Re: Softlayer hostname changes

2015-10-15 Thread Bill Cole
On 15 Oct 2015, at 13:15, Joseph Brennan wrote: What is Softlayer up to now? It had looked like a safe bet to score something for a hostname ending "static.reverse.softlayer.com", on the assumption that legitimate senders would get the PTR changed to their own domain. There's always the exc

Re: SpamAssassin Rules Regarding Abuse of New Top Level Domains

2015-10-19 Thread Bill Cole
On 19 Oct 2015, at 15:22, Larry Goldman wrote: I found that much of the SPAM had a BAYES_00 score of -1.9, which was defeating the contribution of the other tests. A closer inspection of the raw source revealed invisible gibberish text which, I assume, is designed to thwart the default BAYES_0

Re: Learning only on read emails?

2015-10-19 Thread Bill Cole
On 19 Oct 2015, at 17:21, Ryan Coleman wrote: Ok so it was established I don’t have a ham scan (correct). So how do I do it so that it only scans the read emails in a MAILDIR? Assuming your delivery and client access mechanisms (IMAP4/POP3/whatever) follow standard Maildir behavior & naming,

Re: spf records and cnames

2015-10-21 Thread Bill Cole
On 21 Oct 2015, at 13:48, btb wrote: are spf records allowed to be a cname? I can't see any reason why they shouldn't be... e.g.: http://dpaste.com/0MR0R3C.txt is this explicitly addressed in an rfc? I don't believe so and there's no reason to. CNAME records trump all DNS record types f

Re: How to get rid of this spam? Spam assassin does not catch it

2015-10-27 Thread Bill Cole
On 27 Oct 2015, at 16:02, j...@lexoncom.com wrote: SO i setup the dns server. Can i force spam assassin to use localhost for dns or I must reconfigure the host? You can just change SA, but you should change the whole host to use it if your MTA is running there as well. the MTA is probably d

Re: Filtering snowshoe spam

2015-10-29 Thread Bill Cole
On 29 Oct 2015, at 11:09, Alex wrote: Hi, I've been receiving tons of messages not being tagged by spamassassin on one host, despite it hitting bayes999, and wanted to see if there was something that could be done. http://pastebin.com/vxrUdEvy As of right now, 23.246.233.6 isn't listed on zen

Re: New SA install, configuring for retraining on false positives

2015-11-05 Thread Bill Cole
On 5 Nov 2015, at 6:52, David Mehler wrote: Hello, I've got a Postfix email server going with a Mysql database backend on FreeBSD 10.2. I'm now wanting to add Spamassassin to the picture and am wondering current best practices? It's been a number of years since I did it and last time effectiven

Re: auto-learn? no: scored as spam but autolearn wanted ham

2015-11-06 Thread Bill Cole
On 6 Nov 2015, at 1:52, Matthias Apitz wrote: El día Thursday, November 05, 2015 a las 04:24:04PM +0100, John Wilcock escribió: Le 05/11/2015 15:54, Matthias Apitz a écrit : X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on c720-r276659 X-Spam-Flag: YES X-Spam-Level: **

Re: ClamAV.pm Plugin Not Working

2015-11-19 Thread Bill Cole
On 19 Nov 2015, at 5:20, Daniel L. Srebnick wrote: That means user clamscan cannot read the file eicar. This is idenepdant of the user that launchs clamdscan. Try to put eicar.txt in /tmp and make it mode 777. I did so. Clamdscan still does not see the file and returns an lstat error. I ev

Re: Trouble with SPF plugin

2015-11-19 Thread Bill Cole
On 19 Nov 2015, at 13:05, Jonathan Hilgeman wrote: I just recently noticed that I hadn't enabled the SPF plugin, so I did that and ran a quick test to test an SPF failure. However, in the resulting email, I get an SPF_HELO_PASS result and no other SPF_ test results. Did the plugin only ru

Re: question re/ RDNS_NONE

2015-11-24 Thread Bill Cole
On 24 Nov 2015, at 13:47, David Jones wrote: Could this be dependent on the MTA used? I am using Postfix which puts in Received headers like this: Received: from econnect.dmsgs.com (unknown [8.224.216.57]) That IP has a PTR record but it doesn't match the SMTP HELO of econnect.dmsgs.com so Po

