When investigating spam, I noticed several times that URIBL scores sometimes do not work on proxmox. And the mail server behind proxmox scores the URIBL for the same letter. According to the log, scoring works for other letters.
Here is an example,
on proxmox: SA score=0/5 time=3.467 bayes=undefined autolearn=disabled hits=DKIM_SIGNED(0.1),DKIM_VALID(-0.1),DKIM_VALID_AU(-0.1),DKIM_VALID_EF(-0.1),DMARC_PASS(-0.1),HTML_MESSAGE(0.001),HTTPS_HTTP_MISMATCH(0.1),KAM_INFOUSMEBIZ(0.75),SPF_HELO_PASS(-0.001),SPF_PASS(-0.001)
on mail server behind proxmox same latter:
X-Spam-Status: No, score=5.561 tagged_above=2 required=6.2
tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1,
DKIM_VALID_EF=-0.1, FROM_FMBLA_NEWDOM14=1, HTML_MESSAGE=0.001,
HTTPS_HTTP_MISMATCH=0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001,
T_SCC_BODY_TEXT_LINE=-0.01, [B]URIBL_ABUSE_SURBL=1.948,
URIBL_DBL_SPAM=2.5, URIBL_PH_SURBL=0.224[/B]]
Other logos that the scoring works:
cat /var/log/mail.log | grep -i --color="always" "URIBL_"
"
Apr 17 05:24:36 pmg pmg-smtp-filter[212905]: 3013BD643CBBF0354D9: SA score=17/5 time=3.808 bayes=undefined autolearn=disabled hits=CBJ_GiveMeABreak(1.75),DMARC_MISSING(0.1),GOOG_REDIR_NORDNS(3.099),HTML_MESSAGE(0.001),HTML_MIME_NO_HTML_TAG(0.635),KAM_2TLD_PROBLEMS(2),KAM_DMARC_STATUS(0.01),KAM_SA_ZA_ABUSE(4.5),MIME_HTML_ONLY(0.1),RDNS_NONE(2.5),SPF_HELO_PASS(-0.001),SPF_PASS(-0.001),URIBL_ABUSE_SURBL(3)
Apr 17 05:24:48 pmg pmg-smtp-filter[212933]: 3013BD643CBBFEE900C: SA score=17/5 time=1.981 bayes=undefined autolearn=disabled hits=CBJ_GiveMeABreak(1.75),DMARC_MISSING(0.1),GOOG_REDIR_NORDNS(3.099),HTML_MESSAGE(0.001),HTML_MIME_NO_HTML_TAG(0.635),KAM_2TLD_PROBLEMS(2),KAM_DMARC_STATUS(0.01),KAM_SA_ZA_ABUSE(4.5),MIME_HTML_ONLY(0.1),RDNS_NONE(2.5),SPF_HELO_PASS(-0.001),SPF_PASS(-0.001),URIBL_ABUSE_SURBL(3)
Apr 17 05:27:23 pmg pmg-smtp-filter[212905]: 3013BD643CBC0B8B243: SA score=8/5 time=144.285 bayes=undefined autolearn=disabled hits=DMARC_MISSING(0.1),FSL_BULK_SIG(0.001),HTML_MESSAGE(0.001),KAM_DMARC_STATUS(0.01),KAM_MANYCOMMENTS(1.2),MIME_HTML_ONLY(0.1),RAZOR2_CF_RANGE_51_100(2.43),RAZOR2_CHECK(1.729),SPF_HELO_PASS(-0.001),SPF_PASS(-0.001),T_KAM_HTML_FONT_INVALID(0.01),URIBL_ABUSE_SURBL(3),URIBL_PH_SURBL(0.001)
