Step by step improving antispam protection.

BiteMyElbow

Member
Jul 5, 2021
31
0
11
39
Hello to everyone.
Exuse me, I'm not so familiar with antispam protection.

We have Exchange 2013 installed with Proxmox Mail Gateway 7.3-3 as an incoming mail point. I have setuped DNS black lists and it works well, but i still has several SPAM mails in my mailbox almost every day. Other users have it too.

Can anyone explain to me STEP BY STEP, what should i do to improve our antispam protection? What should i search for in PMG to understand why SPAM mails are not filtered and how can i fix it (which tools there are in PMG for that)?

Is it possible to make SPAM folders for all the users so that they can move junk mail to it and antispam can learn from it? Is there any manual to make it?

Thank you in advance.
 
Last edited:
Today example:
Sep 22 09:39:29 postfix/smtpd[473550]: connect from mail1.falconsender.ru[185.117.118.196]
Sep 22 09:39:29 postfix/smtpd[473550]: A700D16104E: client=mail1.falconsender.ru[185.117.118.196]
Sep 22 09:39:29 postfix/cleanup[473526]: A700D16104E: message-id=<mass-230922093922_282873_20193311_b14aaf75a0@Falconsender.ru>
Sep 22 09:39:29 postfix/qmgr[846]: A700D16104E: from=<trash@Falconsender.ru>, size=34410, nrcpt=1 (queue active)
Sep 22 09:39:29 postfix/smtpd[473550]: disconnect from mail1.falconsender.ru[185.117.118.196] ehlo=1 mail=1 rcpt=1 data=1 quit=1 commands=5
Sep 22 09:39:29 pmg-smtp-filter[473611]: 1613A6650D36A1BE6CA: new mail message-id=<mass-230922093922_282873_20193311_b14aaf75a0@Falconsender.ru>#012
Sep 22 09:39:31 pmg-smtp-filter[473611]: 1613A6650D36A1BE6CA: SA score=0/5 time=1.280 bayes=0.00 autolearn=no autolearn_force=no hits=AWL(-0.001),BAYES_00(-1.9),DKIM_INVALID(0.1),DKIM_SIGNED(0.1),HEADER_FROM_DIFFERENT_DOMAINS(0.249),HTML_MESSAGE(0.001),KAM_DMARC_STATUS(0.01),MIME_HTML_ONLY(0.1),RCVD_IN_DNSWL_NONE(-0.0001),RCVD_IN_MSPIKE_BL(0.001),RCVD_IN_MSPIKE_L4(0.001),SPF_HELO_PASS(-0.001),SPF_NONE(0.001)
Sep 22 09:39:31 postfix/smtpd[473557]: connect from comhost.comdomain[127.0.0.1]
Sep 22 09:39:31 postfix/smtpd[473557]: 1B1571613C6: client=comhost.comdomain[127.0.0.1], orig_client=mail1.falconsender.ru[185.117.118.196]
Sep 22 09:39:31 postfix/cleanup[473591]: 1B1571613C6: message-id=<mass-230922093922_282873_20193311_b14aaf75a0@Falconsender.ru>
Sep 22 09:39:31 postfix/qmgr[846]: 1B1571613C6: from=<trash@Falconsender.ru>, size=35612, nrcpt=1 (queue active)
Sep 22 09:39:31 postfix/smtpd[473557]: disconnect from comhost.comdomain[127.0.0.1] ehlo=1 xforward=1 mail=1 rcpt=1 data=1 commands=5
Sep 22 09:39:31 pmg-smtp-filter[473611]: 1613A6650D36A1BE6CA: accept mail to <user01@domain.com> (1B1571613C6) (rule: default-accept)
Sep 22 09:39:31 pmg-smtp-filter[473611]: 1613A6650D36A1BE6CA: processing time: 1.378 seconds (1.28, 0.034, 0)
Sep 22 09:39:31 postfix/lmtp[473610]: A700D16104E: to=<user01@domain.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=1.5, delays=0.06/0/0.04/1.4, dsn=2.5.0, status=sent (250 2.5.0 OK (1613A6650D36A1BE6CA))
Sep 22 09:39:31 postfix/qmgr[846]: A700D16104E: removed
Sep 22 09:39:31 postfix/smtp[473618]: 1B1571613C6: to=<user01@domain.com>, relay=MAIL04.domain.local[192.168.21.112]:25, delay=0.25, delays=0.05/0/0.06/0.14, dsn=2.6.0, status=sent (250 2.6.0 <mass-230922093922_282873_20193311_b14aaf75a0@Falconsender.ru> [InternalId=44049184588034, Hostname=MAIL04.domain.local] Queued mail for delivery)
Sep 22 09:39:31 postfix/qmgr[846]: 1B1571613C6: removed

