Logout

Alt-N Discussion Groups > MDaemon Discussion Groups > MDaemon AntiSpam > Archive > Spam going through

 [F] Alt-N Discussion Groups  / MDaemon Discussion Groups  / MDaemon AntiSpam  / Archive  /

Spam going through

[Devecerski, Aleksandar]
Aleksandar Deve…
Newbie
Newbie
Posts: 47
Aleksandar Devecerski - 08:31am, Jul 12 2021

Occasional AntiSpam engine misses were mentioned here few months ago. This is what I've noticed.
Every once in a while message marked as a spam slips through the cracks.

MDaemon/AV/AntiSpam/Connector all current versions/fully updated.
Spam settings are:
'A message is spam if it scores greater or equal to' -) 6.0
'SMTP rejects messages with scores greater or equal to' -) 10.0
and What to do with spam is:
'... put spam in the spam trap public folder' -) ON

But just half an hour ago attached message went through despite "8.20 points, 6.00 required".
Below is its antispam log section.

It's not a big thing, but anyone have any idea why is this happening?

Regards

Mon 2021-07-12 14:52:13.402: ----------
Mon 2021-07-12 14:55:09.543: * 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was
Mon 2021-07-12 14:55:09.543: * blocked. See
Mon 2021-07-12 14:55:09.543: * http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
Mon 2021-07-12 14:55:09.543: * for more information.
Mon 2021-07-12 14:55:09.543: * [URIs: pasedo.pl]
Mon 2021-07-12 14:55:09.543: * -5.0 RCVD_IN_DNSWL_HI RBL: Sender listed at https://www.dnswl.org/,
Mon 2021-07-12 14:55:09.543: * high trust
Mon 2021-07-12 14:55:09.543: * [94.228.123.102 listed in list.dnswl.org]
Mon 2021-07-12 14:55:09.543: * 1.6 BAYES_50 BODY: Bayes spam probability is 40 to 60%
Mon 2021-07-12 14:55:09.543: * [score: 0.4389]
Mon 2021-07-12 14:55:09.543: * 2.5 MDAEMON_OP_SPAM_HIGH MDaemon: spam/phish
Mon 2021-07-12 14:55:09.543: * 2.5 MDAEMON_SPF_SOFTFAIL MDaemon: soft-failed SPF verification
Mon 2021-07-12 14:55:09.543: * 2.0 DEAR_SOMETHING BODY: Contains 'Dear (something)'
Mon 2021-07-12 14:55:09.543: * 0.0 MILLION_HUNDRED BODY: Million "One to Nine" Hundred
Mon 2021-07-12 14:55:09.543: * -0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
Mon 2021-07-12 14:55:09.543: * [94.228.123.102 listed in wl.mailspike.net]
Mon 2021-07-12 14:55:09.543: * 0.0 HTML_MESSAGE BODY: HTML included in message
Mon 2021-07-12 14:55:09.543: * 0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
Mon 2021-07-12 14:55:09.543: * 0.0 LOTS_OF_MONEY Huge... sums of money
Mon 2021-07-12 14:55:09.543: * 1.0 FROM_FMBLA_NEWDOM14 From domain was registered in last 7-14
Mon 2021-07-12 14:55:09.543: * days
Mon 2021-07-12 14:55:09.543: * 1.0 XFER_LOTSA_MONEY Transfer a lot of money
Mon 2021-07-12 14:55:09.543: * 3.0 ADVANCE_FEE_5_NEW_MONEY Advance Fee fraud and lots of money
Mon 2021-07-12 14:55:11.998: Spam Filter processing e:/mdaemon/queues/inbound/md5001000422638.msg...
Mon 2021-07-12 14:55:11.998: * Message return-path:
Mon 2021-07-12 14:55:11.998: * Message from: lanya.fatih@paseado.com
Mon 2021-07-12 14:55:11.998: * Message to: kogeneracija@wbm.rs
Mon 2021-07-12 14:55:11.998: * Message subject: HELLO kogeneracija@wbm.rs
Mon 2021-07-12 14:55:11.998: * Message ID: (20210712140558.0E821FF5F889AFC5@paseado.com)
Mon 2021-07-12 14:55:12.376: Start SpamAssassin results
Mon 2021-07-12 14:55:12.376: 8.20 points, 6.00 required
Mon 2021-07-12 14:55:12.376: * 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was
Mon 2021-07-12 14:55:12.376: * blocked. See
Mon 2021-07-12 14:55:12.376: * http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
Mon 2021-07-12 14:55:12.376: * for more information.
Mon 2021-07-12 14:55:12.376: * [URIs: pasedo.pl]
Mon 2021-07-12 14:55:12.376: * 1.0 BAYES_40 BODY: Bayes spam probability is 20 to 40%
Mon 2021-07-12 14:55:12.376: * [score: 0.3285]
Mon 2021-07-12 14:55:12.376: * -0.0 SPF_PASS SPF: sender matches SPF record
Mon 2021-07-12 14:55:12.376: * 2.0 DEAR_SOMETHING BODY: Contains 'Dear (something)'
Mon 2021-07-12 14:55:12.376: * 0.0 MILLION_HUNDRED BODY: Million "One to Nine" Hundred
Mon 2021-07-12 14:55:12.376: * 0.0 HTML_MESSAGE BODY: HTML included in message
Mon 2021-07-12 14:55:12.376: * 0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
Mon 2021-07-12 14:55:12.376: * 0.0 LOTS_OF_MONEY Huge.

