[Raw Msg Headers][Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: fighting junk mail in zmailer
> Jon Lewis <jlewis@inorganic5.fdt.net>
> > I don't know if procmail and zmailer can be made to get along...but using
> > /etc/procmailrc, you can filter incoming email based on any extended
> > regular expressions in the header or body.
>
> They can be made to get along, but the idea was to block while the
> message is still in the spammer's queue:
>
> HELO spam.ppgsoft.com
> 220 Hello spam.ppgsoft.com, am I glad to see you!
> MAIL FROM: <info@ppgsoft.com>
> (total silence for four hours)
>
> Unfortunately, it appears that someone's beaten me to it. Sendmail's
> read timeout, which I remember as several hours, is now just a few
> minutes.
>
> So much for that idea.
Yes, RFC 1123 (host requirements) saus that SMTP read
timeout on commands (excluding ".") is 5 minutes. At
the dot it is 10 minutes.
The only real way to do that is to build a front-end
giving instant responses of style:
MAIL FROM:<foo@offending.domain>
552 Policy decission of rejecting email input from this domain
and/or with following followup states:
RCPT TO:<...>
552 The message origin is unacceptable, no recipient is accepted
...and so on including the data, and its terminating dot.
THAT blocks, not any long timeout.
The long timeouts just feed it to your backup MX, from which it comes
back to you..
I have been asked to consider something similar to provide a full
set of blocking capabilities at the ISP MTAs so that a message that
is going thru the MTA must be coming from ISP's customer, or be
going to one. (Ok, the "ISP" is Telecom Finland, where I work at.)
Things that cause bad feelings at some of the Telecom Finland
branches are systems using their routing MTAs to relay email that
is coming from/ is going to somebody that does not pay to Telecom
Finland for the service. If either (or both) the sender or the
recipient were Telecom's customers, nobody would complain.
Anybody can put anybody as their MX-system...
The machine allocated to be our new SMTP hub has arrived, but
I am being pulled to too many crash-priority projects to get it
worked out yet.
Things have been rather busy at my job, and I have not had time
to work on the ZMailer of lately, nor do I have UNIX at home right
now. (Moving 200 km from old home does madate moving some computers,
but that 100 MHz AMD K5 machine runs MickeySoft stuff.. I gotta go
and buy another disk for it -- for UNIX..)
> --Arnt
/Matti Aarnio <mea@nic.funet.fi> <matti.aarnio@tele.fi>