Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 697732 - Check anti-spam service
Summary: Check anti-spam service
Status: CONFIRMED
Alias: None
Product: Gentoo Infrastructure
Classification: Unclassified
Component: Other (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo Infrastructure
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2019-10-14 21:05 UTC by Thomas Deutschmann (RETIRED)
Modified: 2019-10-15 14:15 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Deutschmann (RETIRED) gentoo-dev 2019-10-14 21:05:09 UTC
During last 2 weeks I see an increased amount of SPAM coming through my @gentoo.org address. However, when you check sender, you will notice that IP is listed in various RBLs which makes me wonder if Gentoo's anti-spam service is still working: I.e. I don't see RCVD_IN_* header entries but when manually checking IP, sender is listed.

This makes me wonder if anto-spam service is still running and properly working.

See logs for

> Message-ID: <Y0.046zoQuS.y6cgNH6Ns7PWNk0Z899999067046zoQuS.y6cgNH6Ns7PWNk0Z@correct.lacareconnect.com>

or

> Message-ID: <DdHckoGx3DYDgmQ5a5tExzX6jT2.[rl8rl19}@boone.twitchprimefortnite.com>

or

> Message-ID: <eQNas.UQaxEHZ8DvgAhNvMlKUcDpCSsqgdc4F47KWZ.eQNas.PYfJlQsjAoSuXwLxHId9@coat.omgovice.com>
Comment 1 Brian Evans (RETIRED) gentoo-dev 2019-10-15 13:50:20 UTC
Should we turn on postscreen for pregreet and/or sane RBL blocking?
Comment 2 Thomas Deutschmann (RETIRED) gentoo-dev 2019-10-15 14:15:13 UTC
When you ask me, all of them. But I know that especially US people fear to lose mails and have a problem even with before-queue mode filtering (that way, mail wouldn't get accepted and sending server is responsible to tell sender that mail couldn't get delivered which allows sender to contact recipient through another channel).

But this bug is not about asking for *new* methods. It's about asking if already configured anti-spam checks are still working. I.e. we have RBLs checks configured in Amavis/SA. There should be a check against Spamhaus ZEN for example. But as shown, for yet unknown reason, senders listed in ZEN RBL are not getting tagged anymore.

So I don't know what happend. Did you upgrade perl recently which maybe killed SA?
Have you changed DNS resolver to use public DNS like 8.8.8.8 which is blocked by Spamhaus, i.e. when you use Google DNS to query Spamhaus RBL you will always get "Not listed" (see https://www.spamhaus.org/faq/section/DNSBL%20Usage#261)...?