Re: question re/ RDNS_NONE

2015-11-24 Thread Bill Cole
On 24 Nov 2015, at 14:54, David Jones wrote: From: Bill Cole Sent: Tuesday, November 24, 2015 1:41 PM To: users@spamassassin.apache.org Subject: Re: question re/ RDNS_NONE On 24 Nov 2015, at 13:47, David Jones wrote: Could this be dependent on the MTA used? I am using Postfix which puts

Re: Rule to match when multiple FROM addresses exist

2017-12-01 Thread Bill Cole
tive participants include the creator of Postfix and other real Postfix experts (I just play one on other lists...) -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work: https://linkedin.com/in/billcole

Re: Rule to match when multiple FROM addresses exist

2017-12-01 Thread Bill Cole
That's a good fix for a broader range of misbehaviors. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work: https://linkedin.com/in/billcole

Re: FIlter

2017-12-02 Thread Bill Cole
, research the list's actual purpose and availability. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work: https://linkedin.com/in/billcole

Re: Flakey spam email. How to filter?

2017-12-11 Thread Bill Cole
DKIM_INVALID DKIM-Signature header exists but is not valid 2.3 S25R_4 T_S25R: Bottom of rDNS ends w/ num, next lvl has num-num Note that bad Bayes score, which is because my system never sees this sort of spam. Also: I noticed something interesting in that spam that I&#

Re: check utf-8 subjects/from?

2017-12-13 Thread Bill Cole
to have to do special processing for non 7-bit ASCII headers. There's even a SA rule for that: FROM_EXCESS_BASE64 -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work: https://linkedin.com/in/billcole

Re: orphan spamd childs?

2017-12-18 Thread Bill Cole
ss trying to do anything with it gets stuck. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work: https://linkedin.com/in/billcole

Re: IADB whitelist

2017-12-25 Thread Bill Cole
tial modification on my own system to how IADB results are scored, but those specific adjustments are probably not fit for most other sites. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work: https://linkedin.com/in/billcole

Re: IADB whitelist

2017-12-26 Thread Bill Cole
r the sender to do better. My sense is that ESPs engage ISIPP thinking they are getting an advocate and ambassador to mailbox providers when in fact they get a teacher/evangelist for sender best practices. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grum

Re: IADB whitelist

2017-12-29 Thread Bill Cole
h that is not the case for SA...in fact our data response codes were *specifically* created for SA because SA *can* take advantage of that level of granularity)). As much as I dislike the single/double wording and the use of '100% opt-in' for mechanisms that are highly fallible, I am

Re: Malformed spam email gets through.

2018-01-01 Thread Bill Cole
;d happily make it break hard. HOWEVER, the idea of enforcing any standard on MIDs beyond gross format (e.g.: <[[:ascii:]]{3,996}>) on a system where the admin isn't the sole user is ludicrous. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@b

Re: Malformed spam email gets through.

2018-01-01 Thread Bill Cole
SIBLE* for a receiving system to reliably determine whether the right-hand part of a MID is a valid host or domain identifier for the generator of the MID. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking S

Re: Malformed spam email gets through.

2018-01-01 Thread Bill Cole
On 1 Jan 2018, at 10:33 (-0500), David Jones wrote: On 01/01/2018 09:29 AM, Bill Cole wrote: On 1 Jan 2018, at 9:59 (-0500), David Jones wrote: I think some mail systems will keep the same message-ID per email thread so your system must reject some replies. I have not seen such behavior in

Re: Malformed spam email gets through.

2018-01-01 Thread Bill Cole
pecification of "local" and "domain" parts. Also note that if you demand that MIDs contain '@' with conforming strings on both sides, you risk losing mail that users want. This is a mistake I have made. -- Bill Cole b...@scconsult.com or billc...@apache.org (A

Re: Malformed spam email gets through.

