Discussion:
Qurantine.
Mohammed Ejaz
2015-03-22 15:19:44 UTC
Permalink
Hello All.



Sometimes, Very strangely I noticed that My normal test Emails are being
quarantined from the MailScanner. any help would be highly appreciated.



I am enclosing the my MailScanner configuration file FYR.







Below are my logs and I can see the my test message in the quarantine spam
folder

grep -i ***@hotmail.com /var/log/maillog

Mar 22 16:25:36 mailgate5 postfix/cleanup[4839]: E3A01A504E5: hold: header
Received: from COL004-OMC3S5.hotmail.com (col004-omc3s5.hotmail.com
[65.55.34.143])??by mailgate5.cyberia.net.sa (Postfix) with ESMTP id
E3A01A504E5;??Sun, 22 Mar 2015 16:25:35 +0300 (AST) from
col004-omc3s5.hotmail.com[65.55.34.143]; from=<***@hotmail.com>
to=<***@cyberia.net.sa> proto=ESMTP helo=<COL004-OMC3S5.hotmail.com>

Mar 22 16:25:45 mailgate5 MailScanner[31920]: Message E3A01A504E5.AA0BD from
65.55.34.143 (***@hotmail.com) to cyberia.net.sa is spam, SpamAssassin
(not cached, score=5.453, required 5, BAYES_00 -1.90, DNS_FROM_AHBL_RHSBL
2.70, FREEMAIL_FROM 0.00, HTML_MESSAGE 0.00, KAM_FROM_URIBL_PCCC 5.00,
RCVD_IN_DNSWL_NONE -0.00, RP_MATCHES_RCVD -0.35, SPF_PASS -0.00)





Regards

Ejaz
Jeremy McSpadden
2015-03-22 16:14:32 UTC
Permalink
Being detected as spam.

--
Jeremy McSpadden | Flux Labs
Local - 850-250-5590x501<tel:850-250-5590;501> | Mobile - 850-890-2543<tel:850-890-2543>
Fax - 850-254-2955<tel:850-254-2955> | Toll Free - 877-699-FLUX<tel:877-699-FLUX>
Web - http://www.fluxlabs.net<http://www.fluxlabs.net/>


On Mar 22, 2015, at 10:31 AM, Mohammed Ejaz <***@cyberia.net.sa<mailto:***@cyberia.net.sa>> wrote:


Hello All.

Sometimes, Very strangely I noticed that My normal test Emails are being quarantined from the MailScanner. any help would be highly appreciated.

I am enclosing the my MailScanner configuration file FYR.



Below are my logs and I can see the my test message in the quarantine spam folder
grep -i ***@hotmail.com<mailto:***@hotmail.com> /var/log/maillog
Mar 22 16:25:36 mailgate5 postfix/cleanup[4839]: E3A01A504E5: hold: header Received: from COL004-OMC3S5.hotmail.com<http://COL004-OMC3S5.hotmail.com> (col004-omc3s5.hotmail.com<http://col004-omc3s5.hotmail.com> [65.55.34.143])??by mailgate5.cyberia.net.sa (Postfix) with ESMTP id E3A01A504E5;??Sun, 22 Mar 2015 16:25:35 +0300 (AST) from col004-omc3s5.hotmail.com<http://col004-omc3s5.hotmail.com>[65.55.34.143]; from=<***@hotmail.com<mailto:***@hotmail.com>> to=<***@cyberia.net.sa<mailto:***@cyberia.net.sa>> proto=ESMTP helo=<COL004-OMC3S5.hotmail.com<http://COL004-OMC3S5.hotmail.com>>
Mar 22 16:25:45 mailgate5 MailScanner[31920]: Message E3A01A504E5.AA0BD from 65.55.34.143 (***@hotmail.com<mailto:***@hotmail.com>) to cyberia.net.sa is spam, SpamAssassin (not cached, score=5.453, required 5, BAYES_00 -1.90, DNS_FROM_AHBL_RHSBL 2.70, FREEMAIL_FROM 0.00, HTML_MESSAGE 0.00, KAM_FROM_URIBL_PCCC 5.00, RCVD_IN_DNSWL_NONE -0.00, RP_MATCHES_RCVD -0.35, SPF_PASS -0.00)


Regards
Ejaz
<config.txt>
--
MailScanner mailing list
***@lists.mailscanner.info<mailto:***@lists.mailscanner.info>
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website!
Jerry Benton
2015-03-22 16:29:26 UTC
Permalink
See here

http://community.zimbra.com/collaboration/f/1884/t/1137276 <http://community.zimbra.com/collaboration/f/1884/t/1137276>



