Question about KAM_SOMETLD_ARE_BAD_TLD

Andrei9385

Member
Nov 30, 2023
38
1
8
Привет.

1. Почему сообщение блокируется, если в KAM_SOMETLD_ARE_BAD_TLD условии нет домена .mail?
2. Как я могу редактировать домены из этого списка?

KAM_SOMETLD_ARE_BAD_TLD.png
 
Hi,

please write your posts in english, otherwise it's hard to help
i tried google translate for your post:

Привет.

1. Почему сообщение блокируется, если в KAM_SOMETLD_ARE_BAD_TLD условии нет домена .mail?
2. Как я могу редактировать домены из этого списка?


Hello.

1. Why is the message blocked if there is no .mail domain in the KAM_SOMETLD_ARE_BAD_TLD condition?
2. How can I edit domains from this list?

1. it also checks the content and headers of the mail, so without the full mail, it's hard to say on what it triggered
2. you cannot, this is fixed in the KAM rules, you can however edit the spamscore of that particular rule: see chapter: https://pmg.proxmox.com/pmg-docs/pmg-admin-guide.html#pmgconfig_spamdetector in the docs
 
  • Like
Reactions: Andrei9385
Thank you. According to this header, can you tell me the reason for the blocking ?

Delivered-To: v.volodin@3l.ru Return-Path: nivo72@mail.ru Received-SPF: pass (mail.ru ... _spf.mail.ru: 45.84.129.69 is authorized to use 'nivo72@mail.ru' in 'mfrom' identity (mechanism 'ip4:45.84.128.0/23' matched)) receiver=Valdor.ad.3l.ru; identity=mailfrom; envelope-from="nivo72@mail.ru"; helo=f702.i.mail.ru; client-ip=45.84.129.69 Received: from f702.i.mail.ru (f702.i.mail.ru [45.84.129.69]) by Valdor.ad.3l.ru (Proxmox) with ESMTPS id 4CEFE182049 for <v.volodin@3l.ru>; Fri, 22 Dec 2023 08:14:19 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=mail.ru; s=mail4; h=Content-Type:Reply-To:Message-ID:Date:MIME-Version:Subject:To:From:From:Subject:Content-Type:Content-Transfer-Encoding:To:Cc; bh=eQ4WBjQ0UNpVknT/HwQeU5AP2nXq/EMsypYZfrfSMuU=; t=1703222059;x=1703312059; b=cNOaXRP72HU1cIX15fBOuN2L4fFDIU3clRdci9/LAOyB94j0QJ6qKG3p5zorCtferZ7uBJUlnqhqS5+tsxeVLiVHRtp3lePVz8abIrHoCv7Uj6M2CVuXgQoo4lf1Vi02nIn2+ktffF8OdI3W2R0lmH6EeX61m17plXlvfMd2S88+W248iPPo7asxOK/svBq/q4UYRtvhO/bvXdasfSAm/xwVO3Q2k+UJsU12YqebafEQRpB+cS5qFIdbq53cC/2VQUw2MadPUMPz+cN6da7DUdpVnWcA+E6hhXZN59PPcpN5S00ptyZOGLjJb+tRmqknZHM6EF7YR5GuvTJMGEnzFg==; Received: by f702.i.mail.ru with local (envelope-from <nivo72@mail.ru>) id 1rGXrR-0000JM-74 for v.volodin@3l.ru; Fri, 22 Dec 2023 08:14:13 +0300 Received: by fake_e_aj_host with HTTP; Fri, 22 Dec 2023 08:14:13 +0300 From: =?UTF-8?B?0JXQu9C10L3QsCDQktC+0LvQvtC00LjQvdCw?