Yahoo Groups archive

Milter-greylist

Index last updated: 2026-04-13 23:57 UTC

Message

Re: [milter-greylist] wrong delay handling at ACL change

2016-12-19 by Jim Klimov

19 \u0434\u0435\u043a\u0430\u0431\u0440\u044f 2016�\u0433. 0:30:00 CET, "Greg Troxel gdt@... [milter-greylist]" <milter-greylist@yahoogroups.com> \u043f\u0438\u0448\u0435\u0442:
>
>"Marcus Schopen lists-yahoogroups@... [milter-greylist]"
><milter-greylist@yahoogroups.com> writes:
>
>>> On the other hand, a host being on a bad blocklist leading to big
>>> delays and getting taken off is going to cause all sorts of
>problems,
>>> and people delaying mail for 12h instead of 15m does not seem likely
>>> to rise to the top.
>>
>> Could you technically explain the last point please?
>
>What I mean is that if a host gets put on an RBL that indicates such
>bad
>behavior that people want to delay mail for 12h, then it's likely that
>other anti-spam software will apply other penalties to that host, such
>as high scores, just rejecting SMTP connections, etc.    So if the big
>problem is that when it's taken off the list you think the greylist
>timer should drop to 15m immediately, but that it still gets 12h from
>the time it first tried, that's perhaps not as serious as what other
>people will be doing based on having been on this blocklist.

On a similar note: sometimes we have spam bursts where a "legit" but abused mail server sent out spam. It may have got greylisted, but got autowhited on timeout and resubmission of a message, and only some hours later that IP got into DNS RBLs because its infestation continues and spam level got to a critical threshold of the honeypots. But our relay already trusts the host as previously autowhited (and the trust continues as we get new spams regularly).

Is there a way to do enforce some checks (like DNS RBL) for *auto*whited hosts as well (but avoid the re-check for manual/ldap/dnswl etc. whitelists)?

Jim
--
Typos courtesy of K-9 Mail on my Samsung Android

Attachments

Move to quarantaine

This moves the raw source file on disk only. The archive index is not changed automatically, so you still need to run a manual refresh afterward.