Spamassassin message

mbardelmeijer

Verified User
Joined
Jun 18, 2013
Messages
12
Hello,

We have a problem with our directadmin configuration. We have a VPS with directadmin only for handling mail (pop / imap). An client of ours gets a lot of spam messages like:

Spam detection software, running on the system "mail03.refreshserver.nl",
has identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see the administrator of
that system for details.

Content preview: H A_IR: There has been the beginning of a significant
bullish
rally!!! H A_IR showed great purchases on Monday. Savvy brokers know the
opportunity for more large profits are are readily available. You do
clearly
experiencing the start of an integral short squeeze trading. This is
actually
same form of sign we perceive with your other stocks, tresses are no
question
primed for any big performance to view massive profits here. Short
squeeze
can be rapid increase in the price of a stock that happens when you will
notice lack of supply and an excess of interest in the stock. Purchasing
is
obviously heating on H A_IR and we project prices to go lot higher, much
faster here. Tresses are primed and capable to go!!! Place H A_IR for your
investment for large returns - we are surely purchasing on June 11th and
locking these shares long lasting. [...]

Content analysis details: (11.9 points, 5.0 required)

pts rule name description
---- ----------------------
--------------------------------------------------
0.6 RCVD_IN_SORBS_WEB RBL: SORBS: sender is an abusable web server
[178.125.250.60 listed in dnsbl.sorbs.net]
1.4 FSL_HELO_BARE_IP_1 FSL_HELO_BARE_IP_1
3.4 RCVD_ILLEGAL_IP Received: contains illegal IP address
1.2 RCVD_HELO_IP_MISMATCH Received: HELO and IP do not match, but should
0.9 RCVD_NUMERIC_HELO Received: contains an IP address used for HELO
1.6 RCVD_IN_BRBL_LASTEXT RBL: RCVD_IN_BRBL_LASTEXT
[178.125.250.60 listed in
bb.barracudacentral.org]
0.1 MISSING_MID Missing Message-Id: header
1.3 RDNS_NONE Delivered to internal network by a host with no
rDNS
1.4 MISSING_DATE Missing Date: header

How can we prevent this? It looks like the clients gets a copy of the spamassassin report.

Version: DirectAdmin v.1.42.1

If i have to provide any more information, just let me know.

Regards,
Michel
 
If the spammers use their (your client) email in the from field, then, yes, they'll receive any bounces, reports, etc back
 
A recent update to DirectAdmin has screwed up SpamAssasin.
There is a thread somewhere explaining what needs to be done to alleviate the problem, however, this has to be done on the server side, by whoever looks after your service.

To my knowledge, there is no permanent fix at the moment.
It's driving me insane. Ive seen the amount of spam getting through or hitting the spam folder increase drmatically over the last 3 or 4 weeks.

Still waiting for a real fix guys.
 
I noticed problems on or around the 13th of May if it helps determine which version is affected.
 
Yes, mail03.refreshserver.nl is our server. It's a VPS with an Directadmin setup.
We've changed the exim filter to change the finish rule. So now we wait.

Thank you all for your help, thanks keat63 for the link!
 
Back
Top