Discussion:
MailScanner filtering out less and less spam
Jonathan Horne
2014-05-23 02:12:25 UTC
Permalink
Greetings,




I have several MailScanner installs that lately, have been allowing an increased amount of spam to deliver. all separate systems, at separate sites, but all behaving the same way. more and more spam each week is getting thru. ive been noticing an increase at least over the past 3-4 weeks.




is there anything that can be done? previously when these systems were deployed (about 9-12 months ago, I forget now) they were incredibly effective.




thanks for any tips,

Jonathan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20140523/73f405d7/attachment.html
Jeremy McSpadden
2014-05-23 02:25:54 UTC
Permalink
RBL or grey listing ?

--
Jeremy McSpadden
Flux Labs | http://www.fluxlabs.net | Endless Solutions
Office : 850-250-5590x501<tel:850-250-5590;501> | Cell : 850-890-2543<tel:850-890-2543> | Fax : 850-254-2955<tel:850-254-2955>




On Thu, May 22, 2014 at 7:22 PM -0700, "Jonathan Horne" <jonathanmhorne at outlook.com<mailto:jonathanmhorne at outlook.com>> wrote:

Greetings,

I have several MailScanner installs that lately, have been allowing an increased amount of spam to deliver. all separate systems, at separate sites, but all behaving the same way. more and more spam each week is getting thru. ive been noticing an increase at least over the past 3-4 weeks.

is there anything that can be done? previously when these systems were deployed (about 9-12 months ago, I forget now) they were incredibly effective.

thanks for any tips,
Jonathan




-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20140523/8ebeaae9/attachment.html
Alex Neuman
2014-05-23 05:21:34 UTC
Permalink
Updates to spamassassin? Better ruleset scoring and tuning?



*Alex Neuman van der Hans*Reliant Technologies / Vida Digital
http://vidadigital.com.pa/

Mobile: +507-6781-9505
Work: +507-832-6725
Work (USA): +1-440-253-9789

Follow *@AlexNeuman <https://twitter.com/alexneuman>* on Twitter
Like Vida Digital <https://facebook.com/vidadigital/> on Facebook
Follow VidaDigital <http://instagram.com/vidadigital> on Instagram
Subscribe to Vida Digital <https://youtube.com/reliantpty> on Youtube
Post by Jeremy McSpadden
RBL or grey listing ?
--
Jeremy McSpadden
Flux Labs | http://www.fluxlabs.net | Endless Solutions
Office : 850-250-5590x501 <850-250-5590;501> | Cell : 850-890-2543 | Fax
: 850-254-2955
On Thu, May 22, 2014 at 7:22 PM -0700, "Jonathan Horne" <
Greetings,
I have several MailScanner installs that lately, have been allowing an
increased amount of spam to deliver. all separate systems, at separate
sites, but all behaving the same way. more and more spam each week is
getting thru. ive been noticing an increase at least over the past 3-4
weeks.
is there anything that can be done? previously when these systems were
deployed (about 9-12 months ago, I forget now) they were incredibly
effective.
thanks for any tips,
Jonathan
--
MailScanner mailing list
mailscanner at lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner
Before posting, read http://wiki.mailscanner.info/posting
Support MailScanner development - buy the book off the website!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20140523/104cf32e/attachment.html
Michael Huntley
2014-05-23 05:45:12 UTC
Permalink
I always keep a sizable chunk of recent spam on hand to feed to
spamassassin. I do it on a 45 day or so schedule. I place the spam in
a folder and sa-learn it using the proper user. This seems to keep
things sane.

Cheers!

mph
Post by Jonathan Horne
Greetings,
I have several MailScanner installs that lately, have been allowing an
increased amount of spam to deliver. all separate systems, at
separate sites, but all behaving the same way. more and more spam
each week is getting thru. ive been noticing an increase at least over
the past 3-4 weeks.
is there anything that can be done? previously when these systems
were deployed (about 9-12 months ago, I forget now) they were
incredibly effective.
thanks for any tips,
Jonathan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20140522/41dd73f0/attachment.html
Martin Hepworth
2014-05-23 13:42:24 UTC
Permalink
Hi
add the SA info into email headers to see what the score and rule hits are
( helps with debug), in MailScanner.conf make sure the follow are set thus:

Spam Score Number Format = %5.2f

Detailed Spam Report = yes

Include Scores In SpamAssassin Report = yes

Always Include SpamAssassin Report = yes

Spam Score Number Format = %5.2f
This should give you some clue as to whats (not) happening as first step
--
Martin Hepworth, CISSP
Oxford, UK
Post by Michael Huntley
I always keep a sizable chunk of recent spam on hand to feed to
spamassassin. I do it on a 45 day or so schedule. I place the spam in a
folder and sa-learn it using the proper user. This seems to keep things
sane.
Cheers!
mph
Greetings,
I have several MailScanner installs that lately, have been allowing an
increased amount of spam to deliver. all separate systems, at separate
sites, but all behaving the same way. more and more spam each week is
getting thru. ive been noticing an increase at least over the past 3-4
weeks.
is there anything that can be done? previously when these systems were
deployed (about 9-12 months ago, I forget now) they were incredibly
effective.
thanks for any tips,
Jonathan
--
MailScanner mailing list
mailscanner at lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner
Before posting, read http://wiki.mailscanner.info/posting
Support MailScanner development - buy the book off the website!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20140523/a390acab/attachment.html
Kai Schaetzl
2014-05-23 18:31:03 UTC
Permalink
compare the scores with older scores. Easy if you have Mailwatch or other
interface installed.

Kai
--
Get your web at Conactive Internet Services: http://www.conactive.com
Philip Parsons
2014-05-23 18:41:32 UTC
Permalink
What version of spamassassin are you using upgrade to 3.4 it is very good.

From: mailscanner-bounces at lists.mailscanner.info [mailto:mailscanner-bounces at lists.mailscanner.info] On Behalf Of Jonathan Horne
Sent: May-22-14 7:12 PM
To: mailscanner at lists.mailscanner.info
Subject: MailScanner filtering out less and less spam

Greetings,

I have several MailScanner installs that lately, have been allowing an increased amount of spam to deliver. all separate systems, at separate sites, but all behaving the same way. more and more spam each week is getting thru. ive been noticing an increase at least over the past 3-4 weeks.

is there anything that can be done? previously when these systems were deployed (about 9-12 months ago, I forget now) they were incredibly effective.

thanks for any tips,
Jonathan





--
This message has been scanned for viruses and
dangerous content by MailScanner<http://www.mailscanner.info/>, and is
believed to be clean.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20140523/ebce73be/attachment.html
Jonathan Horne
2014-05-27 14:20:14 UTC
Permalink
im not totally sure, what ever the default config gave me. how can I tell?











From: Jeremy McSpadden
Sent: ?Thursday?, ?May? ?22?, ?2014 ?10?:?12? ?PM
To: mailscanner at lists.mailscanner.info





RBL or grey listing ?


--
Jeremy McSpadden
Flux Labs | http://www.fluxlabs.net | Endless Solutions
Office : 850-250-5590x501 | Cell : 850-890-2543 | Fax : 850-254-2955





On Thu, May 22, 2014 at 7:22 PM -0700, "Jonathan Horne" <jonathanmhorne at outlook.com> wrote:






Greetings,




I have several MailScanner installs that lately, have been allowing an increased amount of spam to deliver. all separate systems, at separate sites, but all behaving the same way. more and more spam each week is getting thru. ive been noticing an increase at least over the past 3-4 weeks.




is there anything that can be done? previously when these systems were deployed (about 9-12 months ago, I forget now) they were incredibly effective.




thanks for any tips,

Jonathan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20140527/b36bf3a2/attachment.html
-------------- next part --------------
--
MailScanner mailing list
mailscanner at lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website!
Jonathan Horne
2014-05-27 14:24:04 UTC
Permalink
the only one not enabled as Always Include SpamAssassin Report. the spam score number format was %d I think, but I tried the setting below, looks like that will be more verbose.


overall, im not seeing rules get skipped, but emails that are obviously spams are just being no scored as such.


thanks for the advice!











From: Martin Hepworth
Sent: ?Friday?, ?May? ?23?, ?2014 ?9?:?32? ?AM
To: mailscanner at lists.mailscanner.info





Hi
add the SA info into email headers to see what the score and rule hits are ( helps with debug), in MailScanner.conf make sure the follow are set thus:
Spam Score Number Format = %5.2f

Detailed Spam Report = yes

Include Scores In SpamAssassin Report = yes

Always Include SpamAssassin Report = yes

Spam Score Number Format = %5.2f

This should give you some clue as to whats (not) happening as first step
--
Martin Hepworth, CISSP
Oxford, UK



On 23 May 2014 06:45, Michael Huntley <michael at huntley.net> wrote:


I always keep a sizable chunk of recent spam on hand to feed to spamassassin. I do it on a 45 day or so schedule. I place the spam in a folder and sa-learn it using the proper user. This seems to keep things sane.

