Spam question

Jerry Benton jerry.benton at mailborder.com
Thu Aug 6 17:50:28 UTC 2015


- Use RBLs at the MTA level
- Use greylisting

-
Jerry Benton
www.mailborder.com



> On Aug 6, 2015, at 1:49 PM, Sean M. Schipper <sean.m.schipper at lawrence.edu> wrote:
> 
> Since last November I’ve been getting inundated with spam (yesterday just under 7,000 just in the am) from coming from 3 or 4 IP addresses on the same subnet in the morning starting like clockwork just after 9am.  Then sometimes I’ll get a similar rush of spam in the afternoon coming from a separate IP range.  Countries of origin include US and Bulgaria mostly but also have come from Brasil, Romania and S. Africa.
>  
> I’ve been able to train MailScanner to correctly identify these as spam since the content is very similar -- tons of links to websites with .php extensions.  Examples of subject lines:  Situations for 2015 that forgive your Student-Loan, 12 month MBA programs, accelerated...
>  
> To cut down on the processing/traffic on my server I’ve been just blacklisting these IP subnets at smtp with a deny bounce message.  Does anyone have any other suggestions on actions I can take to rid myself of this annoying daily routine?  Does anyone else have similar battle stories like this?
>  
> Thanks for any suggestions on this.  
>  
> Sean
> 
> 
> -- 
> MailScanner mailing list
> mailscanner at lists.mailscanner.info <mailto:mailscanner at lists.mailscanner.info>
> http://lists.mailscanner.info/listinfo/mailscanner <http://lists.mailscanner.info/listinfo/mailscanner>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.mailscanner.info/pipermail/mailscanner/attachments/20150806/3c75c64b/attachment.html>


More information about the MailScanner mailing list