2018-01-01 Thread Bill Cole
On 1 Jan 2018, at 12:47 (-0500), Matus UHLAR - fantomas wrote: On 1 Jan 2018, at 11:41 (-0500), Matus UHLAR - fantomas wrote: the gross format in RFCs 822,2822 and 5322 describes message-id consisting of local and domain part, thus is must contain "@". On 01.01.18 12:17, Bill Cole

Re: Malformed spam email gets through.

2018-01-01 Thread Bill Cole
On 1 Jan 2018, at 14:30 (-0500), Alan Hodgson wrote: On Mon, 2018-01-01 at 10:29 -0500, Bill Cole wrote: [...] HOWEVER, the idea of enforcing any standard on MIDs beyond gross format  (e.g.: <[[:ascii:]]{3,996}>) on a system where the admin isn't the sole  user is ludicrous. I&

Re: Malformed spam email gets through.

2018-01-02 Thread Bill Cole
is RECOMMENDED that the right-hand side contain some domain identifier (either of the host itself or otherwise) such that the generator of the message identifier can guarantee the uniqueness of the left-hand side within the scope of that domain. >> Note the use of RFC2119 te

Re: Malformed spam email gets through.

2018-01-03 Thread Bill Cole
On 2 Jan 2018, at 20:39, Alex wrote: Is it possible to at least enforce that the message-ID has a valid domain? Not reliably. About 1.5% of my personal non-spam email over the past 20 years has had "localhost" as the right hand side of the MID. This implies a de facto RFC violation because

Re: Malformed spam email gets through.

2018-01-04 Thread Bill Cole
On 3 Jan 2018, at 15:42, @lbutlr wrote: [...] On 03 Jan 2018, at 12:36, Bill Cole wrote: About 1.5% of my personal non-spam email over the past 20 years has had "localhost" as the right hand side of the MID. This implies a de facto RFC violation because it poses a real risk of d

Re: Malformed spam email gets through.

2018-01-04 Thread Bill Cole
On 4 Jan 2018, at 21:13 (-0500), @lbutlr wrote: On 4 Jan 2018, at 11:47, Bill Cole wrote: On 3 Jan 2018, at 15:42, @lbutlr wrote: There is no requirement that the right side be globally unique, just that the entire message ID is globally unique. Right. And any software that can use

Re: FSL_MIME_NO_TEXT and MIME_NO_TEXT

2018-01-09 Thread Bill Cole
On 9 Jan 2018, at 13:47 (-0500), Matus UHLAR - fantomas wrote: this is a real duplicity... Semantic note: "duplication" or "redundancy," NOT "duplicity," which is English for the flavor of dishonesty involving contradictory statements. -- Bill Co

Re: [Bug 7331] channel: SHA1 verification failed, channel failed

2018-01-11 Thread Bill Cole
49638.tar.gz. If there was no download, the attempt to hash a nonexistent file would fail without generating a hash and emitting some error. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work:

Re: skipping nameserver '0.ns.spamhaus.org' because it is a CNAME

2018-01-14 Thread Bill Cole
s like spamhaus updated their nameserver config and added cloudflare by way of CNAME. Which is a rather surprising error. Both organizations should know better. Thankfully, all the other authoritative NS targets have A and/or records. -- Bill Cole b...@scconsult.com or billc...@apache.org (

Re: Mail flagged as spam on command line getting passed through as ham

2018-01-19 Thread Bill Cole
ass-milter, and a menagerie of scripts that pipe messages into spamc for checking by spamd. How to troubleshoot your problem is dependent on what machnism you use. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Curren

Re: Autolearn says it learned but dump magic stays at zero

2018-01-19 Thread Bill Cole
learn --dump magic    This checks the Bayes DB for the user root. root != debian-spamd You need to either run sa-learn as debian-spamd (possibly infeasible) or make root use the Bayes DB used by debian-spamd, which may be as simple as this: ln -sf ~debian-spamd/.spamassassin ~root/ -- Bil

Re: From name containing a spoofed email address

2018-01-19 Thread Bill Cole
On 19 Jan 2018, at 10:20 (-0500), Rupert Gallagher wrote: > Empty Message You're repeating yourself... -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work: https://linkedin.com/in/billcole

Re: From name containing a spoofed email address

2018-01-19 Thread Bill Cole
solved. As a byproduct of this habit of mine, when I see a "To: John" or other name than mine it's automatically spam, especially when it cannot even get the gender right. That can be useful even without a nym in the From header, although it is helpful to have a tricky name. e.

