setup filetype and filename rules per domain

Stephen Swaney steve.swaney at fsl.com
Mon Aug 7 17:25:05 IST 2006


> -----Original Message-----
> From: mailscanner-bounces at lists.mailscanner.info [mailto:mailscanner-
> bounces at lists.mailscanner.info] On Behalf Of Jeremy Blonde
> Sent: Monday, August 07, 2006 12:00 PM
> To: MailScanner discussion
> Subject: RE: setup filetype and filename rules per domain
> 
> I've been having trouble stopping the attached message from getting thru
> mailscanner.  I've got RBLs, Rulesdujour, and bayes (using MySQL).
> Bayes reports that there are 14,953 spam messages and 133,137 tokens in
> the database.  To actually block the messages, I've had to add the URLs
> in the messages to MCP.  I've been under the impression that bayes would
> be able to pick out the message details and score similar messages, but
> it seems they come across as new messages and their scores are 0.
> Perhaps, bayes is not working as well as it should be?
> 
> Can I get some information on how others have blocked those types of
> messages?
> 
> Jeremy Blonde
> Instructional Technology - Server Support
> Grant Joint Union School District

We tagged your post to the list as spam :)

pts rule name              description
---- ----------------------
--------------------------------------------------
 0.1 FORGED_RCVD_HELO       Received: contains a forged HELO
 1.3 INFO_TLD               URI: Contains an URL in the INFO top-level
domain
-0.2 BAYES_40               BODY: Bayesian spam probability is 20 to 40%
                            [score: 0.3560]
 1.5 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level
                            above 50%
                            [cf: 100]
 0.5 RAZOR2_CHECK           Listed in Razor2 (http://razor.sf.net/)
 0.5 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
                            [cf: 100]
 1.6 URIBL_SBL              Contains an URL listed in the SBL blocklist
                            [URIs: filmogenka.com]
 3.0 URIBL_BLACK            Contains an URL listed in the URIBL blacklist
                            [URIs: filmogenka.com]

Just adding the message to the Bayes database is not enough. You need to use
all the tools available:

	Razor
	DCC
	SpamAssassin plugins

There are also some nifty milters available if you use sendmail (or now the
latest postfix :). We're blocking a ton of stuff with a free milter,
milter-limit available at www.snertsoft.com.

Also please change the subject line when you reply to a list message and
change the topic :) 

Steve

Stephen Swaney
Fort Systems Ltd.
stephen.swaney at fsl.com
www.fsl.com



More information about the MailScanner mailing list