Spam not getting caught

bcc

New Member
Feb 19, 2009
6
0
1
Hi,

We've been using Proxmox for number of years and always been happy with spam catching rates. Very rarely we've seen spam slip through or legitimate email getting accidentally quarantined. Over last couple of months though things got worse and our power users get more spam slip through than before. Here is one example:

[FONT=&quot]Apr 21 09:43:53[/FONT]
[FONT=&quot]smtpd[/FONT]
[FONT=&quot]connect from unknown[74.50.95.17][/FONT]
[FONT=&quot]Apr 21 09:43:54[/FONT]
[FONT=&quot]smtpd[/FONT]
[FONT=&quot]89A481F8E56: client=unknown[74.50.95.17][/FONT]
[FONT=&quot]Apr 21 09:43:55[/FONT]
[FONT=&quot]proxprox[/FONT]
[FONT=&quot]1F8F884BCE3C3B1DAAC: new mail
message-id=<2efe26c843c4e6d69f4a287904e63956@bluespan.pt> [/FONT]
[FONT=&quot]Apr 21 09:43:55[/FONT]
[FONT=&quot]cleanup[/FONT]
[FONT=&quot]89A481F8E56: message-id=<2efe26c843c4e6d69f4a287904e63956@bluespan.pt>[/FONT]
[FONT=&quot]Apr 21 09:43:55[/FONT]
[FONT=&quot]qmgr[/FONT]
[FONT=&quot]89A481F8E56: from=<orcascandy@bluespan.pt>, size=7048, nrcpt=1 (queue active)[/FONT]
[FONT=&quot]Apr 21 09:43:57[/FONT]
[FONT=&quot]smtpd[/FONT]
[FONT=&quot]disconnect from unknown[74.50.95.17][/FONT]
[FONT=&quot]Apr 21 09:43:58[/FONT]
[FONT=&quot]proxprox[/FONT]
[FONT=&quot]1F8F884BCE3C3B1DAAC: SA score=4/5 time=2.804 bayes=0.500214262838918
autolearn=no hits=BAYES_50,DRUGS_ERECTILE,FB_CIALIS_LEO3,HTML_MESSAGE
MIME_HTML_MOSTLY,RAZOR2_CF_RANGE_51_100,RAZOR2_CF_RANGE_E8_51_100,RAZOR2_CHECK
RCVD_IN_SORBS_WEB,RDNS_NONE,SUBJECT_DRUG_GAP_C [/FONT]
[FONT=&quot]Apr 21 09:43:58[/FONT]
[FONT=&quot]proxprox[/FONT]
[FONT=&quot]1F8F884BCE3C3B1DAAC: accept mail to <bburns@bcc.com.au> (14E2A1F8F93) [/FONT]
[FONT=&quot]Apr 21 09:43:58[/FONT]
[FONT=&quot]proxprox[/FONT]
[FONT=&quot]1F8F884BCE3C3B1DAAC: processing time: 3.037 seconds [/FONT]
[FONT=&quot]Apr 21 09:43:58[/FONT]
[FONT=&quot]lmtp[/FONT]
[FONT=&quot]89A481F8E56: to=<user@bcc.com.au>, relay=127.0.0.1[127.0.0.1]:10024,
delay=3.9, delays=0.77/0/0.04/3.1, dsn=2.5.0, status=sent (250 2.5.0 OK
(1F8F884BCE3C3B1DAAC))[/FONT]
[FONT=&quot]Apr 21 09:43:58[/FONT]
[FONT=&quot]qmgr[/FONT]
[FONT=&quot]89A481F8E56: removed[/FONT]
[FONT=&quot]Apr 21 09:43:58[/FONT]
[FONT=&quot]smtpd[/FONT]
[FONT=&quot]connect from localhost[127.0.0.1][/FONT]
[FONT=&quot]Apr 21 09:43:58[/FONT]
[FONT=&quot]smtpd[/FONT]
[FONT=&quot]14E2A1F8F93: client=unknown[74.50.95.17][/FONT]
[FONT=&quot]Apr 21 09:43:58[/FONT]
[FONT=&quot]smtpd[/FONT]
[FONT=&quot]disconnect from localhost[127.0.0.1][/FONT]
[FONT=&quot]Apr 21 09:43:58[/FONT]
[FONT=&quot]cleanup[/FONT]
[FONT=&quot]14E2A1F8F93: message-id=<2efe26c843c4e6d69f4a287904e63956@bluespan.pt>[/FONT]
[FONT=&quot]Apr 21 09:43:58[/FONT]
[FONT=&quot]qmgr[/FONT]
[FONT=&quot]14E2A1F8F93: from=<orcascandy@bluespan.pt>, size=7230, nrcpt=1 (queue active)[/FONT]
[FONT=&quot]Apr 21 09:43:58[/FONT]
[FONT=&quot]smtp[/FONT]
[FONT=&quot]14E2A1F8F93: to=<user@bcc.com.au>, relay=192.168.1.5[192.168.1.5]:25,
delay=0.2, delays=0.07/0.01/0.01/0.12, dsn=2.6.0, status=sent (250 2.6.0
<2efe26c843c4e6d69f4a287904e63956@bluespan.pt> Queued mail for delivery)[/FONT]
[FONT=&quot]Apr 21 09:43:58[/FONT]
[FONT=&quot]qmgr[/FONT]
[FONT=&quot]14E2A1F8F93: removed[/FONT]

Looking at this log, it is bloody obvious to me this is spam. Subject contains words that identify spam 100%. Why is it calculating such a low spam probability score? Has anything changed in the product? I haven't had to touch config on our Proxmox for long time. It's always been working just fine. All I do is install latest service packs and hotfixes. Or do I need to change my config?

Can you please explain?

Regards,

Tomas Repka
 
you are filter level is still 5 (default). as you run your gateway since a long time you can set this to 3.
(this example email has a spam score of 4).
 
Hi Tom,

Thanks for response. Setting spam level to 3 is an option by I didn't want to do it as last time we tested it, legit email was getting caught as well. I might try setting it to 4.

I was hoping there is something else I can do to address this.

Regards,

Tomas
 
if you own a commercial license just send a backup of your config to our support team for review and you will get optimization tips - I assume you run 2.4. - 4237?
 
support@ ...
 
Thanks. I have just emailed config through. Please advise if there is anything we can do to optimize.

Tomas