Re: From name containing a spoofed email address

2018-01-19 Thread Bill Cole
s & governance today than VWoA had a decade ago, but I doubt that. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work: https://linkedin.com/in/billcole

Re: Maxium URL acceptable length

2018-01-23 Thread Bill Cole
?) and not need to worry much about FPs. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work: https://linkedin.com/in/billcole

Re: Penalty for no/bad SPF

2018-01-24 Thread Bill Cole
On 24 Jan 2018, at 9:12, David Jones wrote: What does everyone think about slowly increasing the score for SPF_NONE and SPF_FAIL over time in the SA rulesets to force the awareness and importance of proper SPF? -1 In every real mailstream I've worked with in the lifetime of SPF, lack of SPF

Re: Pretty good spoof of AmEx

2018-01-24 Thread Bill Cole
le do blindly re-register "burner" domains that spammers have had their fill of and let expire. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work: https://linkedin.com/in/billcole

Re: Penalty for no/bad SPF

2018-01-24 Thread Bill Cole
On 24 Jan 2018, at 14:59 (-0500), David Jones wrote: On 01/24/2018 01:33 PM, Bill Cole wrote: On 24 Jan 2018, at 9:12, David Jones wrote: What does everyone think about slowly increasing the score for SPF_NONE and SPF_FAIL over time in the SA rulesets to force the awareness and importance

Re: Penalty for no/bad SPF

2018-01-24 Thread Bill Cole
s and expose them to some degree to the world. Those who have tried to change policy from inside such an organization might argue that a multiple-B SPF authorization is neither malicious nor messed up in itself, but rather merely an admission of a reality which i arguably messed up bu

Re: Make test fails on macOS High Sierra - help needed

2018-01-25 Thread Bill Cole
s or Homebrew are great alternatives for building a distinct environment of open source software (including, if you want, a current and less pathologically configured Perl environment) and can install SpamAssassin functionally. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpyboz

Re: Scoring Issues

2018-01-26 Thread Bill Cole
side of the -0.01 to 0.01 range: SPF is informative but not probative. These rules somehow got set intentionally to sabotage-level scores somewhere that only the amavisd-new process is looking. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult

Re: Body rules hit on Subject

2018-02-03 Thread Bill Cole
USIGN_BODY_NOT1ST /(?!\A).*\bdocusign\b.*\n/mi meta DOCUSIGN_BODY (HAS_SUBJECT && __DOCUSIGN_BODY_NOT1ST) || (__DOCUSIGN_BODY_1ST || __DOCUSIGN_BODY_NOT1ST) -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking

Re: Body rules hit on Subject

2018-02-03 Thread Bill Cole
On 3 Feb 2018, at 16:37 (-0500), Bill Cole wrote: On 2 Feb 2018, at 16:59 (-0500), Kevin A. McGrail wrote: There is no solution at the moment.  The subject is appended to the body of the text for rule parsing.  The 2nd sentence is wrong: the subject is *prepended* to the body. Also: the

Re: Email filtering theory and the definition of spam

2018-02-10 Thread Bill Cole
to do dumb things. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work: https://linkedin.com/in/billcole

Re: Barracuda Reputation Block List (BRBL) removal from the SA ruleset

2018-02-11 Thread Bill Cole
ld make no sense at all and require many more SOA queries than actually happen. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work: https://linkedin.com/in/billcole

Re: Email filtering theory and the definition of spam

2018-02-11 Thread Bill Cole
On 11 Feb 2018, at 16:20 (-0500), Antony Stone wrote: Strange that I can't find SMTP under www.rfc-editor.org/rfc/std/std-index.txt ‎though, other than STD0060 and STD0071, which are both extensions. STD10 is SMTP (RFC821), STD11 is message format(RFC822). -- Bill Cole b...@scconsul

Re: Train SA with e-mails 100% proven spams and next time it should be marked as spam