= <nivo72@mail.ru> To: =?UTF-8?B?di52b2xvZGlu?= <v.volodin@3l.ru> subject: SPAM: =?UTF-8?Q?=D0=9E=D1=82=D0=BF=D1=80=D0=B0=D0=B2=D0=BA=D0=B0=20?= =?UTF-8?Q?=D0=BF=D0=BE=20?= =?UTF-8?Q?=D1=8D=D0=BB=D0=B5=D0=BA=D1=82=D1=80=D0=BE=D0=BD=D0=BD=D0=BE=D0=B9=20?= =?UTF-8?Q?=D0=BF=D0=BE=D1=87=D1=82=D0=B5=20?=691B061C-8B7B-4859-975C-868B9747A8FF.pdf MIME-Version: 1.0 X-Mailer: Mail.Ru Mailer 1.0 Date: Fri, 22 Dec 2023 08:14:13 +0300 Message-ID: <1703222053.775503837@f174.i.mail.ru> X-Priority: 3 (Normal) Reply-To: =?UTF-8?B?0JXQu9C10L3QsCDQktC+0LvQvtC00LjQvdCw?= <nivo72@mail.ru> Content-Type: multipart/mixed; boundary="----vdajYhBWfbAfy2lyjnN90J99mjchIKcm-IPvbRL30WHhRrdSy-1703222053" Authentication-Results: f702.i.mail.ru; auth=pass smtp.auth=nivo72@mail.ru smtp.mailfrom=nivo72@mail.ru X-Mailru-Src: fe X-4EC0790: 10 X-7564579A: B8F34718100C35BD X-77F55803: 119C1F4DF6A9251C047F89FE214EBC15AFBBA70AF3AF8EA811AEBA15109372858FD872164937FA4C20CE0387B346D9C29066F19DDC0FF8DBB79A1EE5D6CFEA11CBDF7AADC3168B8A X-7FA49CB5: 70AAF3C13DB70168C09775C1D3CA48CF27F547E70D814A38B2086D80B0504778CF19DD082D7633A0ACBFF42033827DA764CD17681C2FEB7A23F8577A6DFFEA7C4E26D63774B61FC1C4224003CC836476ABE134FDCE4E2725BFD28B28ED4578739E625A9149C048EE9ECD01F8117BC8BEBFD28B28ED4578732EF20D2F80756B5F40A5AABA2AD37119BCF491FFA38154B6D5E8D9A59859A8B6F4758F8EC3E027EDBCF491FFA38154B6B5C8C57E37DE458B7AC6C5076A9912D9A93B80C6DEB9DEE97C6FB206A91F05B238536013C6885F6021E6B6636130AD957D6ED8DD83F142CB02ED4CEA229C1FA827C277FBC8AE2E8BAA867293B0326636D2E47CDBA5A96583C09775C1D3CA48CF5E26F3260102D3FB117882F4460429724CE54428C33FAD30A8DF7F3B2552694AC26CFBAC0749D213D2E47CDBA5A9658378DA827A17800CE701C05ED510F1C3F19FA2833FD35BB23DF004C906525384302BEBFE083D3B9BA71A620F70A64A45A98AA50765F7900637A451E1E29F2EDBED6D1867E19FE1407959CC434672EE6371089D37D7C0E48F6C8AA50765F7900637427B078F297B269AEFF80C71ABB335746BA297DBC24807EABDAD6C7F3747799A X-C1DE0DAB: 0D63561A33F958A5D2E0CAFE7617BEDD5CCF0ABE13649368AAF0FFF103DD0312F87CCE6106E1FC07E67D4AC08A07B9B01DAA61796BF5227BCB5012B2E24CD356 X-C8649E89: 1C3962B70DF3F0ADE2815F1F17DA7190F22D334B9B612B432CCB5A6D6581D03D0776B5B2C279835F17BCBE6708A5A68D02015372BE9702A2BE0C783B5F42DBBD4C3B77C46F52E5BAD0E9E47AF5285EE42B531DBE08B6A27CE258096F5873ED151B56794A24E1788A49E75517F564A323F5A8A7FFF29179BF52EE4E5D9E54FDA44C41F94D744909CECBD9FF066CFE41DE2FD1FA715FA7279FCC2E138FFB4ACBED X-D57D3AED: 