Attachments:

md5001000043531.msg (3 KB)


  All MessagesOldest ItemsOlder ItemsNewer ItemsNewest Items

Arron Caruth - Jul 12, 2021 9:50 am (#1 Total: 2)  

Guest User  

Photo of Author
Posts: 1
What version of MDaemon are you using?

What does the inbound SMTP log show for the AntiSpam processing when the message is received? 
 

--
Arron Caruth
Vice President of Product Development
o: 817-601-3222    e: Arron.Caruth@mdaemon.com

MDaemon Technologies
Simple Secure Email

Visit us on www.mdaemon.com | Facebook | LinkedIn | YouTube
Sent using the MDaemon Email Server

On Mon, 12 Jul 2021 08:31:41 -0500, "lists-md-anti-spam@mdaemon.com (Aleksandar Devecerski)" <lists-md-anti-spam@mdaemon.com> wrote:
Occasional AntiSpam engine misses were mentioned here few months ago. This is what I've noticed.
Every once in a while message marked as a spam slips through the cracks.

MDaemon/AV/AntiSpam/Connector all current versions/fully updated.
Spam settings are:
'A message is spam if it scores greater or equal to' -) 6.0
'SMTP rejects messages with scores greater or equal to' -) 10.0
and What to do with spam is:
'... put spam in the spam trap public folder' -) ON

But just half an hour ago attached message went through despite "8.20 points, 6.00 required".
Below is its antispam log section.

It's not a big thing, but anyone have any idea why is this happening?

Regards

Mon 2021-07-12 14:52:13.402: ----------
Mon 2021-07-12 14:55:09.543: * 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was
Mon 2021-07-12 14:55:09.543: * blocked. See
Mon 2021-07-12 14:55:09.543: * http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
Mon 2021-07-12 14:55:09.543: * for more information.
Mon 2021-07-12 14:55:09.543: * [URIs: pasedo.pl]
Mon 2021-07-12 14:55:09.543: * -5.0 RCVD_IN_DNSWL_HI RBL: Sender listed at https://www.dnswl.org/,
Mon 2021-07-12 14:55:09.543: * high trust
Mon 2021-07-12 14:55:09.543: * [94.228.123.102 listed in list.dnswl.org]
Mon 2021-07-12 14:55:09.543: * 1.6 BAYES_50 BODY: Bayes spam probability is 40 to 60%
Mon 2021-07-12 14:55:09.543: * [score: 0.4389]
Mon 2021-07-12 14:55:09.543: * 2.5 MDAEMON_OP_SPAM_HIGH MDaemon: spam/phish
Mon 2021-07-12 14:55:09.543: * 2.5 MDAEMON_SPF_SOFTFAIL MDaemon: soft-failed SPF verification
Mon 2021-07-12 14:55:09.543: * 2.0 DEAR_SOMETHING BODY: Contains 'Dear (something)'
Mon 2021-07-12 14:55:09.543: * 0.0 MILLION_HUNDRED BODY: Million "One to Nine" Hundred
Mon 2021-07-12 14:55:09.543: * -0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
Mon 2021-07-12 14:55:09.543: * [94.228.123.102 listed in wl.mailspike.net]
Mon 2021-07-12 14:55:09.543: * 0.0 HTML_MESSAGE BODY: HTML included in message
Mon 2021-07-12 14:55:09.543: * 0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
Mon 2021-07-12 14:55:09.543: * 0.0 LOTS_OF_MONEY Huge... sums of money
Mon 2021-07-12 14:55:09.543: * 1.0 FROM_FMBLA_NEWDOM14 From domain was registered in last 7-14
Mon 2021-07-12 14:55:09.543: * days
Mon 2021-07-12 14:55:09.543: * 1.0 XFER_LOTSA_MONEY Transfer a lot of money
Mon 2021-07-12 14:55:09.543: * 3.0 ADVANCE_FEE_5_NEW_MONEY Advance Fee fraud and lots of money
Mon 2021-07-12 14:55:11.998: Spam Filter processing e:/mdaemon/queues/inbound/md5001000422638.msg...
Mon 2021-07-12 14:55:11.998: * Message return-path:
Mon 2021-07-12 14:55:11.998: * Message from: lanya.fatih@paseado.com
Mon 2021-07-12 14:55:11.998: * Message to: kogeneracija@wbm.rs
Mon 2021-07-12 14:55:11.998: * Message subject: HELLO kogeneracija@wbm.rs
Mon 2021-07-12 14:55:11.998: * Message ID: (20210712140558.0E821FF5F889AFC5@paseado.com)
Mon 2021-07-12 14:55:12.376: Start SpamAssassin results
Mon 2021-07-12 14:55:12.376: 8.20 points, 6.00 required
Mon 2021-07-12 14:55:12.376: * 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was
Mon 2021-07-12 14:55:12.376: * blocked. See
Mon 2021-07-12 14:55:12.376: * http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
Mon 2021-07-12 14:55:12.376: * for more information.
Mon 2021-07-12 14:55:12.376: * [URIs: pasedo.pl]
Mon 2021-07-12 14:55:12.376: * 1.0 BAYES_40 BODY: Bayes spam probability is 20 to 40%
Mon 2021-07-12 14:55:12.376: * [score: 0.3285]
Mon 2021-07-12 14:55:12.376: * -0.0 SPF_PASS SPF: sender matches SPF record
Mon 2021-07-12 14:55:12.376: * 2.0 DEAR_SOMETHING BODY: Contains 'Dear (something)'
Mon 2021-07-12 14:55:12.376: * 0.0 MILLION_HUNDRED BODY: Million "One to Nine" Hundred
Mon 2021-07-12 14:55:12.376: * 0.0 HTML_MESSAGE BODY: HTML included in message
Mon 2021-07-12 14:55:12.376: * 0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
Mon 2021-07-12 14:55:12.376: * 0.0 LOTS_OF_MONEY Huge.

