> Headers show that the message come from DSL and cable pools, so IMO it's > from a botnet. X-Greylist header reports that the sender retried only one > time and after 5 minutes and a few seconds. My greylist delay is 5 mn, > so I wonder if this is a coincidence, or if the spam engine reads the > text message in the SMTP reply that says "please come back in 00:05:00". > > Do we have to face spam engine that implement resends? What is your > experience with that problem? Yes, it is 5 minutes and some seconds for me too. I had on one minute greylist time, increased now it to 6 minutes. (by the way, would be nice to specify in second granularity) Since I am in quite mode (not communicating the delay), pretty sure that the spamware does not read the SMTP reply text. Anyhow, the spamware retries now in double time (~10m20s). I think nothing really to do. We expected this to happen. It just costs a bit more to send the spam. Bests, Attila
Message
RE: [milter-greylist] new spam engines
2006-04-04 by attila.bruncsak@itu.int
Attachments
- No local attachments were found for this message.