Apr 17 07:44:46 pmg pmg-smtp-filter[216738]: 301720643CDCCB9CD94: SA score=11/5 time=2.944 bayes=undefined autolearn=disabled hits=AWL(-1.500),DMARC_MISSING(0.1),HTML_MESSAGE(0.001),HTML_MIME_NO_HTML_TAG(0.635),KAM_2TLD_PROBLEMS(2),KAM_DMARC_STATUS(0.01),KAM_SA_ZA_ABUSE(4.5),MIME_HTML_ONLY(0.1),MIME_QP_LONG_LINE(0.001),RDNS_NONE(2.5),SPF_HELO_PASS(-0.001),SPF_PASS(-0.001),T_SCC_BODY_TEXT_LINE(-0.01),URIBL_ABUSE_SURBL(3)
Apr 17 08:16:47 pmg pmg-smtp-filter[217687]: 3016F0643CE44E7B9F5: SA score=14/5 time=1.113 bayes=undefined autolearn=disabled hits=DKIM_INVALID(0.1),DKIM_SIGNED(0.1),DMARC_MISSING(0.1),EWG_CIALIS(1),EWG_VIAGRA(1),FONT_INVIS_MSGID(0.001),HTML_MESSAGE(0.001),HTML_TEXT_INVISIBLE_FONT(1.999),KAM_DMARC_STATUS(0.01),MIME_HTML_ONLY(0.1),RAZOR2_CF_RANGE_51_100(2.43),RAZOR2_CHECK(1.729),RDNS_NONE(2.5),SPF_HELO_NONE(0.001),SPF_NONE(0.001),T_REMOTE_IMAGE(0.01),T_SCC_BODY_TEXT_LINE(-0.01),URIBL_ABUSE_SURBL(3),WORD_INVIS_MANY(0.001)
Apr 17 08:52:08 pmg pmg-smtp-filter[218964]: 3016F7643CEC94A6800: SA score=16/5 time=3.330 bayes=undefined autolearn=disabled hits=AWL(2.156),DATE_IN_PAST_06_12(1.103),DKIM_SIGNED(0.1),DKIM_VALID(-0.1),DKIM_VALID_AU(-0.1),DKIM_VALID_EF(-0.1),DMARC_PASS(-0.1),HTML_MESSAGE(0.001),KAM_BODY_URIBL_PCCC(9),KAM_TRACKIMAGE(0.2),MIME_HTML_ONLY(0.1),RAZOR2_CF_RANGE_51_100(2.43),RAZOR2_CHECK(1.729),SPF_HELO_NONE(0.001),SPF_PASS(-0.001),T_FILL_THIS_FORM_SHORT(0.01),T_SCC_BODY_TEXT_LINE(-0.01)
"
How can i investigate this further?
Here is an example,
on proxmox: SA score=0/5 time=3.467 bayes=undefined autolearn=disabled hits=DKIM_SIGNED(0.1),DKIM_VALID(-0.1),DKIM_VALID_AU(-0.1),DKIM_VALID_EF(-0.1),DMARC_PASS(-0.1),HTML_MESSAGE(0.001),HTTPS_HTTP_MISMATCH(0.1),KAM_INFOUSMEBIZ(0.75),SPF_HELO_PASS(-0.001),SPF_PASS(-0.001)
on mail server behind proxmox same latter:
X-Spam-Status: No, score=5.561 tagged_above=2 required=6.2
tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1,
DKIM_VALID_EF=-0.1, FROM_FMBLA_NEWDOM14=1, HTML_MESSAGE=0.001,
HTTPS_HTTP_MISMATCH=0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001,
T_SCC_BODY_TEXT_LINE=-0.01, [B]URIBL_ABUSE_SURBL=1.948,
URIBL_DBL_SPAM=2.5, URIBL_PH_SURBL=0.224[/B]]
Other logos that the scoring works:
cat /var/log/mail.log | grep -i --color="always" "URIBL_"
"
Apr 17 05:24:36 pmg pmg-smtp-filter[212905]: 3013BD643CBBF0354D9: SA score=17/5 time=3.808 bayes=undefined autolearn=disabled hits=CBJ_GiveMeABreak(1.75),DMARC_MISSING(0.1),GOOG_REDIR_NORDNS(3.099),HTML_MESSAGE(0.001),HTML_MIME_NO_HTML_TAG(0.635),KAM_2TLD_PROBLEMS(2),KAM_DMARC_STATUS(0.01),KAM_SA_ZA_ABUSE(4.5),MIME_HTML_ONLY(0.1),RDNS_NONE(2.5),SPF_HELO_PASS(-0.001),SPF_PASS(-0.001),URIBL_ABUSE_SURBL(3)
