americanintel
Verified User
I have some of this posted in an older thread: http://forum.directadmin.com/showthread.php?t=33321
I need to stop this in it's tracks and it will require someone smarter than me with Exim and Spamassassin. I've munged this but myemail should be usamail.
1. I don't want it going to our archive server
2. I don't want an NDR sent back to the forged sender's address (backscatter).
Spamassassin may not catch and score all of these but at least when it does you can eliminate the backscatter/ndr type of spam without the fear of killing off normal NDR in case someone fat fingers a legitimate email address.
This is a prime example. Receiving tons of email with variations of 'victoror' or 'vict...' whatever.
So, as you can see we have a 7.9 which is above the 4.0 required to consider this as spam, it should stop right there and be deleted just as I have it set to do (not sent to a Spam folder).
I'd really appreciate any help in dealing with this whether it's modifying the template in directadmin, routers in exim or acl or ???
I need to stop this in it's tracks and it will require someone smarter than me with Exim and Spamassassin. I've munged this but myemail should be usamail.
1. I don't want it going to our archive server
2. I don't want an NDR sent back to the forged sender's address (backscatter).
Spamassassin may not catch and score all of these but at least when it does you can eliminate the backscatter/ndr type of spam without the fear of killing off normal NDR in case someone fat fingers a legitimate email address.
This is a prime example. Receiving tons of email with variations of 'victoror' or 'vict...' whatever.
Subject: A survey conducted by American pharmacists showed that 43% of men suffer from impotence.
From: [email protected]
To: [email protected]
Date: Fri, 18 Jul 2014 12:51:04 +0300
Notes:
This is a multi-part message in MIME format.
Spam detection software, running on the system "mail.myemail.us",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: This drug is the only medication that produced some positive
effect on my sexual performance! urltruncated-magdalenas.com/wp-admin/maint/canadianshop....
[...]
Content analysis details: (7.9 points, 4.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.2 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
[Blocked - see <http://www.spamcop.net/bl.shtml?188.53.0.230>]
2.5 DATE_IN_FUTURE_12_24 Date: is 12 to 24 hours after Received: date
0.0 HTML_MESSAGE BODY: HTML included in message
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 MIME_QP_LONG_LINE RAW: Quoted-printable line longer than 76 chars
1.3 URIBL_MW_SURBL Contains a Malware Domain or IP listed in the MW SURBL
blocklist
[URIs: magdalenas.com]
0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag
0.1 MISSING_MID Missing Message-Id: header
1.0 URI_WPADMIN WordPress login/admin URI, possible phishing
The original message was not completely plain text, and may be unsafe to
open with some email clients; in particular, it may contain a virus,
or confirm that your address can receive spam. If you wish to view
it, it may be safer to save it to a file and open it with an editor.
Received: from mail by mail.myemail.us with spam-scanned (Exim 4.82.1)
(envelope-from <[email protected]>)
id 1X7stN-0002Qf-Kb
for [email protected]; Thu, 17 Jul 2014 16:07:10 -0500
Received: from localhost by mail.myemail.us
with SpamAssassin (version 3.4.0);
Thu, 17 Jul 2014 16:07:10 -0500
From: [email protected]
To: [email protected]
Subject: =?UTF-8?Q?A_survey_conducted_by_American_pharmacists_?=
=?UTF-8?Q?showed_that_43%_of_men_suffer_from_?= =?UTF-8?Q?impotence.?=
Date: Fri, 18 Jul 2014 12:51:04 +0300
X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on mail.myemail.us
X-Spam-Flag: YES
X-Spam-Level: *******
X-Spam-Status: Yes, score=7.9 required=4.0 tests=DATE_IN_FUTURE_12_24,
HTML_MESSAGE,HTML_MIME_NO_HTML_TAG,MIME_HTML_ONLY,MIME_QP_LONG_LINE,
MISSING_MID,RCVD_IN_BL_SPAMCOP_NET,URIBL_MW_SURBL,URI_WPADMIN autolearn=no
autolearn_force=no version=3.4.0
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----------=_53C83AFE.27426C5C"
Message-Id: <[email protected]>
So, as you can see we have a 7.9 which is above the 4.0 required to consider this as spam, it should stop right there and be deleted just as I have it set to do (not sent to a Spam folder).
I'd really appreciate any help in dealing with this whether it's modifying the template in directadmin, routers in exim or acl or ???
Last edited: