Solved phishing , spambloker , rspamd

MisterM

Verified User
Joined
Jul 31, 2022
Messages
350
Hello

Have you ever received false advertising that spambloker does not stop

Mz
 
Perhaps look at RBL filtering - i.e. using Spamhaus, Barracuda, etc. This should help to stop a lot of the junk email you're receiving.

But first of all, you could get the message's source IP and check it at https://mxtoolbox.com/blacklists.aspx to see if it's the kind of thing that the big blacklists are picking up on.

Also, I'd suggest only enabling one RBL at a time, i.e. Spamhaus first, then monitor to see if there's improvement, and if not, add in Barracuda, etc.
 
Perhaps look at RBL filtering - i.e. using Spamhaus, Barracuda, etc. This should help to stop a lot of the junk email you're receiving.

But first of all, you could get the message's source IP and check it at https://mxtoolbox.com/blacklists.aspx to see if it's the kind of thing that the big blacklists are picking up on.

Also, I'd suggest only enabling one RBL at a time, i.e. Spamhaus first, then monitor to see if there's improvement, and if not, add in Barracuda, etc.
Yes, you are absolutely right.

I checked the IP address of the spammer/phishing via TinyCP it is Good.

What it would take, filtering by word, url, decrypting url, etc., because this is passed by amazon, bpost, DHL, etc., for a user, it would pass but not for a user who knows problem ...

Mz
 
List-Unsubscribe: <https://mer.apollon-special-nl.eu/d?q00ig7vidwvgoo00l0000lzy000000000otpg4vy1207>
Reply-To: Le compte de votre entreprise <[email protected]>
Forward-Confirmed-ReverseDNS: Reverse and forward lookup success on 162.19.142.193, -10 Spam score
X-DKIM: signer='mer.apollon-special-nl.eu' status='pass' reason=''
DKIMCheck: Server passes DKIM test, -20 Spam score
X-Spam-Bar: +++++++
SpamTally: Final spam score: 48
X-Antivirus-Scanner: Clean mail though you should still use an Antivirus

Message body :

Achetez-vous sur Amazon pour votre entreprise ?

Passez à Amazon Business et profitez de nos prix compétitifs, de nos livraisons fiables et d'achats sécurisés. Rejoignez des millions d'autres entreprises dans le monde entier.

Message that looks like amazon, under spamassassin this pass, is I use:

ConfigServer MailScanner Front-End v9.19​


With the Phishing function activate

Mz
 
I also regularly get spam from "amazonaws.com" so yes spam is coming from there too.

I personally don't use Spamhaus anymore, too many false positives from home users several times, because Spamhaus used home source sending ip instead of ISP source sending ip which users are using.

But good chance that Amazon is on the dnswl.org whitelist which is used by Exim.
I always report spam to Spamcop.
 
Create an account at Spamcop.net, create the mailhosts and then report the spam by pasting the headers in their report form.
Quite easy in fact.
 
Just follow the links via how tot sign up... it's all there.
Here is direct link.

But you have to know what you're doing, also with the headers and how to make mailhost. It's all explained there, but if I have to teach you, you might better consider not to use it.
 
Please let us know how the mail.baby rules are doing, if you notice better filtering or false positives over time. Thank you!
Still happy with it, despite sometime connection errors to interserver happens the filter works fine, we are also teaching rSPAMD with spam email for better filtering :)
 
For me rspamd does not filter asser inside the message, it lets too much pass in my opinion ...
 
I have a client of sex emails without stop is that they are sent by servers with IP nickel, like amazon, mailgun, I think in an automatic way, we should have a script that analyzes every message that comes in that comes from a source of word is that if it is listed, it is blocked automatically is not do it manually ...
 
i also receive alot dhl and phishing mails
but i allready have:

RBL_DNS_LIST=\
cbl.abuseat.org!&0.255.0.0 : \
b.barracudacentral.org : \
zen.spamhaus.org!&0.255.0.0
 
Back
Top