-
Jerry Benton
www.mailborder.com
Post by Mohammed Ejaz
Hello All.
Sometimes, Very strangely I noticed that My normal test Emails are being quarantined from the MailScanner. any help would be highly appreciated.
I am enclosing the my MailScanner configuration file FYR.
Below are my logs and I can see the my test message in the quarantine spam folder
Regards
Ejaz
<config.txt>--
MailScanner mailing list
http://lists.mailscanner.info/mailman/listinfo/mailscanner <http://lists.mailscanner.info/mailman/listinfo/mailscanner>
Before posting, read http://wiki.mailscanner.info/posting <http://wiki.mailscanner.info/posting>
Support MailScanner development - buy the book off the website!
Mohammed Ejaz
2015-03-23 10:04:36 UTC
Permalink
Thank you, as seen in the article



I opened the 50_scores.cf file and comment the lines from
DNS_FROM_AHBL_RHSB



Ejaz



From: mailscanner-***@lists.mailscanner.info
[mailto:mailscanner-***@lists.mailscanner.info] On Behalf Of Jerry
Benton
Sent: Sunday, March 22, 2015 7:29 PM
To: MailScanner discussion
Subject: Re: Qurantine.



See here



http://community.zimbra.com/collaboration/f/1884/t/1137276






-

Jerry Benton

www.mailborder.com







On Mar 22, 2015, at 11:19 AM, Mohammed Ejaz <***@cyberia.net.sa> wrote:





Hello All.



Sometimes, Very strangely I noticed that My normal test Emails are being
quarantined from the MailScanner. any help would be highly appreciated.



I am enclosing the my MailScanner configuration file FYR.







Below are my logs and I can see the my test message in the quarantine spam
folder

grep -i <mailto:***@hotmail.com> ***@hotmail.com /var/log/maillog

Mar 22 16:25:36 mailgate5 postfix/cleanup[4839]: E3A01A504E5: hold: header
Received: from <http://col004-omc3s5.hotmail.com/>
COL004-OMC3S5.hotmail.com ( <http://col004-omc3s5.hotmail.com/>
col004-omc3s5.hotmail.com [65.55.34.143])??by mailgate5.cyberia.net.sa
(Postfix) with ESMTP id E3A01A504E5;??Sun, 22 Mar 2015 16:25:35 +0300 (AST)
from <http://col004-omc3s5.hotmail.com/>
col004-omc3s5.hotmail.com[65.55.34.143]; from=< <mailto:***@hotmail.com>
***@hotmail.com> to=< <mailto:***@cyberia.net.sa>
***@cyberia.net.sa> proto=ESMTP helo=< <http://col004-omc3s5.hotmail.com/>
COL004-OMC3S5.hotmail.com>

Mar 22 16:25:45 mailgate5 MailScanner[31920]: Message E3A01A504E5.AA0BD from
65.55.34.143 ( <mailto:***@hotmail.com> ***@hotmail.com) to
cyberia.net.sa is spam, SpamAssassin (not cached, score=5.453, required 5,
BAYES_00 -1.90, DNS_FROM_AHBL_RHSBL 2.70, FREEMAIL_FROM 0.00, HTML_MESSAGE
0.00, KAM_FROM_URIBL_PCCC 5.00, RCVD_IN_DNSWL_NONE -0.00, RP_MATCHES_RCVD
-0.35, SPF_PASS -0.00)





Regards

Ejaz

<config.txt>--
MailScanner mailing list
<mailto:***@lists.mailscanner.info>
***@lists.mailscanner.info
<http://lists.mailscanner.info/mailman/listinfo/mailscanner>
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read <http://wiki.mailscanner.info/posting>
http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website!
Randal, Phil
2015-03-24 10:03:38 UTC
Permalink
That change will get trashed next time sa-update is run.

Better to put

score DNS_FROM_AHBL_RHSB 0

in your local.cf

Cheers,

Phil
--
Phil Randal
Infrastructure Engineer
Hoople Ltd | Thorn Office Centre | Hereford | HR2 6JT
Tel : 01432 260415 |Email: ***@hoopleltd.co.uk<mailto:***@hoopleltd.co.uk>
General email: ***@hoopleltd.co.uk<mailto:***@hoopleltd.co.uk>
Website: www.hoopleltd.co.uk<http://www.hoopleltd.co.uk/>

From: mailscanner-***@lists.mailscanner.info [mailto:mailscanner-***@lists.mailscanner.info] On Behalf Of Mohammed Ejaz
Sent: 23 March 2015 10:05
To: 'MailScanner discussion'
Subject: RE: Qurantine.

