Re: [milter-greylist] Re: Fake/wildcard SPF domain rejection
2007-11-02 by manu@netbsd.org
... Better than +all, you can check whether your own IP address validates the sender SPF record. If it does, odd are that you have a wide-open SPF record. I
Yahoo Groups archive
Messages
Page 65 of 144 · 7199 messages matched
2007-11-02 by manu@netbsd.org
... Better than +all, you can check whether your own IP address validates the sender SPF record. If it does, odd are that you have a wide-open SPF record. I
2007-11-02 by Jim Hermann
... See http://tech.groups.yahoo.com/group/milter-greylist/message/3701 We need all the SPF return codes available, plus a custom return code for +all results.
2007-11-02 by Сергей Коган
Hi ! More and more spammers are using misconfigured (or spam-and-drop) domains with wildcard (+all) SPF policy. This defeats milter-greylist protection, as
2007-10-31 by manu@netbsd.org
... The person in charge of the machine if away from keyboard for a week. We ll have to wait for him to come back. -- Emmanuel Dreyfus
2007-10-31 by manu@netbsd.org
... Updated. -- Emmanuel Dreyfus http://hcpnet.free.fr/pubz manu@netbsd.org
2007-10-31 by Nerijus Baliunas
Hello, The link to README in http://hcpnet.free.fr/milter-greylist/ (http://hcpnet.free.fr/milter-greylist/README) is an old version. Regards, Nerijus
2007-10-30 by manu@netbsd.org
... I ve notified the person that provides us this service. Let s wait for the fix, now... -- Emmanuel Dreyfus http://hcpnet.free.fr/pubz manu@netbsd.org
2007-10-30 by Nerijus Baliunas
Hello, cvs does not work. # export CVS_RSH=ssh # cvs -danoncvs@anoncvs.fr.netbsd.org:/milter-greylist co -P milter-greylist cvs server: cannot find module
2007-10-30 by Johann E. Klasek
... 4.0rc2 works fine also on Solaris 9 x86 (32bit) and enabled stdio-hack (USE_FD_POOL) in MX-sync configuration with an Linux x86_64 system based on 4.0rc1.
2007-10-30 by manu@netbsd.org
After a few months of code settleing, here is milter-greylist 4.0 http://ftp.espci.fr/pub/milter-greylist/milter-greylist-4.0.tgz MD5 (milter-greylist-4.0.tgz)
2007-10-30 by manu@netbsd.org
... You have a web front-end that queries your database? You might want to give a try at the urlcheck keyword in milter-greylist ACL. I use it to dynamically
2007-10-30 by Michael Mansour
Hi Emmanuel, ... Yes, as a caveat the person would need to get used to running milter-greylist -cf or script it with an errorlevel 0 response before actually
2007-10-29 by manu@netbsd.org
... An include statement would be an interesting feature indeed. OTOH, the ability to query a database directly might be even more interesting. You ll have to
2007-10-29 by Matt Kettler
... You don t need a real mailserver to retry. You also don t need a lot of time to retry. Spammers don t retry because they re trying to keep their bot
2007-10-29 by Michael Mansour
Hi Emmanuel, ... I also haven t had any dramas with the 4.0rc2 version. One thing I d like to suggest though, as I want to integrate milter-greylist with
2007-10-29 by Emmanuel Dreyfus
... Thank you for the report. I suspect it s high time for releasing 4.0. -- Emmanuel Dreyfus manu@netbsd.org
2007-10-29 by shuttlebox
... I have been running 4.0b4 for almost three weeks with no problems and 4.0rc2 since before the weekend, also with no problems. No crashes and mx syncing
2007-10-28 by manu@netbsd.org
... tls This is used to select the distinguished name (DN) of a user that succeeded STARTTLS. Using such a clause automatically dis- able global
2007-10-28 by Jim Hermann
... easily retry.. Why can they just as easily retry if they can link against openSSL? I thought that spammers did not retry because it took too much time or
2007-10-28 by Jim Hermann
... You mean the passing reference to global STARTTLS and SMTP AUTH whitelisting under the WHITELIST Section? I can t find any other reference to STARTTLS.
2007-10-27 by manu@netbsd.org
... greylist.conf man page. -- Emmanuel Dreyfus http://hcpnet.free.fr/pubz manu@netbsd.org
2007-10-27 by Dan Mahoney, System Admin
... That was more tongue-in-cheek than anything else, heh. -Dan -- You recreate the stars in the sky with cows? -Furrball, March 7 2005, on Katamari Damacy
2007-10-27 by Matt Kettler
... Does it matter? If they link against openSSL, they can also jut as easily retry.. Remember, greylisting isn t resistant to a clever spammer. Never will
2007-10-27 by Jim Hermann
... Which part of TFM says that TLS bypasses greylisting? This part in Chapter 14 Using TLS? Using the tls clause, an ACL could match any email that
2007-10-27 by manu@netbsd.org
... RTFM! :-) TLS validation cause a message to be whitelisted, except if you use the noauth configuration statement. You can also setup ACL using the tls
2007-10-27 by Dan Mahoney, System Admin
... Hrmmm, then the next question is: does greylisting check the cert validity? My own system has the CA roots fully configured, so if it s a true
2007-10-26 by Matt Kettler
... Yep. You ll see messages like this in your logs: milter-greylist: STARTTLS succeeded for DN= xyz , bypassing greylisting Which is really quite reasonable.
