Good afternoon.
Can you please tell me how to solve the problem?
We started receiving SPAM emails from GMAIL, see the examples below.
Of course, I can't block GMAIL by IP. Adding the sender to the BLACKLIST also does not seem to be effective. How do I set up PMG to filter similar emails?
Can you please tell me how to solve the problem?
We started receiving SPAM emails from GMAIL, see the examples below.
Of course, I can't block GMAIL by IP. Adding the sender to the BLACKLIST also does not seem to be effective. How do I set up PMG to filter similar emails?
Received: from MAIL05.innerdomain (172.30.21.129) by MAIL05.innerdomain
(172.30.21.129) with Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.4 via Mailbox
Transport; Tue, 15 Apr 2025 13:41:26 +0300
Received: from MAIL05.innerdomain (172.30.21.129) by MAIL05.innerdomain
(172.30.21.129) with Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.4; Tue, 15 Apr
2025 13:41:25 +0300
Received: from smtp40.outerdomain (172.30.21.120) by MAIL05.innerdomain
(172.30.21.129) with Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.4 via Frontend
Transport; Tue, 15 Apr 2025 13:41:25 +0300
Received: from EDGE02.innerdomain (localhost.localdomain [127.0.0.1])
by EDGE02.innerdomain (Proxmox) with ESMTP id AB05816152F;
Tue, 15 Apr 2025 13:41:25 +0300 (MSK)
Received: from mail-pl1-f177.google.com (mail-pl1-f177.google.com [209.85.214.177])
by EDGE02.innerdomain (Proxmox) with ESMTPS id 44B7116116B;
Tue, 15 Apr 2025 13:41:19 +0300 (MSK)
Received: by mail-pl1-f177.google.com with SMTP id d9443c01a7336-22409077c06so70076385ad.1;
Tue, 15 Apr 2025 03:41:19 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20230601; t=1744713677; x=1745318477; darn=outerdomain;
h=mime-version:disposition-notification-to:subject:message-id:from
:date:from:to:cc:subject:date:message-id:reply-to;
bh=IUTCS05e7xhOeuGpp0DwawogS+Ig1YXcUxCmzyaqsSE=;
b=WccNHD0DQBcW3DRUvQBX2ZbX948evSkUiqZVQRoUaBRKrIctCAyGrEld3HiN7OAkxo
pVRk+nI24mMOLAZDp6HeMHQk1qSKdqYUkADA+TxsKJVBSZMTfMV0MHfeIEhjUZ+nKcyV
j4U8pooqQA2xHvDuAoiMr38xP0zD1InfED67AMiiOSvw07CzceOExcnkpQTjyxnjJEUN
fPJGzOpqlsy++ZXtPR7nIwZithO3yK4rvfr+coJ/igKnWqbBsyHrmfuKPmKJQZovp6oo
kFtp42+z8w+Gn0/rfiR/oSr7eiJcSDLn3ZT47S/eh6zxDIrklW+RDpuCxLBnNPrhvSbR
jjhg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1744713677; x=1745318477;
h=mime-version:disposition-notification-to:subject:message-id:from
:date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
bh=IUTCS05e7xhOeuGpp0DwawogS+Ig1YXcUxCmzyaqsSE=;
b=RaUgYHKHTVc41r+2KnlcgNVC3pImgOkBiNXEQh0cwbd8ZE62jixvQUnyMIdOboCbFM
WbiddMtCuBc2218gZYOtg7Zq/671yZBeUr2VykGLF/+xD9Fe7HxgkBIg96kH3+riJFQm
GeuV7TXJKCbobjcnmmnShRFPZunDH6GbDQ1Kds6kflu2UZ3GX8oRCryiplgopcY/Ww3B
PV2gyj+C0M2shNVAwOBcQQN277wLOLyCQlzT1C01do1lOfqNT0AvbmXfkj8o2vjkM/1W
