You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@spamassassin.apache.org by Menno van Bennekom <mv...@xs4all.nl> on 2005/05/17 11:59:26 UTC

German political spam was blocked here

FYI, so far I only found 3 of these right-wing mails in my company.
It seems almost all have been blocked by the RBL's in postfix:
- dynablock.njabl.org
- dul.dnsbl.sorbs.net
- and a lot of dsl* dial* provider-domain-names I blocked in postfix.
This helps for all kinds of spam from infected pc's so not only for this
spam-run.
They all get a reject at the MTA-level with a message like 'please send
mail through your provider', and you can include a link to a web-form to
complain about this.
So far I only had to whitelist 5 addresses because they didn't know how to
configure a smtp-server in their mail-system.
It has been said before but I still would appreciate it very much if ISP's
would only allow SMTP traffic to go through the provider's mail-servers,
not directly from dsl/cable to the Internet.
It would stop most spam/viruses from infected systems.

Just my 2 eurocents ;)
Menno van Bennekom


Re: German political spam was blocked here

Posted by mouss <us...@free.fr>.
Menno van Bennekom wrote:
> FYI, so far I only found 3 of these right-wing mails in my company.
> It seems almost all have been blocked by the RBL's in postfix:
> - dynablock.njabl.org
> - dul.dnsbl.sorbs.net
> - and a lot of dsl* dial* provider-domain-names I blocked in postfix.
> This helps for all kinds of spam from infected pc's so not only for this
> spam-run.
> They all get a reject at the MTA-level with a message like 'please send
> mail through your provider', and you can include a link to a web-form to
> complain about this.
> So far I only had to whitelist 5 addresses because they didn't know how to
> configure a smtp-server in their mail-system.
> It has been said before but I still would appreciate it very much if ISP's
> would only allow SMTP traffic to go through the provider's mail-servers,
> not directly from dsl/cable to the Internet.
> It would stop most spam/viruses from infected systems.

Recent viruses do use the ISP relay. and it is probable that most will, 
since some ISPs already block port 25. As a consequence, DUL or block-25 
will be less and less effective.

If this isn't a sufficient argument, I can volunteer free code to be 
used to send via ISP relay if that can help you change your mind.

now how many of these would you miss if you check for non resolvable HELO?



Re: German political spam was blocked here

Posted by Kenneth Porter <sh...@sewingwitch.com>.
--On Tuesday, May 17, 2005 11:59 AM +0200 Menno van Bennekom 
<mv...@xs4all.nl> wrote:

> It has been said before but I still would appreciate it very much if ISP's
> would only allow SMTP traffic to go through the provider's mail-servers,
> not directly from dsl/cable to the Internet.
> It would stop most spam/viruses from infected systems.

Even better, block but provide a web page to unblock. Anyone savvy enough 
to navigate the web page has a good chance of being competent to use 
direct-to-MX (not to be confused with "running a mail server").