Thank you, as seen in the article

I opened the 50_scores.cf file and comment the lines from DNS_FROM_AHBL_RHSB

Ejaz

From: mailscanner-***@lists.mailscanner.info<mailto:mailscanner-***@lists.mailscanner.info> [mailto:mailscanner-***@lists.mailscanner.info] On Behalf Of Jerry Benton
Sent: Sunday, March 22, 2015 7:29 PM
To: MailScanner discussion
Subject: Re: Qurantine.

See here

http://community.zimbra.com/collaboration/f/1884/t/1137276



-
Jerry Benton
www.mailborder.com<http://www.mailborder.com>



On Mar 22, 2015, at 11:19 AM, Mohammed Ejaz <***@cyberia.net.sa<mailto:***@cyberia.net.sa>> wrote:


Hello All.

Sometimes, Very strangely I noticed that My normal test Emails are being quarantined from the MailScanner. any help would be highly appreciated.

I am enclosing the my MailScanner configuration file FYR.



Below are my logs and I can see the my test message in the quarantine spam folder
grep -i ***@hotmail.com<mailto:***@hotmail.com> /var/log/maillog
Mar 22 16:25:36 mailgate5 postfix/cleanup[4839]: E3A01A504E5: hold: header Received: from COL004-OMC3S5.hotmail.com<http://col004-omc3s5.hotmail.com/> (col004-omc3s5.hotmail.com<http://col004-omc3s5.hotmail.com/> [65.55.34.143])??by mailgate5.cyberia.net.sa (Postfix) with ESMTP id E3A01A504E5;??Sun, 22 Mar 2015 16:25:35 +0300 (AST) from col004-omc3s5.hotmail.com<http://col004-omc3s5.hotmail.com/>[65.55.34.143]; from=<***@hotmail.com<mailto:***@hotmail.com>> to=<***@cyberia.net.sa<mailto:***@cyberia.net.sa>> proto=ESMTP helo=<COL004-OMC3S5.hotmail.com<http://col004-omc3s5.hotmail.com/>>
Mar 22 16:25:45 mailgate5 MailScanner[31920]: Message E3A01A504E5.AA0BD from 65.55.34.143 (***@hotmail.com<mailto:***@hotmail.com>) to cyberia.net.sa is spam, SpamAssassin (not cached, score=5.453, required 5, BAYES_00 -1.90, DNS_FROM_AHBL_RHSBL 2.70, FREEMAIL_FROM 0.00, HTML_MESSAGE 0.00, KAM_FROM_URIBL_PCCC 5.00, RCVD_IN_DNSWL_NONE -0.00, RP_MATCHES_RCVD -0.35, SPF_PASS -0.00)


Regards
Ejaz
<config.txt>--
MailScanner mailing list
***@lists.mailscanner.info<mailto:***@lists.mailscanner.info>
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website!

Hoople Ltd, Registered in England and Wales No. 7556595
Registered office: Plough Lane, Hereford, HR4 0LE

"Any opinion expressed in this e-mail or any attached files are those of the individual and not necessarily those of Hoople Ltd. You should be aware that Hoople Ltd. monitors its email service. This e-mail and any attached files are confidential and intended solely for the use of the addressee. This communication may contain material protected by law from being passed on. If you are not the intended recipient and have received this e-mail in error, you are advised that any use, dissemination, forwarding, printing or copying of this e-mail is strictly prohibited. If you have received this e-mail in error please contact the sender immediately and destroy all copies of it."
Mohammed Ejaz
2015-03-24 14:14:08 UTC
Permalink
Thank you as I did it.



From: mailscanner-***@lists.mailscanner.info
[mailto:mailscanner-***@lists.mailscanner.info] On Behalf Of Randal,
Phil
Sent: Tuesday, March 24, 2015 1:04 PM
To: MailScanner discussion
Subject: RE: Qurantine.



That change will get trashed next time sa-update is run.



Better to put



score DNS_FROM_AHBL_RHSB 0



in your local.cf



Cheers,



Phil
--
Phil Randal

Infrastructure Engineer

Hoople Ltd | Thorn Office Centre | Hereford | HR2 6JT

Tel : 01432 260415 |Email: ***@hoopleltd.co.uk
General email: <mailto:***@hoopleltd.co.uk> ***@hoopleltd.co.uk

Website: www.hoopleltd.co.uk <http://www.hoopleltd.co.uk/>



From: mailscanner-***@lists.mailscanner.info
[mailto:mailscanner-***@lists.mailscanner.info] On Behalf Of Mohammed
Ejaz
Sent: 23 March 2015 10:05
To: 'MailScanner discussion'
Subject: RE: Qurantine.