JSQFA/YMEIKpI8Tk1QUvKNuaUWug+sdMJuG7zPqVFaSexGux5wvupd3VBoZMGswD+upU
RmyA==
X-Forwarded-Encrypted: i=1; AJvYcCU+6rPw8DtgZjjJw/rrGLbLnUmu6TSAc1VWHfkzFnmIb3e0S8JbgTs/jImwkUJGPnmykdLQcQPufjM=@outerdomain, AJvYcCW7BpNWtkmCLQvbOQudFEinCmibZfQhHSHyz0BwjMBJ4d9/QeXhNPtdFaDYueP/IlsLBFn9@outerdomain
X-Gm-Message-State: AOJu0YwaSueKLYXVdcJcjHmfuoOTw5n24JcVz3ja9kYiWhSKN4it3Hdf
CsEQi7qs3Cy/+Ru3OIlLU2QC0upaZPNE6aw2fD9l4KZZyiQhtV6B
X-Gm-Gg: ASbGncvrMlBmADNGlDpEguGKLCj8mb2gFvQiRY7NmVSAdKCJBKAPKFfoKUDY4RtRTOq
pGRNxwOV9ZN2nUElFUY94OwSvhhTTNmcyI+YPCLHwUU281stiesZgZ914L75+87TZH9EvqbQqXJ
VGbuIxwJi5Sc2fxfv+aI7FI3f2cxqg0BWxmmtmSYfDM1Dgp8d2RdKX6ao9s5ynh8EE8AFnAw7Vw
wtYvoAX4oglr3X1he08BwtN6gNbw17GF66o49b3VsqRKGR06oDUFgcwJlAMd6iNQvzzGNc4evpP
wmBndI8A1fwTuWdKSWQfvw2bsSz/bdJcdMhr+Buvr0H+tCSnpYn70KcoV+3NEctP39JzIgQPTvo
u/LCGKK+60zJP1A==
X-Google-Smtp-Source: AGHT+IHMziT7aHZeBg/SWXJUfVFh5E5DXW/OYmCJo88EpsHGdCNFmJR4PGMLaEqZlv+WENNI1Kj5Rw==
X-Received: by 2002:a17:902:9885:b0:224:24d5:f20a with SMTP id d9443c01a7336-22bea4fe132mr186189605ad.48.1744713676677;
Tue, 15 Apr 2025 03:41:16 -0700 (PDT)
Received: from CHINAMI-6T5SRGC ([103.223.122.190])
by smtp.gmail.com with ESMTPSA id d9443c01a7336-22ac7c93addsm113735605ad.152.2025.04.15.03.41.06
(version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256);
Tue, 15 Apr 2025 03:41:16 -0700 (PDT)
Date: Tue, 15 Apr 2025 18:41:04 +0800
From: kishashaw111 <kishashaw111@gmail.com>
Message-ID: <5C25327A-4118-40B9-8BAA-FD69AF2C66DB@gmail.com>
Subject: Truck prices 2025/4/14-2025/4/20
Disposition-Notification-To: kishashaw111<kishashaw111@gmail.com>
X-Mailer: MailMasterPC/5.2.2.1009 (10.0.19045)
X-MailMaster-ShowOneRcpt: 1
X-CUSTOM-MAIL-MASTER-SENT-ID: FA634A72-1EFC-4721-9F73-06C203B159C7
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="=_mailmaster-67fe37c0_0_18be_="
X-SPAM-LEVEL: Spam detection results: 2
DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid
DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature
DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain
DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain
FREEMAIL_ENVFROM_END_DIGIT 0.25 Envelope-from freemail username ends in digit
FREEMAIL_FROM 0.001 Sender email is commonly abused enduser mail provider
GB_FREEMAIL_DISPTO 0.001 Disposition-Notification-To/From or Disposition-Notification-To/body contain different freemails
GB_FREEMAIL_NUM 1 Freemail spammy address
HTML_MESSAGE 0.001 HTML included in message
KAM_NUMSUBJECT 0.5 Subject ends in numbers excluding current years
MALFORMED_FREEMAIL 0.1 Bad headers on message from free email service
MISSING_HEADERS 1.207 Missing To: header
RCVD_IN_DNSWL_NONE -0.0001 Sender listed at https://www.dnswl.org/, no trust
RCVD_IN_MSPIKE_H3 0.001 Good reputation (+3)
RCVD_IN_MSPIKE_WL 0.001 Mailspike good senders
SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record
SPF_PASS -0.001 SPF: sender matches SPF record
T_KAM_HTML_FONT_INVALID 0.01 Test for Invalidly Named or Formatted Colors in HTML
To: Undisclosed recipients:;
Return-Path: kishashaw111@gmail.com
X-MS-Exchange-Organization-Network-Message-Id: a452b79d-c17c-42f8-3ca2-08dd7c0a127a
X-MS-Exchange-Organization-AVStamp-Enterprise: 1.0
X-MS-Exchange-Organization-AuthSource: MAIL05.innerdomain
X-MS-Exchange-Organization-AuthAs: Anonymous
X-MS-Exchange-Transport-EndToEndLatency: 00:00:00.2770362
X-MS-Exchange-Processed-By-BccFoldering: 15.02.1544.004
Received: from MAIL05.innerdomain (172.30.21.129) by MAIL05.innerdomain
(172.30.21.129) with Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.4 via Mailbox
Transport; Tue, 15 Apr 2025 11:06:30 +0300
Received: from MAIL05.innerdomain (172.30.21.129) by MAIL05.innerdomain
(172.30.21.129) with Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.4; Tue, 15 Apr
2025 11:06:30 +0300
Received: from smtp40.outerdomain (172.30.21.120) by MAIL05.innerdomain
(172.30.21.129) with Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.4 via Frontend
Transport; Tue, 15 Apr 2025 11:06:30 +0300
Received: from EDGE02.innerdomain (localhost.localdomain [127.0.0.1])
by EDGE02.innerdomain (Proxmox) with ESMTP id 0ABE216151A
for <info@outerdomain>; Tue, 15 Apr 2025 11:06:30 +0300 (MSK)
Received: from mail-pg1-f194.google.com (mail-pg1-f194.google.com [209.85.215.194])
by EDGE02.innerdomain (Proxmox) with ESMTPS id 3A0F9161529
for <info@outerdomain>; Tue, 15 Apr 2025 11:06:25 +0300 (MSK)
Received: by mail-pg1-f194.google.com with SMTP id 41be03b00d2f7-7fd581c2bf4so4512194a12.3
for <info@outerdomain>; Tue, 15 Apr 2025 01:06:25 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20230601; t=1744704382; x=1745309182; darn=outerdomain;
h=to:subject:message-id:date:from:mime-version:from:to:cc:subject
:date:message-id:reply-to;
bh=6wyo+fICMq8Af2sYxsPP5l5PTtxsWkBvl8gal+QwW7E=;
b=O6JAl+TOD1qPC9iQgqxN8/xZOJDuoQ5SElhJeHL61JIpxTFGPY6fFeTYeM24QSP/54
yOqH+8nY5AuoDywPIaRdjIf6+hct4Q5kojlMRZ11YPxNdNmUEPVXbdqNJZ3GvbahFE1G
VMFpbv+nDW8rwo+eJkENR2almtKs5CgM/4DBvK5u/IFi4hfZNNHpTXYYbx3EFf9EO2Ug
0lCPvbtkEO+e0oYjIdnVmsYi/D/tGsAr0Se4UZG7vuzwwU1MnavbZ8SY1HaSmx5BLKm8
xXtR2K3n+/I2bGnZ1o57Dh5J3gXtk318wUPoYhUgF3xN/buw6KUO47EETmXfzqopWrVq
uv7Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1744704382; x=1745309182;
h=to:subject:message-id:date:from:mime-version:x-gm-message-state
:from:to:cc:subject:date:message-id:reply-to;
bh=6wyo+fICMq8Af2sYxsPP5l5PTtxsWkBvl8gal+QwW7E=;
b=qLwEm8sF4xouwLLmgf4HYR0A4csSSlHrGgRJdfRH/PN8UXF8g5go5lK5iNEyFNuFxM
nWRWX65bg5LqseVx1n8IQZm8PsCT6FMVVm0nFRP0IGQWP6B7gU2OUPz+nlsv4nxW4QKp
S0yf0/6LfTtL1H09zdRk7szwuGJ0zmHiIVlJjMTM8e1QPrk7EYCsxIM1153j/87lMSLv