2007-10-26 by Jim Hermann
Does TLS bypass greylisting like authentication? Oct 26 16:39:13 host sm-acceptingconnections[2716]: STARTTLS=server, relay=deliver.hol.gr [62.38.3.31],
2007-10-25 by Dan Mahoney, System Admin
... I m aware of that -- my goal is different from yours, though. Yours is to manage known senders of good mail. Mine is simply to maintain a list of
2007-10-25 by Benoit Branciard
... DNSWL aims to inventory all known legitimate email servers , that are servers which are powered by real MTAs (not spambots). Greylisting sole goal is to
2007-10-25 by Dan Mahoney, System Admin
... Sure, because spammers will DDOS a whitelist, so then everyone s mail is as delayed as theirs is? -Dan -- this is too stupid even for irc -mtreal, EFnet
2007-10-25 by manu@netbsd.org
... I guess the goal is to address a possible DDoS attack of DNSRBL by spammers. -- Emmanuel Dreyfus http://hcpnet.free.fr/pubz manu@netbsd.org
2007-10-24 by Dan Mahoney, System Admin
... Part of my desire here would be to actually put the code for this site right in the 451 return code. ... Last updated 19 months ago, crashes at the end
2007-10-24 by Emmanuel Dreyfus
... You can also use DNS dynamic updates to manage your zone file from your forms. ... I can provide you a secondary DNS if you need one. -- Emmanuel Dreyfus
2007-10-24 by Brian W. Antoine
... Admin ... Been there, done that. :) When the smoke cleared I ended up creating a daily report that users could opt into that would tell them what had been
2007-10-24 by shuttlebox
... You may want to bring all the above together in something that you feel is better than what is available today, I just want to make sure you know that it
2007-10-24 by Dan Mahoney, System Admin
All, I just spent an hour trying to explain greylisting to one of my end-users (I greylist against APEWS) I am registering the above domain name for the usage
2007-10-24 by Nerijus Baliunas
... No, they are features. But you are right that default build without --defines should work without changing permissions manually. So it you think that user
2007-10-24 by Nerijus Baliunas
... If you mean rpmbuild --define build_user smmsp -tb milter-greylist-4.0xx.tgz does not use the spec file you are incorrect. Regards, Nerijus
2007-10-24 by Emmanuel Dreyfus
... As I don t use that RPM stuff, I m no enthousiast at touching it on my own: I don t even know how to test a change is fine. So send a patch, and don t miss
2007-10-24 by Michael Mansour
... You should also note Emmanuel that the command he used earlier does not even use the spec file. Regards, Michael.
2007-10-24 by Michael Mansour
Hi Emmanuel, ... No, the spec file does need to be fixed. Building an RPM manually is usually done with the least amount of arguments like this: # rpmbuild -bb
2007-10-24 by manu@netbsd.org
... No need to change anything, then? -- Emmanuel Dreyfus http://hcpnet.free.fr/pubz manu@netbsd.org
2007-10-23 by Nerijus Baliunas
... I created rpm with a command: rpmbuild --define build_user smmsp -tb milter-greylist-4.0xx.tgz and it created rpm with: drwxr-xr-x 2 smmsp root
2007-10-23 by Emmanuel Dreyfus
... It checks on each incoming message. ... I suspect that if you have a whitelist rule that lets the message pass trhough before the greylist rule is reached,
2007-10-23 by Michael Mansour
Hi, ... What Steve may really be asking, is if a tuplet has already been greylisted and the delay is in effect, can he then whitelist that tuplet (either via
2007-10-23 by Chris Hoogendyk
... They are not being held. They were temp failed. If they resend after your greylist period, they will succeed. A record of tuples that have been greylisted
2007-10-23 by Emmanuel Dreyfus
... I don t know, but you just have to wait 6 hours and the problem will go away by itself. ... I do, but I suspect ntpd crashed. I ll check when I ll be back
2007-10-23 by Oliver Fromme
... You mean a copy of the greylist? It is stored in the data- base. It s a plain ASCII file so you can look at it with more(1) or similar; the location is
2007-10-23 by Steven Eberhart
Is it possible to get a list of all e-mails that are being held pending receipt of the re-send? Is it possible to OK an e-mail that is being held? THanks,