Apr 17 05:24:48 pmg pmg-smtp-filter[212933]: 3013BD643CBBFEE900C: SA score=17/5 time=1.981 bayes=undefined autolearn=disabled hits=CBJ_GiveMeABreak(1.75),DMARC_MISSING(0.1),GOOG_REDIR_NORDNS(3.099),HTML_MESSAGE(0.001),HTML_MIME_NO_HTML_TAG(0.635),KAM_2TLD_PROBLEMS(2),KAM_DMARC_STATUS(0.01),KAM_SA_ZA_ABUSE(4.5),MIME_HTML_ONLY(0.1),RDNS_NONE(2.5),SPF_HELO_PASS(-0.001),SPF_PASS(-0.001),URIBL_ABUSE_SURBL(3)
Apr 17 05:27:23 pmg pmg-smtp-filter[212905]: 3013BD643CBC0B8B243: SA score=8/5 time=144.285 bayes=undefined autolearn=disabled hits=DMARC_MISSING(0.1),FSL_BULK_SIG(0.001),HTML_MESSAGE(0.001),KAM_DMARC_STATUS(0.01),KAM_MANYCOMMENTS(1.2),MIME_HTML_ONLY(0.1),RAZOR2_CF_RANGE_51_100(2.43),RAZOR2_CHECK(1.729),SPF_HELO_PASS(-0.001),SPF_PASS(-0.001),T_KAM_HTML_FONT_INVALID(0.01),URIBL_ABUSE_SURBL(3),URIBL_PH_SURBL(0.001)
Apr 17 07:44:46 pmg pmg-smtp-filter[216738]: 301720643CDCCB9CD94: SA score=11/5 time=2.944 bayes=undefined autolearn=disabled hits=AWL(-1.500),DMARC_MISSING(0.1),HTML_MESSAGE(0.001),HTML_MIME_NO_HTML_TAG(0.635),KAM_2TLD_PROBLEMS(2),KAM_DMARC_STATUS(0.01),KAM_SA_ZA_ABUSE(4.5),MIME_HTML_ONLY(0.1),MIME_QP_LONG_LINE(0.001),RDNS_NONE(2.5),SPF_HELO_PASS(-0.001),SPF_PASS(-0.001),T_SCC_BODY_TEXT_LINE(-0.01),URIBL_ABUSE_SURBL(3)
Apr 17 08:16:47 pmg pmg-smtp-filter[217687]: 3016F0643CE44E7B9F5: SA score=14/5 time=1.113 bayes=undefined autolearn=disabled hits=DKIM_INVALID(0.1),DKIM_SIGNED(0.1),DMARC_MISSING(0.1),EWG_CIALIS(1),EWG_VIAGRA(1),FONT_INVIS_MSGID(0.001),HTML_MESSAGE(0.001),HTML_TEXT_INVISIBLE_FONT(1.999),KAM_DMARC_STATUS(0.01),MIME_HTML_ONLY(0.1),RAZOR2_CF_RANGE_51_100(2.43),RAZOR2_CHECK(1.729),RDNS_NONE(2.5),SPF_HELO_NONE(0.001),SPF_NONE(0.001),T_REMOTE_IMAGE(0.01),T_SCC_BODY_TEXT_LINE(-0.01),URIBL_ABUSE_SURBL(3),WORD_INVIS_MANY(0.001)
Apr 17 08:52:08 pmg pmg-smtp-filter[218964]: 3016F7643CEC94A6800: SA score=16/5 time=3.330 bayes=undefined autolearn=disabled hits=AWL(2.156),DATE_IN_PAST_06_12(1.103),DKIM_SIGNED(0.1),DKIM_VALID(-0.1),DKIM_VALID_AU(-0.1),DKIM_VALID_EF(-0.1),DMARC_PASS(-0.1),HTML_MESSAGE(0.001),KAM_BODY_URIBL_PCCC(9),KAM_TRACKIMAGE(0.2),MIME_HTML_ONLY(0.1),RAZOR2_CF_RANGE_51_100(2.43),RAZOR2_CHECK(1.729),SPF_HELO_NONE(0.001),SPF_PASS(-0.001),T_FILL_THIS_FORM_SHORT(0.01),T_SCC_BODY_TEXT_LINE(-0.01)
"
How can i investigate this further?