spam filtering

John Summerfied debian at herakles.homelinux.org
Mon Jan 16 23:25:14 UTC 2006


John Summerfied wrote:
> Justin Zygmont wrote:
> 
>> hi, I was using postfix and was wondering what the best method would 
>> be to discard all messages that have been marked as spam in the 
>> subject line.  I guess spamassassin just prosesses email, but doesnt 
>> remove them, has anyone setup procmail with postfix to work well?
> 
> 
> I run postfix, spamassassinn & imap on the server. I use blocklists to 
> reject known spam sites, postfix header checks to block misconfigured 
> mail servers (eg the helo name must be well-formed and resolve) and SA 
> to mark up probable/possible spam.

Here's the sort of drivel I drop with the header checks:
errors in HELO/EHLO conversation:
    211-74-214-117.adsl.dynamic.seed.net.tw[211.74.214.117] : Helo 
command rejected (need fully-qualified hostname) : 1 Time(s)
    59-104-101-121.adsl.dynamic.seed.net.tw[59.104.101.121] : Helo 
command rejected (need fully-qualified hostname) : 1 Time(s)
    CPE-72-128-63-194.kc.res.rr.com[72.128.63.194] : Helo command 
rejected (need fully-qualified hostname) : 1 Time(s)
    ProxyBox.office.lan[192.168.1.249] : Helo command rejected (need 
fully-qualified hostname) : 1 Time(s)
    c-24-1-182-201.hsd1.tx.comcast.net[24.1.182.201] : Helo command 
rejected (need fully-qualified hostname) : 1 Time(s)
    i577B174B.versanet.de[87.123.23.75] : Helo command rejected (need 
fully-qualified hostname) : 1 Time(s)
    l3-202-89-184-225.arach.net.au[202.89.184.225] : Helo command 
rejected (need fully-qualified hostname) : 2 Time(s)
    mail2.californiapsychicsemail.com[63.236.1.34] : Helo command 
rejected (need fully-qualified hostname) : 1 Time(s)
    p4122-ipad48sasajima.aichi.ocn.ne.jp[222.144.151.122] : Helo command 
rejected (need fully-qualified hostname) : 1 Time(s)
    pcp03515179pcs.strl1201.mi.comcast.net[68.61.205.130] : Helo command 
rejected (need fully-qualified hostname) : 1 Time(s)
    ppp85-140-44-177.pppoe.mtu-net.ru[85.140.44.177] : Helo command 
rejected (need fully-qualified hostname) : 1 Time(s)
    unknown[195.34.115.117] : Helo command rejected (need 
fully-qualified hostname) : 1 Time(s)
    unknown[211.212.237.201] : Helo command rejected (need 
fully-qualified hostname) : 1 Time(s)
    unknown[211.61.156.189] : Helo command rejected (need 
fully-qualified hostname) : 1 Time(s)
    unknown[220.73.115.116] : Helo command rejected (need 
fully-qualified hostname) : 1 Time(s)
    unknown[222.67.32.64] : Helo command rejected (need fully-qualified 
hostname) : 1 Time(s)
    unknown[61.48.185.187] : Helo command rejected (need fully-qualified 
hostname) : 1 Time(s)


Unrecognized warning:
     smtpd_peer_init: 201.130.66.175: hostname 
host064175.metrored.net.mx verification failed: Name or service not 
known : 1 Time(s)
     smtpd_peer_init: 202.74.166.202: hostname 
cust202.166.rwa.globaldial.com verification failed: Name or service not 
known : 11 Time(s)
     smtpd_peer_init: 210.193.161.27: address not listed for hostname 
ecm7.com : 2 Time(s)
     smtpd_peer_init: 212.90.202.145: hostname 
cn-zh-aar-212-90-202-145.cybernet.ch verification failed: Name or 
service not known : 1 Time(s)
     smtpd_peer_init: 213.141.159.53: hostname nat-altair53.nebynet.ru 
verification failed: Name or service not known : 1 Time(s)
     smtpd_peer_init: 61.95.110.106: hostname 
dsl-61-95-110-106.request.com.au verification failed: Name or service 
not known : 1 Time(s)
     smtpd_peer_init: 63.206.157.134: hostname 
63-206-157-134.ded.pacbell.net verification failed: Name or service not 
known : 1 Time(s)
     unknown[195.34.115.117] sent non-SMTP command: From: "Robert Jones" 
<krgpzp at filantropia.com> : 1 Time(s)


Some days this list rivals mail blocked via block lists.



-- 

Cheers
John

-- spambait
1aaaaaaa at computerdatasafe.com.au  Z1aaaaaaa at computerdatasafe.com.au
Tourist pics http://portgeographe.environmentaldisasters.cds.merseine.nu/

do not reply off-list




More information about the fedora-list mailing list