3ZO7eAau8CL7WIMRKs4sN3D3tLDjz0dLbV79QFUyzQ2Ujvy7cMT6pYYqY16iZVKkSc3dCLJ7zSJH7+u4VD18S7Vl4ZUrpaVfd2+vE6kuoey4m4VkSEu530nj6fImhcD4MUrOEAnl0W826KZ9Q+tr5+wYjsrrSY/u8Y3PrTqANeitKFiSd6Yd7yPpbiiZ/d5BsxIjK0jGQgCHUM3Ry2Lt2G3MDkMauH3h0dBdQGj+BB/iPzQYh7XS329fgu+/vnDhAOy59T/ifnKV9i4J162WMg== X-Mailru-MI: 10000000000400800 X-Mailru-Sender: C10344ED1A7CE1C1FEB5AD81A5CD7EBFA72156C57E8623A7D0F718B247C393463623D6D133F0FBFAF88451B4EDDC779A5741A55E8AFF8007A865350EB6915815E3B20D4B0CCE638DC25C2E7011D4219E908C227F6AC68D648321DD71810D370894889C9CD72890785FEEDEB644C299C0ED14614B50AE0675 X-Mras: Ok X-Spam: undefined X-SPAM-LEVEL: Spam detection results: 5 BAYES_00 -1.9 Bayes spam probability is 0 to 1% DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_PASS -0.1 DMARC pass policy FREEMAIL_ENVFROM_END_DIGIT 0.25 Envelope-from freemail username ends in digit FREEMAIL_FROM 0.001 Sender email is commonly abused enduser mail provider FREEMAIL_REPLYTO_END_DIGIT 0.25 Reply-To freemail username ends in digit HTML_MESSAGE 0.001 HTML included in message KAM_SHORT 0.001 Use of a URL Shortener for very short URL KAM_SOMETLD_ARE_BAD_TLD 5 .bar, .beauty, .buzz, .cam, .casa, .cfd, .club, .date, .guru, .link, .live, .monster, .online, .press, .pw, .quest, .rest, .sbs, .shop, .stream, .top, .trade, .wiki, .work, .xyz TLD abuse SHORT_SHORTNER 1.999 Short body with little more than a link to a shortener SPF_HELO_PASS -0.001 SPF: HELO matches SPF record SPF_PASS -0.001 SPF: sender matches SPF record T_FREEMAIL_DOC_PDF 0.01 MS document or PDF attachment, from freemail T_SCC_BODY_TEXT_LINE -0.01 - URIBL_DBL_BLOCKED_OPENDNS 0.001 ADMINISTRATOR NOTICE: The query to dbl.spamhaus.org was blocked due to usage of an open resolver. See https://www.spamhaus.org/returnc/pub/ [adobeacrobat.app.link,www.ozon.ru,www.nalog.ru] ------vdajYhBWfbAfy2lyjnN90J99mjchIKcm-IPvbRL30WHhRrdSy-1703222053 Content-Type: multipart/alternative; boundary="--ALT--vdajYhBWfbAfy2lyjnN90J99mjchIKcm1703222053"
 
Last edited:
it seems there was a link to 'adobeacrobat.app.link' somewhere in the body, and '.link' is in the list
 
  • Like
Reactions: Andrei9385
Thanks, I set the rating for KAM_SOMETLD_ARE_BAD_TLD to 0.00 to analyze because emails get caught in spam that are not really spam. Is it possible to add in the next update to edit this list ?
 
no, those rules are not really editable, so that won't be possible
you can try to write the creators of the KAM spamassassin list that they can adapt their rules for 'app.link' maybe ? (since that seems like a legit site) but no idea if they'll do something like this
 
  • Like
Reactions: Andrei9385

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!