2018-02-13 Thread Bill Cole
On 13 Feb 2018, at 9:33, Horváth Szabolcs wrote: This is a production mail gateway serving since 2015. I saw that a few messages (both hams and spams) automatically learned by amavisd/spamassassin. Today's statistics: 3616 autolearn=ham 10076 autolearn=no 2817 autolearn=spam 134 a

Re: URIBL_BLOCKED

2018-02-15 Thread Bill Cole
ially use their connections in the same ways as home users, but it's lethal for mail systems. My provider (WOW Business) does it by default. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work: htt

Re: problem with spamassassin for WIndows

2018-02-15 Thread Bill Cole
On 15 Feb 2018, at 15:33, Gianluca Furnarotto wrote: Hi, I am trying to use Bayes with spamassassin, now it seems stop to learn, and when I use a command as "sa-learn --dump magic", or "sa-learn --sync", or other sa-learn commands, it appears this error: "Use of uninitialized value $_[1] in

Re: problem with spamassassin for WIndows

2018-02-17 Thread Bill Cole
Furnarotto (keyst...@libero.it <mailto:keyst...@libero.it>) scritto: Hi Bill, this is the result of the command you suggested to type: feb 16 07:21:09.678 [21824] warn: Use of uninitialized value $_[1] in hash eleme nt at Mail/SpamAssassin/Conf/Parser.pm line 571, line 717

Re: Junk mixed in with ham on whitelists

2018-02-20 Thread Bill Cole
who barely use email and occasional waves of transient spammers. It makes them hard to pigeonhole either way. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work: https://linkedin.com/in/billcole

Re: spamasssassin vs mimedefang scores

2018-02-22 Thread Bill Cole
On 22 Feb 2018, at 4:15, saqariden wrote: Hello guys, i'm using mimedefang with spamassasin, when I test an email with the command "spamassain -t file.eml", I got results like this: Dails de l'analyse du message: (-5.8 points, 3.0 requis) -5.0 RCVD_IN_DNSWL_HI RBL: Sender listed at

Re: Run expensive test last, and skip if meaningless

2018-02-25 Thread Bill Cole
ely to be the most uneconomic choice available to addressing your root problem. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work: https://linkedin.com/in/billcole

Re: how to grep multiline add-header X-Spam lines

2018-03-01 Thread Bill Cole
you want to use grep, you can pipe the files through an awk one-liner to unfold the headers. That works, but it is probably more convenient (if one has the procmail package installed or can install it easily and doesn't have awk syntax in the wetware) to use formmail -cs -- Bill C

Re: Spam from compromised accounts scoring just under block threshold

2018-03-05 Thread Bill Cole
On 5 Mar 2018, at 15:14, David Jones wrote: FYI This could be something for KAM.cf potentially... I have seen a few of these this morning that would be scoring just under the default SA threshold of 5.0 and are just under my MailScanner 6.0 threshold. https://pastebin.com/r2eZJaef I am re

Re: Dealing with links to malicious documents

2018-03-13 Thread Bill Cole
le links to the DEBUG_README file posted. The example provided was apparently to a directory (URL ending in '/') but redirected to a .doc. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work

Re: T_DKIM_INVALID false positives with Gmail

2018-03-19 Thread Bill Cole
On 19 Mar 2018, at 11:29, Sebastian Arcus wrote: I've been seeing a number of false positives recently from T_DKIM_INVALID with Gmail emails. Are some Gmail servers misconfigured, or could something be going on at my end? The DKIM record which is flagged as invalid is below: DKIM-Signature:

Re: Lots of money, score of 0??

2018-03-27 Thread Bill Cole
On 27 Mar 2018, at 10:24, Robert Boyl wrote: Guys, Do you usually tune up Lots of money rule? Strange, our spamassassin/EFA scores 0 and false negative. Imho it should score at least something, few people would write Million dollars in an email, why not add up score? LOTS_OF_MONEY 0.00 See

Re: This sucks

2018-04-01 Thread Bill Cole
ag --lint' will give you all the details. Figuring out what spamd is using is less simple (and system-specific) but since you've been maintaining a system by hand for a long time I expect you'll be able to figure out how to do so safely. -- Bill Cole b...@scconsult.com or

Re: This sucks

2018-04-01 Thread Bill Cole
anch or the last 3.4.2 release candidate package, or if you're adventurous, from the SVN 'trunk' that will eventually yield v4.0. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Curre

Re: Spam from addresses where full name mirrors left-hand side of address

2018-04-02 Thread Bill Cole
rom =~ /(\w+) (\w+) (\w+) <\1.\2.\3/ And assuming it can be done, is it *worthwhile* to do it?  Not a clue. Maybe worth a try? -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work: https://linkedin.com/in/billcole

Re: Problems with SORBS?