But i received it even with other sender:
Received: from MAIL04.domain.local (192.168.21.112) by MAIL04.domain.local
(192.168.21.112) with Microsoft SMTP Server (TLS) id 15.0.1497.2 via Mailbox
Transport; Fri, 22 Sep 2023 09:39:31 +0300
Received: from MAIL04.domain.local (192.168.21.112) by MAIL04.domain.local
(192.168.21.112) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Fri, 22 Sep
2023 09:39:31 +0300
Received: from EDGE02.domain.local (192.168.21.120) by MAIL04.domain.local
(192.168.21.112) with Microsoft SMTP Server (TLS) id 15.0.1497.2 via Frontend
Transport; Fri, 22 Sep 2023 09:39:31 +0300
Received: from EDGE02.domain.local (localhost.localdomain [127.0.0.1])
by EDGE02.domain.local (Proxmox) with ESMTP id 1B1571613C6
for <user01@domail.com>; Fri, 22 Sep 2023 09:39:31 +0300 (MSK)
Received-SPF: SoftFail (MAIL04.domain.local: domain of transitioning
ss@ecargentum.ru discourages use of 192.168.21.120 as permitted sender)
Received-SPF: none (falconsender.ru: No applicable sender policy available) receiver=EDGE02.domain.local; identity=mailfrom; envelope-from="trash@falconsender.ru"; helo=mail1.falconsender.ru; client-ip=185.117.118.196
Received: from mail1.falconsender.ru (mail1.falconsender.ru [185.117.118.196])
by EDGE02.domain.local (Proxmox) with ESMTP id A700D16104E
for <user01@domail.com>; Fri, 22 Sep 2023 09:39:29 +0300 (MSK)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; s=dkim; d=ecargentum.ru;
h=Content-Type:MIME-Version:To:From:Reply-To:Message-Id:List-Unsubscribe:Date:Subject; i=ss@ecargentum.ru;
bh=WiINKDl0h0O0EKDi0HU0cd7M2cU=;
b=MiYNfhOsd7P3Qz9kTjMlhygZdiiEJGDiP6wsKoUGAKHEzOZVet6FcBZfFgjhf/FL2rM9qtWxUjmP
qiyGFSHu4I1WDhxHWBfOOTdS25quYxTNsrpSA0vlbLValSqFasoIBoudVCGkm4JCZwRkYnokdZYb
GPYvB6EXoBVXW83nis0=
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; s=dkim; d=mail1.falconsender.ru;
h=Content-Type:MIME-Version:To:From:Reply-To:Message-Id:List-Unsubscribe:Date:Subject;
bh=WiINKDl0h0O0EKDi0HU0cd7M2cU=;
b=HH3vHNgLYlgfvkhHsjl0zvSs86jGesWHig1BrX/QrPnCRxlEPKZw4KAXciD3oKe60rV0S4qTHZI7
n2lQ4au2oQkN23ncVE+9opwK7Cwy6qRLlDQloNF1HiPwkrLqDAud66flAfdgXBqhAOI4yP70BUBj
+lLpV0ptIJqpg7DiK1Q=
DomainKey-Signature: a=rsa-sha1; c=nofws; q=dns; s=dkim; d=ecargentum.ru;
b=GDt2J7JJLOf0cX1+E40wzwGCvNdphs9csNKz5IDKTrH1ts9tpaJ0KNk9oBJvZ5pRHMmEkbMx1ImL
lS2YBqRfGdzhvDt7DrWRBb2oSW3DvVifmHSCGoZvfkhNHBra0oot3aKZrWz/WTd5kuzKBtTtcDLZ
SWY+lBn/nsIhK/9edQg=;
Content-Type: text/html; charset=utf-8
MIME-Version: 1.0
To: =?utf-8?B?IA==?= <user01@domail.com>
From: =?utf-8?B?0J7QpiDQkNGA0LPQtdC90YLRg9C8?= <ss@ecargentum.ru>
X-Mailru-Msgtype: mass2-viptolstobokov
X-Smart-Mailer: 2/6
X-Smart-QID: 1466966806
Reply-To: =?utf-8?B?0J7QpiDQkNGA0LPQtdC90YLRg9C8?= <ss@ecargentum.ru>