Thank you, as seen in the article



I opened the 50_scores.cf file and comment the lines from
DNS_FROM_AHBL_RHSB



Ejaz



From: mailscanner-***@lists.mailscanner.info
[mailto:mailscanner-***@lists.mailscanner.info] On Behalf Of Jerry
Benton
Sent: Sunday, March 22, 2015 7:29 PM
To: MailScanner discussion
Subject: Re: Qurantine.



See here



http://community.zimbra.com/collaboration/f/1884/t/1137276






-

Jerry Benton

www.mailborder.com







On Mar 22, 2015, at 11:19 AM, Mohammed Ejaz <***@cyberia.net.sa> wrote:





Hello All.



Sometimes, Very strangely I noticed that My normal test Emails are being
quarantined from the MailScanner. any help would be highly appreciated.



I am enclosing the my MailScanner configuration file FYR.







Below are my logs and I can see the my test message in the quarantine spam
folder

grep -i <mailto:***@hotmail.com> ***@hotmail.com /var/log/maillog

Mar 22 16:25:36 mailgate5 postfix/cleanup[4839]: E3A01A504E5: hold: header
Received: from <http://col004-omc3s5.hotmail.com/>
COL004-OMC3S5.hotmail.com ( <http://col004-omc3s5.hotmail.com/>
col004-omc3s5.hotmail.com [65.55.34.143])??by mailgate5.cyberia.net.sa
(Postfix) with ESMTP id E3A01A504E5;??Sun, 22 Mar 2015 16:25:35 +0300 (AST)
from <http://col004-omc3s5.hotmail.com/>
col004-omc3s5.hotmail.com[65.55.34.143]; from=< <mailto:***@hotmail.com>
***@hotmail.com> to=< <mailto:***@cyberia.net.sa>
***@cyberia.net.sa> proto=ESMTP helo=< <http://col004-omc3s5.hotmail.com/>
COL004-OMC3S5.hotmail.com>

Mar 22 16:25:45 mailgate5 MailScanner[31920]: Message E3A01A504E5.AA0BD from
65.55.34.143 ( <mailto:***@hotmail.com> ***@hotmail.com) to
cyberia.net.sa is spam, SpamAssassin (not cached, score=5.453, required 5,
BAYES_00 -1.90, DNS_FROM_AHBL_RHSBL 2.70, FREEMAIL_FROM 0.00, HTML_MESSAGE
0.00, KAM_FROM_URIBL_PCCC 5.00, RCVD_IN_DNSWL_NONE -0.00, RP_MATCHES_RCVD
-0.35, SPF_PASS -0.00)





Regards

Ejaz

<config.txt>--
MailScanner mailing list
<mailto:***@lists.mailscanner.info>
***@lists.mailscanner.info
<http://lists.mailscanner.info/mailman/listinfo/mailscanner>
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read <http://wiki.mailscanner.info/posting>
http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website!



Hoople Ltd, Registered in England and Wales No. 7556595
Registered office: Plough Lane, Hereford, HR4 0LE

"Any opinion expressed in this e-mail or any attached files are those of the
individual and not necessarily those of Hoople Ltd. You should be aware that
Hoople Ltd. monitors its email service. This e-mail and any attached files
are confidential and intended solely for the use of the addressee. This
communication may contain material protected by law from being passed on. If
you are not the intended recipient and have received this e-mail in error,
you are advised that any use, dissemination, forwarding, printing or copying
of this e-mail is strictly prohibited. If you have received this e-mail in
error please contact the sender immediately and destroy all copies of it."
Glenn Steen
2015-03-25 10:35:35 UTC
Permalink
I'd say the problem is twofold:
1. AHBL closing is probably what is tipping you over the edge. Running
sa-update on a regular basis (from cron) solves this as the update
removed those rules almost a year ago.. See:
# grep AHBL /var/lib/spamassassin/3.004000/updates_spamassassin_org/*
/var/lib/spamassassin/3.004000/updates_spamassassin_org/20_dnsbl_tests.cf:#
AHBL is closing down. disabling early. (Axb-2014-03-28)
/var/lib/spamassassin/3.004000/updates_spamassassin_org/20_dnsbl_tests.cf:#header
DNS_FROM_AHBL_RHSBL eval:check_rbl_envfrom('ahbl',
'rhsbl.ahbl.org.')
/var/lib/spamassassin/3.004000/updates_spamassassin_org/20_dnsbl_tests.cf:#describe
DNS_FROM_AHBL_RHSBL Envelope sender listed in dnsbl.ahbl.org
/var/lib/spamassassin/3.004000/updates_spamassassin_org/20_dnsbl_tests.cf:#tflags
DNS_FROM_AHBL_RHSBL net
/var/lib/spamassassin/3.004000/updates_spamassassin_org/20_dnsbl_tests.cf:#reuse
DNS_FROM_AHBL_RHSBL
/var/lib/spamassassin/3.004000/updates_spamassassin_org/50_scores.cf:#
AHBL is closing down. disabling early. (Axb-2014-03-28)
/var/lib/spamassassin/3.004000/updates_spamassassin_org/50_scores.cf:#score
DNS_FROM_AHBL_RHSBL 0 2.438 0 2.699 # n=0 n=2
#
Check that you have Disabled=no in /etc/cron.daily/update_spamassassin
(or wherever...:-)