2018-04-06 Thread Bill Cole
On 6 Apr 2018, at 8:08, Martin Gregorie wrote: I'm getting a lot of SORBS lookups rejected due to an "unexpected RCODE". Is anybody else seeing these? I'm sure someone is... There are none of those where I see. If the "unexpected RCODE" is SERVFAIL, it was likely transient on their end. If i

Re: FSL_BULK_SIG still active?

2018-04-07 Thread Bill Cole
d score adjustments, and have a valid reason to believe that your mail flow fits that divergence. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work: https://linkedin.com/in/billcole

Re: MSGID_SPAM_CAPS fp's hitting messages from The Pension Regulator in UK

2018-04-07 Thread Bill Cole
with that name (and mot with a 'T_' or developer's tag prefix) implies that at some point in the past it was reliable enough as an indicator of spam to be part of the default set. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scc

Re: low score on very spammy email

2018-04-11 Thread Bill Cole
On 10 Apr 2018, at 18:28, Motty Cruz wrote: reject_rbl_client zen.spamhaus.org, reject_rbl_client cbl.abuseat.org, That is redundant. The Zen list includes the CBL and Spamhaus has taken over operation of the CBL so there's no lag time between them any more.

Re: FORGED_GMAIL_RCVD and USER_IN_DEF_SPF_WL

2018-04-11 Thread Bill Cole
t's good enough for def_whitelist_auth. Messages of this sort make an irrefutable argument for removing the general pass given to Google in the default ruleset, as it is clearly based on a use model of the domain which no longer is true. -- Bill Cole b...@scconsult.com or billc...@apache.org

Re: URI_TRY_3LD fp's with QuickBooks Intuit emails

2018-04-13 Thread Bill Cole
gs publish. Giovanni Yes, but it is published in 72_scores.cf with a trivial score: score URI_TRY_3LD 0.001 0.001 0.001 0.001 -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Stead

Re: Differing scores on spamassassin checks

2018-04-16 Thread Bill Cole
can access and spamd can't even TRY to use because it refuses to run as root and drops to 'nobody' if run by root. With a global bayes_path, the bayes_* files will become owned by root and everything else trying to use them (i.e. everything) will fail. -- Bill Cole b...@scconsult.c

Re: SpamAssassin 3.4.2.

2018-04-17 Thread Bill Cole
On 17 Apr 2018, at 16:38, David Jones wrote: On 04/17/2018 03:29 PM, Kevin A. McGrail wrote: Dave, why would it go into EPEL?  SpamAssassin is a core RPM. Oh yeh. I guess because it's been so long since we had an update and my main boxes are running CentOS/SL 6.9 that I forgot it was a cor

Re: SpamAssassin 3.4.2.

2018-04-17 Thread Bill Cole
On 17 Apr 2018, at 16:54, John Hardin wrote: On Tue, 17 Apr 2018, David Jones wrote: On 04/17/2018 03:29 PM, Kevin A. McGrail wrote: Dave, why would it go into EPEL?  SpamAssassin is a core RPM. I will be updating my main SA platform servers to CentOS 7 this summer so this should be good t

Re: SpamAssassin 3.4.2.

2018-04-17 Thread Bill Cole
On 17 Apr 2018, at 18:13, David Jones wrote: Why hasn't the packaging in RHEL/CentOS been updated to 3.4.1? At my last job where there were supported RHEL machines, I asked a RH support person a similar question regarding Postfix and got the answer: "If you want Fedora, you know where to ge

Re: plugin: eval failed: __alarm__ignore__(xxx) how to troubleshoot

2018-04-20 Thread Bill Cole
ckport the fix for either perl or SA. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work: https://linkedin.com/in/billcole

Re: anyone recognize these headers? From SA or are they from another spam product?