Precedence: bulk
Message-ID: <mass-230922093922_282873_20193311_b14aaf75a0@Falconsender.ru>
List-Unsubscribe: <http://fsclick.ru/l_ru/delete.html?q=0ioy5U00001QJzOC7d5d4b820001aOy&robot=1>
Date: Fri, 22 Sep 2023 09:39:22 +0300
Subject: =?utf-8?B?0J3QvtCy0L7QtSDQsiDQsdGD0YXQs9Cw0LvRgtC10YDRgdC60L7QvCDRg9GH0LXRgtC1INC4INC90LDQu9C+0LPQvtC+0LHQu9C+0LbQtdC90LjQuC4g0K3QutGB0L/QtdGA0YLQvdGL0Lkg0LDQvdCw0LvQuNC3INC/0L7RgdC70LXQtNC90LjRhSDQuNC30LzQtdC90LXQvdC40Lkg0LfQsNC60L7QvdC+0LTQsNGC0LXQu9GM0YHRgtCy0LAuINCe0YfQvdC+INC4INC+0L3Qu9Cw0LnQvQ==?=
X-SPAM-LEVEL: Spam detection results: 0
AWL -0.001 Adjusted score from AWL reputation of From: address
BAYES_00 -1.9 Bayes spam probability is 0 to 1%
DKIM_INVALID 0.1 DKIM or DK signature exists, but is not valid
DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid
HEADER_FROM_DIFFERENT_DOMAINS 0.249 From and EnvelopeFrom 2nd level mail domains are different
HTML_MESSAGE 0.001 HTML included in message
KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment
MIME_HTML_ONLY 0.1 Message only has text/html MIME parts
RCVD_IN_DNSWL_NONE -0.0001 Sender listed at https://www.dnswl.org/, no trust
RCVD_IN_MSPIKE_BL 0.001 Mailspike blocklisted
RCVD_IN_MSPIKE_L4 0.001 Bad reputation (-4)
SPF_HELO_PASS -0.001 SPF: HELO matches SPF record
SPF_NONE 0.001 SPF: sender does not publish an SPF Record
Return-Path: trash@Falconsender.ru
X-MS-Exchange-Organization-PRD: ecargentum.ru
X-MS-Exchange-Organization-SenderIdResult: SoftFail
X-MS-Exchange-Organization-Network-Message-Id: 4e95c836-c85e-47fd-a253-08dbbb36ad47
X-Auto-Response-Suppress: DR, OOF, AutoReply
X-MS-Exchange-Organization-AuthSource: MAIL04.domain.local
X-MS-Exchange-Organization-AuthAs: Anonymous

What should i setup to filter such mails?
Thank you.
 
See the Getting Started Page in the PMG wiki:
https://pmg.proxmox.com/wiki/index.php/Getting_started_with_Proxmox_Mail_Gateway

and the reference documentation:
https://pmg.proxmox.com/pmg-docs/

first 2 Things I'd recommend is disabling autowhitelists and bayes in the SpamDetector settings

(on a sidenote Exchange 2013 is End of Support since April 2023)
Thank you for answer.

Yes. I have studied your guides and i have setuped DNS black lists. And there is no additional info in your documentation what can i do if i I still get SPAM?

I'm not that familiar with this topic so please don't be too hard on me.

I have given SPAM example and i dont understand why this mail was not filtered. Could you please give me clear STEP BY STEP algorithm what should i do (what should i search in logs for and where are right logs in PMG?) when i receive SPAM despite the configured antispam?
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!