole
e Bayes DB with proper training. *IN THEORY* one could fix a corrupted DB by 'unlearning' messages which learned incorrectly, but as a practical matter that's usually a fantasy. Most of the scanning and DB details that you included are not useful. You cannot fix the bad DB, you n

Re: long delay with the new rules from 8 dec

2023-12-08 Thread Bill Cole
back to 5/12 and it's back to 200 ~ 5000 ms. Note: I also have some personal rules. Am I the only one seeing this? -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: proper use of internal_networks?

2023-12-07 Thread Bill Cole
re three levels of To-welcomelisting, "welcomelist_to", "more_spam_to" and "all_spam_to". Users in the first level may still get some spammish mails blocked, but users in "all_spam_to" should never get mail blocked. Th

Re: sa-learn on an Exchange public folder

2023-12-04 Thread Bill Cole
Internet, while it uses its own proprietary formats internally. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Catch a rejected message ?

2023-12-01 Thread Bill Cole
ng and its cousin MailMunge both use a unique working directory for each message, and it is trivial to just replicate that whole structure elsewhere for safekeeping. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Ava

Re: ATT RBL f---wits

2023-11-27 Thread Bill Cole
anyone else had to deal with this bullocks and gotten it resolved? Yes. Twice. Time is your friend. AT&T still operates like it's 1970... -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: spamc -L does not return 5, or 6

2023-11-08 Thread Bill Cole
it should be doing, >> except that it gives back 0 instead of 5 or 6. >> > It seems to be a documentation bug, see > https://bz.apache.org/SpamAssassin/show_bug.cgi?id=6069 and > https://bz.apache.org/SpamAssassin/show_bug.cgi?id=1201#c47 > Documentation fixed

Re: Getting error 74

2023-11-01 Thread Bill Cole
e Engineer LinkedIn: http://www.linkedin.com/in/cecilwesterhof -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: spamd: still running as root

2023-10-30 Thread Bill Cole
for asking this is the log entry, just forget about it. 'man spamd' provides more info. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: external API request

2023-10-27 Thread Bill Cole
really need it, you'd need to create it yourself. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Missing Mail::SpamAssassin::Plugin::WelcomeListSubject

2023-10-26 Thread Bill Cole
bution. Consult the author of 'w7_whitelist.cf' for support of whatever configuration it includes. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: def_welcomelist_auth versus def_whitelist_auth in 60_welcomelist_auth.cf

2023-10-12 Thread Bill Cole
* Sending60_welcomelist_auth.cf Transmitting file data .done Committing transaction... Committed revision 1912923. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

Re: Getting phishing from sender in 60_welcomelist_auth.cf

2023-10-12 Thread Bill Cole
l.com def_whitelist_auth *@*.subaru.com def_whitelist_auth *@*.aexp.com -def_whitelist_auth *@*.usssa.com def_whitelist_auth *@*.bestwesternrewards.com def_whitelist_auth *@*.email-weightwatchers.com def_whitelist_auth *@*.email-allstate.com On Thu, Oct 12, 2023 at 8:48 AM Bill Cole wrote: On

Re: Getting phishing from sender in 60_welcomelist_auth.cf

2023-10-12 Thread Bill Cole
re that we aren't open to being used for mischief and can justify the removal later if asked to. The bar for removal is very low (being listed is a privilege, not a right) but it can't be simply 'someone said...' On Wed, Oct 11, 2023 at 9:25 PM Bill Cole wrote: On 2

Re: Getting phishing from sender in 60_welcomelist_auth.cf

2023-10-11 Thread Bill Cole
60_welcomelist_auth.cf with def_welcomelist_auth/def_whitelist_auth entries with *@*.usssa.com. If anyone has a shareable sample spam to substantiate this, that would be helpful. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not

Re: Pre-processor for spamassassin

2023-10-08 Thread Bill Cole
and that would avoid the housekeeping issues of how to integrate a 'preprocessor' with your existing MTA and whatever yopu're using as 'glue' for SA. (content_filter script, spamass-milter, MIMEDefang, etc.) -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @gru

Re: Filtering emails from word-oliv...@somewhere.com

2023-10-05 Thread Bill Cole
ch one match, autolearn it as spam, and (hopefully) recognize its sibling messages as such. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Not Currently Available For Hire

  1   2   3   4   5   6   7   8   9   10   >