2018-04-24 Thread Bill Cole
ubmitting mail to. Presumably that is an entity with whom you have a direct relationship. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steady Work: https://linkedin.com/in/billcole

Re: Why emails relayedfrom trusted/internal networks trigger rules?

2018-04-26 Thread Bill Cole
ceived headers use RFC1918 IPs and a generic name in a non-resolvable domain doesn't matter: SA cannot trust these because the chain of trust and working DNS is already broken. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.c

Re: dropping other's email(s) as a "best practice" for hosted email? (was: "anyone recognize these headers? ...")

2018-04-26 Thread Bill Cole
They handle every step of delivery from sender to recipient and are prepaid by every sender to perform end-to-end delivery. In most of the Internet-heavy world, no email provider has any of those supporting features of reliability, even within their own home nations. -- Bill Cole b...@scconsult.co

Re: regexp dealing with display name don't work

2018-04-27 Thread Bill Cole
't be the first character of a user-defined variable name. It would also work with digits and most other symbols. SpamAssassin rules also must escape $ or %, which are the other characters Perl uses before variable names to indicate that they are variable names. -- Bill Cole b...@sccons

Re: Cause for non delivery when Spam Scanner Report is empty

2018-04-28 Thread Bill Cole
lyzes mail. To determine why a message was rejected, you need to look into the actions of whatever is actually making the decision to act on mail handling based on the SpamAssassin analysis. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scc

Re: Invoice phish

2018-05-16 Thread Bill Cole
On 15 May 2018, at 20:27, Alex wrote: Hi, We received another of those phishes as a result of a compromised O365 account. https://pastebin.com/raw/Fv5NKRAP Anyone able to take a look and provide ideas on how to block them? It passes with DKIM_VALID_AU, RCVD_IN_SENDERSCORE_90_100 and SPF_PAS

Re: [Offtopic] List From and Reply-To

2018-05-30 Thread Bill Cole
On 30 May 2018, at 10:00, Palvelin Postmaster wrote: On 30 May 2018, at 16:48, Antony Stone wrote: On Wednesday 30 May 2018 at 15:33:13, Palvelin Postmaster wrote: On 30 May 2018, at 16:06, Matus UHLAR - fantomas wrote: On 30.05.18 15:49, Palvelin Postmaster wrote: Hitting reply sends t

Re: [Offtopic] List From and Reply-To

2018-05-30 Thread Bill Cole
On 30 May 2018, at 8:49, Palvelin Postmaster wrote: Why does this list apparently use the original From header of the poster’s message and doesn't set a Reply-To header at all? 1. Traditional standard practice. Doing otherwise in either case would offend more people than sticking with the han

Re: [Offtopic] List From and Reply-To

2018-05-30 Thread Bill Cole
On 30 May 2018, at 10:25, Bill Cole wrote: On 30 May 2018, at 10:00, Palvelin Postmaster wrote: On 30 May 2018, at 16:48, Antony Stone wrote: On Wednesday 30 May 2018 at 15:33:13, Palvelin Postmaster wrote: On 30 May 2018, at 16:06, Matus UHLAR - fantomas wrote: On 30.05.18 15:49

Re: [Offtopic] List From and Reply-To

2018-05-30 Thread Bill Cole
red essentially a full rewrite to keep working on MacOS X given the ongoing rot in the Carbon APIs. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steadier Work: https://linkedin.com/in/billcole signature.as

Re: [Offtopic] List From and Reply-To

2018-05-30 Thread Bill Cole
lare a 2.0 release to make it clear that MM today is much more solid than it was in 2015. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steadier Work: https://linkedin.com/in/billcole

Re: [Offtopic] List From and Reply-To

2018-05-30 Thread Bill Cole
On 30 May 2018, at 17:19 (-0400), Luis E. Muñoz wrote: On 30 May 2018, at 13:54, Bill Cole wrote: On 30 May 2018, at 14:51 (-0400), Grant Taylor wrote: Since Qualcom transferred the Eudora IP to the Computer History Museum and open sourced the source code, I expect that we will be seeing

Re: Problem with sa-update via proxy

2018-06-06 Thread Bill Cole
On 5 Jun 2018, at 4:24, Peter Hutchison wrote: I have recently upgraded my mail mta servers from Ubuntu 14.04 to Ubuntu 16.04 but the daily spamassassin cron job is failing to update the database in /usr/lib/spamassassin/3.9004001/update_spamassassin_org folder. That's a very odd version nu

Re: Autolearn as ham with a positive score.

