SparkDT
Newbie | Редактировать | Профиль | Сообщение | Цитировать | Сообщить модератору
Цитата: SparkDT покажи полный кусок лога антиспама. Я не вижу хидера X-Spam-Flag: YES или NO. | Код: X-Spam-Flag: YES X-Spam-Checker-Version: SpamAssassin 3.2.4 (2008-01-01) on server X-Spam-Level: ************** X-Spam-Status: Yes, score=15.0 required=6.5 tests=AWL,EXTRA_MPART_TYPE, FH_DATE_PAST_20XX,HTML_IMAGE_ONLY_08,HTML_IMAGE_RATIO_02,HTML_MESSAGE, HTML_SHORT_LINK_IMG_1,MPART_ALT_DIFF,RCVD_IN_BL_SPAMCOP_NET,URIBL_BLACK shortcircuit=no autolearn=disabled version=3.2.4 X-Spam-Report: * 2.2 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net * [Blocked - see <http://www.spamcop.net/bl.shtml?46.28.68.144>] * 1.0 EXTRA_MPART_TYPE Header has extraneous Content-type:...type= entry * 3.4 FH_DATE_PAST_20XX The date is grossly in the future. * 0.6 HTML_IMAGE_RATIO_02 BODY: HTML has a low ratio of text to image area * 0.0 HTML_MESSAGE BODY: HTML included in message * 2.4 HTML_IMAGE_ONLY_08 BODY: HTML: images with 400-800 bytes of words * 1.1 MPART_ALT_DIFF BODY: HTML and text parts are different * 4.0 URIBL_BLACK Contains an URL listed in the URIBL blacklist * [URIs: enterings.com.ua] * 1.1 HTML_SHORT_LINK_IMG_1 HTML is very short with a linked image * -0.8 AWL AWL: From: address is in the auto white-list | Цитата: В настройках антиспама точно есть настройка, что после 6.5 очков письмо удалять, а не помечать в теме что спам? | Все верно, письмо с очками >6.5 помечаются в теме [***SPAM*** Score/Req: _SCORE(0)_/_REQD_] и продолжается его доставка. Но при условии очков >12.00 во время SMTP сканирования, они отклоняются. Вот пример куска лога из SMTP сессии, где была проверка SpamAssassin Код: Thu 2014-04-17 00:47:43: [8031:1] ---- Start SpamAssassin results ---- Thu 2014-04-17 00:47:43: [8031:1] 53.3 points, 6.5 required; Thu 2014-04-17 00:47:43: [8031:1] * 0.5 RCVD_IN_PBL RBL: Received via a relay in Spamhaus PBL Thu 2014-04-17 00:47:43: [8031:1] * [176.101.198.244 listed in zen.spamhaus.org] Thu 2014-04-17 00:47:43: [8031:1] * 2.9 RCVD_IN_XBL RBL: Received via a relay in Spamhaus XBL Thu 2014-04-17 00:47:43: [8031:1] * 0.0 MISSING_MID Missing Message-Id: header Thu 2014-04-17 00:47:43: [8031:1] * 0.0 MISSING_DATE Missing Date: header Thu 2014-04-17 00:47:43: [8031:1] * 3.3 TVD_RCVD_IP4 TVD_RCVD_IP4 Thu 2014-04-17 00:47:43: [8031:1] * 1.6 TVD_RCVD_IP TVD_RCVD_IP Thu 2014-04-17 00:47:43: [8031:1] * 2.6 RCVD_NUMERIC_HELO Received: contains an IP address used for HELO Thu 2014-04-17 00:47:43: [8031:1] * 3.2 RCVD_ILLEGAL_IP Received: contains illegal IP address Thu 2014-04-17 00:47:43: [8031:1] * 2.3 RCVD_HELO_IP_MISMATCH Received: HELO and IP do not match, but should Thu 2014-04-17 00:47:43: [8031:1] * 4.0 URIBL_BLACK Contains an URL listed in the URIBL blacklist Thu 2014-04-17 00:47:43: [8031:1] * [URIs: pfdnlwyu.in] Thu 2014-04-17 00:47:43: [8031:1] * 2.2 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net Thu 2014-04-17 00:47:43: [8031:1] * [Blocked - see <http://www.spamcop.net/bl.shtml?176.101.198.244>] Thu 2014-04-17 00:47:43: [8031:1] * 9.0 URIBL_WS_SURBL Contains an URL listed in the WS SURBL blocklist Thu 2014-04-17 00:47:43: [8031:1] * [URIs: pfdnlwyu.in] Thu 2014-04-17 00:47:43: [8031:1] * 8.0 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist Thu 2014-04-17 00:47:43: [8031:1] * [URIs: pfdnlwyu.in] Thu 2014-04-17 00:47:43: [8031:1] * 9.5 URIBL_OB_SURBL Contains an URL listed in the OB SURBL blocklist Thu 2014-04-17 00:47:43: [8031:1] * [URIs: pfdnlwyu.in] Thu 2014-04-17 00:47:43: [8031:1] * 4.0 URIBL_SBL Contains an URL listed in the SBL blocklist Thu 2014-04-17 00:47:43: [8031:1] * [URIs: pfdnlwyu.in] Thu 2014-04-17 00:47:43: [8031:1] * 0.1 RDNS_NONE Delivered to trusted network by a host with no rDNS Thu 2014-04-17 00:47:43: [8031:1] ---- End SpamAssassin results ---- Thu 2014-04-17 00:47:43: [8031:1] Spam Filter score/req: 53.30/12.0 Thu 2014-04-17 00:47:43: [8031:1] Message refused because spam score is too high Thu 2014-04-17 00:47:43: [8031:1] --> 554 Sorry, message looks like SPAM to me | Вот я и понять не могу, почему именно такой проверки не было в том письме, что именно освободило его от проверки.... Цитата: sbl-xbl.spamhaus.org sbl.spamhaus.org эти два объединяет zen.spamhaus.org, так что эти проверки совершенно лишние. list.dsbl.org перестал работать c 21 мая 2008 года, в шапке об этом написано, так что тоже убирай. The CBL is now a division of Spamhaus. The Spamhaus XBL (or SBL-XBL or Zen) is a full superset of the CBL, and you SHOULD NOT USE BOTH DNSBLs at the same time. In fact, for most administrators, we strongly recommend that you use Zen instead of the CBL directly. Так что, если юзаешь zen.spamhaus.org, то cbl.abuseat.org юзать ни к чему ! | Спасибо за совет!!! | Всего записей: 14 | Зарегистр. 25-12-2013 | Отправлено: 15:43 17-04-2014 | Исправлено: SparkDT, 16:00 17-04-2014 |
|