2. The KAM thing is what really loads you down there... Perhaps time
to revisit whether it is a good fit or not, and whether the point
attribution is OK:-)

Cheers
--
-- Glenn
Post by Mohammed Ejaz
Thank you as I did it.
Phil
Sent: Tuesday, March 24, 2015 1:04 PM
To: MailScanner discussion
Subject: RE: Qurantine.
That change will get trashed next time sa-update is run.
Better to put
score DNS_FROM_AHBL_RHSB 0
in your local.cf
Cheers,
Phil
--
Phil Randal
Infrastructure Engineer
Hoople Ltd | Thorn Office Centre | Hereford | HR2 6JT
Website: www.hoopleltd.co.uk
Ejaz
Sent: 23 March 2015 10:05
To: 'MailScanner discussion'
Subject: RE: Qurantine.
Thank you, as seen in the article
I opened the 50_scores.cf file and comment the lines from
DNS_FROM_AHBL_RHSB
Ejaz
Benton
Sent: Sunday, March 22, 2015 7:29 PM
To: MailScanner discussion
Subject: Re: Qurantine.
See here
http://community.zimbra.com/collaboration/f/1884/t/1137276
-
Jerry Benton
www.mailborder.com
Hello All.
Sometimes, Very strangely I noticed that My normal test Emails are being
quarantined from the MailScanner. any help would be highly appreciated.
I am enclosing the my MailScanner configuration file FYR.
Below are my logs and I can see the my test message in the quarantine spam folder
Mar 22 16:25:36 mailgate5 postfix/cleanup[4839]: E3A01A504E5: hold: header
Received: from COL004-OMC3S5.hotmail.com (col004-omc3s5.hotmail.com
[65.55.34.143])??by mailgate5.cyberia.net.sa (Postfix) with ESMTP id
E3A01A504E5;??Sun, 22 Mar 2015 16:25:35 +0300 (AST) from
Mar 22 16:25:45 mailgate5 MailScanner[31920]: Message E3A01A504E5.AA0BD from
(not cached, score=5.453, required 5, BAYES_00 -1.90, DNS_FROM_AHBL_RHSBL
2.70, FREEMAIL_FROM 0.00, HTML_MESSAGE 0.00, KAM_FROM_URIBL_PCCC 5.00,
RCVD_IN_DNSWL_NONE -0.00, RP_MATCHES_RCVD -0.35, SPF_PASS -0.00)
Regards
Ejaz
<config.txt>--
MailScanner mailing list
http://lists.mailscanner.info/mailman/listinfo/mailscanner
Before posting, read http://wiki.mailscanner.info/posting
Support MailScanner development - buy the book off the website!
Hoople Ltd, Registered in England and Wales No. 7556595
Registered office: Plough Lane, Hereford, HR4 0LE
"Any opinion expressed in this e-mail or any attached files are those of the
individual and not necessarily those of Hoople Ltd. You should be aware that
Hoople Ltd. monitors its email service. This e-mail and any attached files
are confidential and intended solely for the use of the addressee. This
communication may contain material protected by law from being passed on. If
you are not the intended recipient and have received this e-mail in error,
you are advised that any use, dissemination, forwarding, printing or copying
of this e-mail is strictly prohibited. If you have received this e-mail in
error please contact the sender immediately and destroy all copies of it."
--
MailScanner mailing list
http://lists.mailscanner.info/mailman/listinfo/mailscanner
Before posting, read http://wiki.mailscanner.info/posting
Support MailScanner development - buy the book off the website!
--
-- Glenn
email: glenn < dot > steen < at > gmail < dot > com
work: glenn < dot > steen < at > ap1 < dot > se
--
MailScanner mailing list
***@lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website!
Loading...