2018-06-12 Thread Bill Cole
On 12 Jun 2018, at 3:34, Reio Remma wrote: Hello! I just noticed *autolearn=ham* for a message with a positive spam score. Is that normal? No, but it is also not especially remarkable. The final operative score is not the score that is used to determine autolearning. bayes_auto_learn_thre

Re: Compromised squareup/amazonses account phish

2018-06-13 Thread Bill Cole
integrity. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steadier Work: https://linkedin.com/in/billcole

Re: Question regarding trusted_networks

2018-06-16 Thread Bill Cole
ump of the non-rule config elements with this one-liner, if all of your config files are in /etc/mail/spamassassin/: egrep -hvr '^(($|[[:space:]]*$|[[:space:]]*#|#)|[[:space:]]*(score|describe|meta|tflags|(mime|)header|body|rawbody|full|uri|if|ifplugin|else|askdns|endif)[[:space:]]*)'

Re: CVE-2018-12558: DOS in perl module Email::Address

2018-06-20 Thread Bill Cole
On 20 Jun 2018, at 11:11, Ian Zimmerman wrote: > This is probably of interest to readers of this list. Only very tangentially. > http://www.openwall.com/lists/oss-security/2018/06/19/3 SpamAssassin does not use Email::Address.

Re: Amazon failing DKIM?

2018-06-25 Thread Bill Cole
ve not seen them do that. 0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid This isn't an isolated email, it's all of the order confirmations. Thanks for the heads-up. I haven't seen one like this yet and hopefully they'll fix their issues soon.

Re: Method of setting score for a custom rule to be the required_score ?

2018-06-28 Thread Bill Cole
On 27 Jun 2018, at 22:17, J Doe wrote: I went back to “man Mail::SpamAssassin::Conf” and can see mention of the shortcircuit plugin . . . is there more documentation (perhaps in another man or perldoc), where the shortcircuit keyword is mentioned ? perldoc Mail::SpamAssassin::Plugin::Shortci

Re: Line too long [rfc 2822, section 2.1.1]

2018-07-13 Thread Bill Cole
On 13 Jul 2018, at 14:49, Rupert Gallagher wrote: A little survey on your local policies... What do you do when a subject line is longer than 78 characters? A. Reject B. Accept as spam C. Accept Accept, absent some actual spam sign. Note that the 78-character recommendation is not applicabl

Re: spample: porn extortion with pure numeric From domain and base64 body

2018-07-17 Thread Bill Cole
test. I would not expect the numeric TLD test to hit much in the submitted corpora, since NO_DNS_FOR_FROM is not hitting enough to have a meaningful score and a pure numeric TLD in the envelope sender would always hit NO_DNS_FOR_FROM. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.com addresses) Currently Seeking Steadier Work: https://linkedin.com/in/billcole

Re: spample: porn extortion with pure numeric From domain and base64 body

2018-07-17 Thread Bill Cole
And in addition... On 17 Jul 2018, at 20:00 (-0400), Chip M. wrote: > 3. Pure numeric TLDs appear to be non existent (so far!) I expect that this will hold true for a long time. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo and many *@billmail.scconsult.

Re: Best practice for learning submissions

2018-07-23 Thread Bill Cole
am. If your users are trainable (it DOES happen...) you might even get them to use specific keywords and/or archival mailboxes and use those to feed ham training. In a POP3 environment, this is a much harder problem to solve. -- Bill Cole b...@scconsult.com or billc...@apache.org (AKA @grumpybozo

<    2   3   4   5   6   7   8   9   10   >