Attachment: md5001000043531.msg



View/reply at Spam going through
--MD-ANTI-SPAM-------------------------------------------------------
This list is for questions and discussions about preventing SPAM 
using MDAEMON. To unsubscribe from this mailing list send an email to 
md-anti-spam-unsubscribe@mdaemon.com .
--POWERED BY MDAEMON!------------------------------------------------

---------------------------------------------------------------------
These forums are provided by MDaemon Technologies for user-to-user 
support and discussion.  MDaemon staff members may participate in the 
forums periodically but please recognize that this is not the official
method of receiving technical support. To receive personal technical 
support please use the form here:
http://www.mdaemon.com/Support/RequestSupport/
---------------------------------------------------------------------

--MD-ANTI-SPAM-------------------------------------------------------
This list is for questions and discussions about preventing SPAM
using MDAEMON. To unsubscribe from this mailing list send an email to
md-anti-spam-unsubscribe@mdaemon.com .
--POWERED BY MDAEMON!------------------------------------------------

---------------------------------------------------------------------
These forums are provided by MDaemon Technologies for user-to-user
support and discussion.  MDaemon staff members may participate in the
forums periodically but please recognize that this is not the official
method of receiving technical support. To receive personal technical
support please use the form here:
http://www.mdaemon.com/Support/RequestSupport/
---------------------------------------------------------------------

Aleksandar Devecerski - Jul 12, 2021 12:16 pm (#2 Total: 2)  

 

Photo of Author
Aleksandar Deve…
Newbie
Newbie
Posts: 47
MDaemon 21.0.2

SMTP-IN log excerpt attached

As a message spamscore was 8.2 and 'SMTP rejects messages with scores
greater or equal to' is set to 10.0, message should have passed SMTP
spamcheck, as it did.
But since 'A message is spam if it scores greater or equal to' is set to
6.0 and 'What to do with spam' has '... put spam in the spam trap public
folder' selected, shouldn't this message end up in the spam trap folder?

On 12.07.2021. 16:50, Arron Caruth wrote:
> What version of MDaemon are you using?
>
> What does the inbound SMTP log show for the AntiSpam processing when the
> message is received?
>
> --
> *Arron Caruth*
> Vice President of Product Development
> *o*: 817-601-3222 *e*: Arron.Caruth@mdaemon.com
>
> *M*Daemon Technologies
> Simple Secure Email
>
> Visit us on www.mdaemon.com <www.mdaemon.com> | Facebook
> <https://www.facebook.com/MDaemon.Technologies/> | LinkedIn
> <https://www.linkedin.com/company/mdaemon-technologies> | YouTube
> <https://www.youtube.com/c/MDaemonTechnologies>
> Sent using the MDaemon Email Server <http://www.mdaemon.com/>

[Last Editor: Aleksandar Devecerski, Jul 12, 2021 12:19 pm. Total Edits: 1]

Attachments:

SMTP-IN log.txt (12 KB) (98 Downloads)




  All MessagesOldest ItemsOlder ItemsNewer ItemsNewest Items



 Content:

Read New | Search

 Guest:

Email to Admin



You are visiting as a Guest user.