I'm looking at a way to stop some generic spam from getting through. I have some spam thats getting through at shouldn't be and would like to know how I can better block this sort of spam.
In the logs, it looks as follows:
The email shows as being from: noreply@server.com, but the email is coming in from slot0.greemertrips.com. I've changed the actual end result mail addresses and domains to user@domain.ca in the post below.
Currently the only DNSBL I am using is zen.spamhaus.org, however when I lookup the hostname on mxtoolbox.com it it listed on Spamhaus, barracuda and ibmsip24 DNSBL's, yet for some reason that email was able to get bast the spam filter.
Any ideas as to how I can better block this type of spam from getting past?
In the logs, it looks as follows:
The email shows as being from: noreply@server.com, but the email is coming in from slot0.greemertrips.com. I've changed the actual end result mail addresses and domains to user@domain.ca in the post below.
Currently the only DNSBL I am using is zen.spamhaus.org, however when I lookup the hostname on mxtoolbox.com it it listed on Spamhaus, barracuda and ibmsip24 DNSBL's, yet for some reason that email was able to get bast the spam filter.
Any ideas as to how I can better block this type of spam from getting past?
Jan 21 04:19:12 | noreply@server.com | user@domain.ca | accepted/delivered | |
Jan 21 04:19:07 swarmx1 postfix/smtpd[371024]: connect from slot0.greemertrips.com[104.168.236.4] Jan 21 04:19:07 swarmx1 postfix/smtpd[371024]: Anonymous TLS connection established from slot0.greemertrips.com[104.168.236.4]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits) Jan 21 04:19:07 swarmx1 postfix/smtpd[371024]: D40DC402DF: client=slot0.greemertrips.com[104.168.236.4] Jan 21 04:19:07 swarmx1 postfix/cleanup[371008]: D40DC402DF: message-id=<20200121024846.10F138D3D812F817@server.com> Jan 21 04:19:07 swarmx1 postfix/qmgr[20531]: D40DC402DF: from=<noreply@server.com>, size=4174, nrcpt=1 (queue active) Jan 21 04:19:08 swarmx1 pmg-smtp-filter[369661]: 2138E5E26C20C02A2F: new mail message-id=<20200121024846.10F138D3D812F817@server.com>#012 Jan 21 04:19:08 swarmx1 postfix/smtpd[371024]: disconnect from slot0.greemertrips.com[104.168.236.4] ehlo=2 starttls=1 mail=1 rcpt=1 data=1 quit=1 commands=7 Jan 21 04:19:12 swarmx1 pmg-smtp-filter[369661]: 2138E5E26C20C02A2F: SA score=1/5 time=4.763 bayes=0.00 autolearn=no autolearn_force=no hits=BAYES_00(-1.9),HTML_FONT_LOW_CONTRAST(0.001),HTML_MESSAGE(0.001),KAM_DMARC_STATUS(0.01),KAM_LAZY_DOMAIN_SECURITY(1),MIME_HTML_ONLY(0.1),PDS_FRNOM_TODOM_NAKED_TO(1),PDS_FROM_NAME_TO_DOMAIN(0.999),SPF_HELO_NONE(0.001),SPF_NONE(0.001) Jan 21 04:19:12 swarmx1 postfix/smtpd[371014]: connect from localhost[127.0.0.1] Jan 21 04:19:12 swarmx1 postfix/smtpd[371014]: C40B240212: client=localhost[127.0.0.1], orig_client=slot0.greemertrips.com[104.168.236.4] Jan 21 04:19:12 swarmx1 postfix/cleanup[371008]: C40B240212: message-id=<20200121024846.10F138D3D812F817@server.com> Jan 21 04:19:12 swarmx1 postfix/qmgr[20531]: C40B240212: from=<noreply@server.com>, size=5145, nrcpt=1 (queue active) Jan 21 04:19:12 swarmx1 postfix/smtpd[371014]: disconnect from localhost[127.0.0.1] ehlo=1 xforward=1 mail=1 rcpt=1 data=1 commands=5 Jan 21 04:19:12 swarmx1 pmg-smtp-filter[369661]: 2138E5E26C20C02A2F: accept mail to <user@domain.ca> (C40B240212) (rule: default-accept) Jan 21 04:19:12 swarmx1 pmg-smtp-filter[369661]: 2138E5E26C20C02A2F: processing time: 4.795 seconds (4.763, 0.015, 0) Jan 21 04:19:12 swarmx1 postfix/lmtp[371027]: D40DC402DF: to=<user@domain.ca>, relay=127.0.0.1[127.0.0.1]:10024, delay=5, delays=0.2/0.01/0/4.8, dsn=2.5.0, status=sent (250 2.5.0 OK (2138E5E26C20C02A2F)) Jan 21 04:19:12 swarmx1 postfix/qmgr[20531]: D40DC402DF: removed Jan 21 04:19:12 swarmx1 postfix/smtp[371015]: C40B240212: to=<user@domain.ca>, relay=192.168.11.221[192.168.11.221]:25, delay=0.06, delays=0/0/0.05/0.01, dsn=2.0.0, status=sent (250 Mail queued for delivery) Jan 21 04:19:12 swarmx1 postfix/qmgr[20531]: C40B240212: removed |