Cheers!

mph




On 5/22/2014 7:12 PM, Jonathan Horne wrote:





Greetings,




I have several MailScanner installs that lately, have been allowing an increased amount of spam to deliver. all separate systems, at separate sites, but all behaving the same way. more and more spam each week is getting thru. ive been noticing an increase at least over the past 3-4 weeks.




is there anything that can be done? previously when these systems were deployed (about 9-12 months ago, I forget now) they were incredibly effective.




thanks for any tips,

Jonathan
















--
MailScanner mailing list
mailscanner at lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website!
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20140527/19e6d099/attachment.html
-------------- next part --------------
--
MailScanner mailing list
mailscanner at lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website!
Richard Mealing
2014-05-27 15:51:25 UTC
Permalink
If you don?t have mailwatch you can turn on ?Log Non Spam?, then you can see the scores in the logs. Maybe your threshold is wrong or you have turned it off altogether?

If you use clamav then you can add the signatured from sanesecurity and then you can treat emails as spam through the ?Virus Names Which Are Spam? option.

For example ?


Thanks,
Rich

From: mailscanner-bounces at lists.mailscanner.info [mailto:mailscanner-bounces at lists.mailscanner.info] On Behalf Of Jonathan Horne
Sent: 27 May 2014 15:24
To: mailscanner at lists.mailscanner.info
Subject: Re: MailScanner filtering out less and less spam

the only one not enabled as Always Include SpamAssassin Report. the spam score number format was %d I think, but I tried the setting below, looks like that will be more verbose.

overall, im not seeing rules get skipped, but emails that are obviously spams are just being no scored as such.

thanks for the advice!



From: Martin Hepworth<mailto:maxsec at gmail.com>
Sent: ?Friday?, ?May? ?23?, ?2014 ?9?:?32? ?AM
To: mailscanner at lists.mailscanner.info<mailto:mailscanner at lists.mailscanner.info>

Hi
add the SA info into email headers to see what the score and rule hits are ( helps with debug), in MailScanner.conf make sure the follow are set thus:

Spam Score Number Format = %5.2f

Detailed Spam Report = yes

Include Scores In SpamAssassin Report = yes

Always Include SpamAssassin Report = yes

Spam Score Number Format = %5.2f
This should give you some clue as to whats (not) happening as first step

--
Martin Hepworth, CISSP
Oxford, UK

On 23 May 2014 06:45, Michael Huntley <michael at huntley.net<mailto:michael at huntley.net>> wrote:
I always keep a sizable chunk of recent spam on hand to feed to spamassassin. I do it on a 45 day or so schedule. I place the spam in a folder and sa-learn it using the proper user. This seems to keep things sane.

Cheers!

mph


On 5/22/2014 7:12 PM, Jonathan Horne wrote:
Greetings,

I have several MailScanner installs that lately, have been allowing an increased amount of spam to deliver. all separate systems, at separate sites, but all behaving the same way. more and more spam each week is getting thru. ive been noticing an increase at least over the past 3-4 weeks.

is there anything that can be done? previously when these systems were deployed (about 9-12 months ago, I forget now) they were incredibly effective.

thanks for any tips,
Jonathan








--
MailScanner mailing list
mailscanner at lists.mailscanner.info<mailto:mailscanner at lists.mailscanner.info>
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website!

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20140527/892b1825/attachment.html
Glenn Steen
2014-05-28 10:59:50 UTC
Permalink
And beware excessive whitelisting! Some of that stuff may well bite you!;-)
--
-- Glenn
Post by Richard Mealing
If you don?t have mailwatch you can turn on ?Log Non Spam?, then you can
see the scores in the logs. Maybe your threshold is wrong or you have
turned it off altogether?
If you use clamav then you can add the signatured from sanesecurity and
then you can treat emails as spam through the ?Virus Names Which Are Spam?
option.
For example ?
Thanks,
Rich
mailscanner-bounces at lists.mailscanner.info] *On Behalf Of *Jonathan Horne
*Sent:* 27 May 2014 15:24
*To:* mailscanner at lists.mailscanner.info
*Subject:* Re: MailScanner filtering out less and less spam
the only one not enabled as Always Include SpamAssassin Report. the spam
score number format was %d I think, but I tried the setting below, looks
like that will be more verbose.
overall, im not seeing rules get skipped, but emails that are obviously
spams are just being no scored as such.
thanks for the advice!
*From:* Martin Hepworth <maxsec at gmail.com>
*Sent:* ?Friday?, ?May? ?23?, ?2014 ?9?:?32? ?AM
*To:* mailscanner at lists.mailscanner.info
Hi
add the SA info into email headers to see what the score and rule hits are
( helps with debug), in MailScanner.conf make sure the follow are set
Spam Score Number Format = %5.2f
Detailed Spam Report = yes
Include Scores In SpamAssassin Report = yes
Always Include SpamAssassin Report = yes
Spam Score Number Format = %5.2f
This should give you some clue as to whats (not) happening as first step
--
Martin Hepworth, CISSP
Oxford, UK
I always keep a sizable chunk of recent spam on hand to feed to
spamassassin. I do it on a 45 day or so schedule. I place the spam in a
folder and sa-learn it using the proper user. This seems to keep things
sane.
Cheers!
mph
Greetings,
I have several MailScanner installs that lately, have been allowing an
increased amount of spam to deliver. all separate systems, at separate
sites, but all behaving the same way. more and more spam each week is
getting thru. ive been noticing an increase at least over the past 3-4
weeks.
is there anything that can be done? previously when these systems were
deployed (about 9-12 months ago, I forget now) they were incredibly
effective.
thanks for any tips,
Jonathan
--
MailScanner mailing list
mailscanner at lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner
Before posting, read http://wiki.mailscanner.info/posting
Support MailScanner development - buy the book off the website!
--
MailScanner mailing list
mailscanner at lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner
Before posting, read http://wiki.mailscanner.info/posting
Support MailScanner development - buy the book off the website!
--
-- Glenn
email: glenn < dot > steen < at > gmail < dot > com
work: glenn < dot > steen < at > ap1 < dot > se
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20140528/fdb65cb7/attachment.html
Richard Mealing
2014-05-28 12:17:33 UTC
Permalink
Hit the wrong button and omitted my example..
Anyway, here?s my example ?