P62DNclC6cSBb6Lqm1UFyyP32RN5pAgm8nbYkKcA/k5rBsSXVISWeVQ1h/lgvPMga0EW
Eynd+2YrAGQd3wOr6uNT56v6S759oZoFpXllsmzv1XiLgdjC/uxdygFdAEevmqQ5xb1w
3VHw==
X-Forwarded-Encrypted: i=1; AJvYcCV8UoeC1W0MjO6BTlzGq/xVrq/dwxwuc+TNBpZuWTI8XqAndQybbQl6+OzF4KE9NxBgulvV@outerdomain
X-Gm-Message-State: AOJu0Yw0uMfIhJzdYL3wTDSnV+uWMZ6LvpTsSVXsl9pj5MZgdaVdo6Rc
YO9ZbY8+DzydbjTLLF7JdYZ9ZeFC8v0T6YWyKNqHxfEQyLz1XjSnvbhmjwKgvh+BwwTBFORkxkp
ZM/Ur6zoPHDx4hRu/sdY1INv6PM0=
X-Gm-Gg: ASbGncvYumykfZM9ettl/NdXvoSnAGj+IwFY2XVBjSE7lBYdSOzj6bQ2uijgm58aIXN
J0IQ/CA0cmKW7J1D6PjjNe2jGrNE7GhsXiZS0C2Jx87FX7wrcF9Yf/yDE1qZmDJbtQRmw7lqK6z
es3RB9Mpjt3Mz/1NIUIcN91vJb6ulO/csjAA==
X-Google-Smtp-Source: AGHT+IFS7ki9JX1yTQXxksgp+ZG7nKz31wOgM5oGpH6r0oRa6Xs14EzxrOPaHECYplzVR0QyA+HdPJd5JRIbuML2BXI=
X-Received: by 2002:a17:90b:582b:b0:308:5273:4dee with SMTP id
98e67ed59e1d1-30852734e83mr2191884a91.15.1744704381789; Tue, 15 Apr 2025
01:06:21 -0700 (PDT)
MIME-Version: 1.0
From: Adrain Zhou <sadigablikazun@gmail.com>
Date: Tue, 15 Apr 2025 16:06:10 +0800
X-Gm-Features: ATxdqUFj-aodqH6HFUyLvwtuFnpUB4xi-13Zq07O0VN_lXurc-0ioMgTLn0Ukw8
Message-ID: <CAKDBgYC1oYJ2dwJze2qkv0dkt0W8j8_WG-FkCyd+oWbfZix4sw@mail.gmail.com>
Subject: Please check our rail freight from China to Russia/Belarus
To: undisclosed-recipients:;
Content-Type: multipart/alternative; boundary="000000000000ea311b0632cca48e"
X-SPAM-LEVEL: Spam detection results: 0
AWL 0.002 Adjusted score from AWL reputation of From: address
DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid
DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature
DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain
DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain
FREEMAIL_FROM 0.001 Sender email is commonly abused enduser mail provider
HTML_FONT_LOW_CONTRAST 0.001 HTML font color similar or identical to background
HTML_MESSAGE 0.001 HTML included in message
KAM_SHORT 0.001 Use of a URL Shortener for very short URL
POISEN_SPAM_PILL 0.1 Meta: its spam
POISEN_SPAM_PILL_1 0.1 random spam to be learned in bayes
POISEN_SPAM_PILL_3 0.1 random spam to be learned in bayes
RCVD_IN_DNSWL_NONE -0.0001 Sender listed at https://www.dnswl.org/, no trust
RCVD_IN_MSPIKE_H3 0.001 Good reputation (+3)
RCVD_IN_MSPIKE_WL 0.001 Mailspike good senders
SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record
SPF_PASS -0.001 SPF: sender matches SPF record
T_REMOTE_IMAGE 0.01 Message contains an external image
Return-Path: sadigablikazun@gmail.com
X-MS-Exchange-Organization-Network-Message-Id: d44966a8-4a87-470f-a647-08dd7bf46dd1
X-MS-Exchange-Organization-AVStamp-Enterprise: 1.0
X-MS-Exchange-Organization-AuthSource: MAIL05.innerdomain
X-MS-Exchange-Organization-AuthAs: Anonymous
X-MS-Exchange-Transport-EndToEndLatency: 00:00:00.2120221
X-MS-Exchange-Processed-By-BccFoldering: 15.02.1544.004