Blocking TLD

Hi. In this situation i use rule like this:
1 In what object create group "Block by TLD"
2 In group create object Match Field with value From=@.+\.bio$
1684969131390.png
3 Create rule TLD off with action Block and Object Block by TLD
 
Did this really work?
For me with this, From (should it be From: ?)
@.+\.ru$
it still sends .ru to the regular spam checks, instead of blocking it. (admin@s6.whatever.ru)
Rule is first in list for me, '99'
Block TLD

Priority: 99
Direction: In
Active: Yes

Action: Block
What: Block by TLD.
 
Did this really work?
For me with this, From (should it be From: ?)
@.+\.ru$
it still sends .ru to the regular spam checks, instead of blocking it. (admin@s6.whatever.ru)
Rule is first in list for me, '99'
Block TLD

Priority: 99
Direction: In
Active: Yes

Action: Block
What: Block by TLD.
Please provide the logs for such a mail - maybe then we can see what the issue is.
Is the Object with the regex a 'What' Object to match the from header or a Who Object to match the envelope sender?
 
It's a WHAT object as per the "how to" above :)

But I updated yesterday to
.*@.*\.ru
and that seems to match better. (past 24 hours, so could be too early to say)

Maybe the rule engine didn't allow for domain only matches anymore.. ?
 
Confirmed. The new rule blocked it.

Not sure why ti goes through spamassassin and gets a score first, when block is set as first rule. But perhaps it's part of SA process to also block?
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!