#Sanesecurity Signature (jurlbl.ndb)
header SPAMVIRUSJurlbl X-YOURORGANISATION-MailScanner-SpamVirus-Report =~ /Sanesecurity.Jurlbl/i
score SPAMVIRUSJurlbl 4.0
describe SPAMVIRUSJurlbl Spam Virus Junk


There are loads of databases you can use, it?s a fantastic ?bolt on? to clamd.

Thanks,
Rich


From: mailscanner-bounces at lists.mailscanner.info [mailto:mailscanner-bounces at lists.mailscanner.info] On Behalf Of Richard Mealing
Sent: 27 May 2014 16:51
To: 'mailscanner at lists.mailscanner.info'
Subject: RE: MailScanner filtering out less and less spam

If you don?t have mailwatch you can turn on ?Log Non Spam?, then you can see the scores in the logs. Maybe your threshold is wrong or you have turned it off altogether?

If you use clamav then you can add the signatured from sanesecurity and then you can treat emails as spam through the ?Virus Names Which Are Spam? option.

For example ?


Thanks,
Rich

From: mailscanner-bounces at lists.mailscanner.info<mailto:mailscanner-bounces at lists.mailscanner.info> [mailto:mailscanner-bounces at lists.mailscanner.info] On Behalf Of Jonathan Horne
Sent: 27 May 2014 15:24
To: mailscanner at lists.mailscanner.info<mailto:mailscanner at lists.mailscanner.info>
Subject: Re: MailScanner filtering out less and less spam

the only one not enabled as Always Include SpamAssassin Report. the spam score number format was %d I think, but I tried the setting below, looks like that will be more verbose.

overall, im not seeing rules get skipped, but emails that are obviously spams are just being no scored as such.

thanks for the advice!



From: Martin Hepworth<mailto:maxsec at gmail.com>
Sent: ?Friday?, ?May? ?23?, ?2014 ?9?:?32? ?AM
To: mailscanner at lists.mailscanner.info<mailto:mailscanner at lists.mailscanner.info>

Hi
add the SA info into email headers to see what the score and rule hits are ( helps with debug), in MailScanner.conf make sure the follow are set thus:

Spam Score Number Format = %5.2f

Detailed Spam Report = yes

Include Scores In SpamAssassin Report = yes

Always Include SpamAssassin Report = yes

Spam Score Number Format = %5.2f
This should give you some clue as to whats (not) happening as first step

--
Martin Hepworth, CISSP
Oxford, UK

On 23 May 2014 06:45, Michael Huntley <michael at huntley.net<mailto:michael at huntley.net>> wrote:
I always keep a sizable chunk of recent spam on hand to feed to spamassassin. I do it on a 45 day or so schedule. I place the spam in a folder and sa-learn it using the proper user. This seems to keep things sane.

Cheers!

mph


On 5/22/2014 7:12 PM, Jonathan Horne wrote:
Greetings,

I have several MailScanner installs that lately, have been allowing an increased amount of spam to deliver. all separate systems, at separate sites, but all behaving the same way. more and more spam each week is getting thru. ive been noticing an increase at least over the past 3-4 weeks.

is there anything that can be done? previously when these systems were deployed (about 9-12 months ago, I forget now) they were incredibly effective.

thanks for any tips,
Jonathan







--
MailScanner mailing list
mailscanner at lists.mailscanner.info<mailto:mailscanner at lists.mailscanner.info>
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website!

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20140528/64cd2aee/attachment.html
Loading...