Community Discussions and Support
Problem with Spam Filter

I asked the open-ended question, as the OP may find their answer in the process;
e.g., a Content Control definition is disabled. Or perhaps they are employing blacklisting
another manner, such as a filtering rule, like: If ListScan "@BLACK.PML" Delete "".

He mentioned the use of Mercury. I'm sure this task would be best addressed
via SMTP transaction-level filtering.

<P>I asked the open-ended question, as the OP may find their answer in the process; e.g., a Content Control definition is disabled. Or perhaps they are employing blacklisting another manner, such as a filtering rule, like: If ListScan "@BLACK.PML" Delete "".</P> <P>He mentioned the use of Mercury. I'm sure this task would be best addressed via SMTP transaction-level filtering. </P>

I'm getting roughly 20 emails an hour from a spambot that's mimicking the output from a registration form on our web site. Since it looks official, no simple spam halter rule will work. I assumed that I could simply add the "From" address to the black list and Pegasus would take care of it. However, the e-mails seem to be making it through. (I also put the same filter on Mercury, also to no avail). I've included the message headers below. The blacklisted address is awren@alynx.in. Is there any reason that this shouldn't work? So far as I know, I don't have anything earlier that would automatically white list this.

Tom Doan

  

Received: from spooler by estima.com (Mercury/32 v3.32); 19 Nov 12 13:19:27 -0500
X-Envelope-To: sales
Return-Path: <estima@lsh1003.lsh.siteprotect.com>
Delivered-To: <sales@estima.com>
Received: from mf32.mfg.siteprotect.com ([192.168.31.235])
 by stor15.mfg.siteprotect.com (Dovecot) with LMTP id g3CzK4+EqlAObAAAOQD4lA
 for <sales@estima.com>; Mon, 19 Nov 2012 13:17:17 -0600
Received: from mx01.mfg.siteprotect.com (unknown [192.168.33.97])
 by mf32.mfg.siteprotect.com (Postfix) with ESMTP id 58ADA8000E08
 for <sales@estima.com>; Mon, 19 Nov 2012 13:17:20 -0600 (CST)
Received: from lsh1003.lsh.siteprotect.com (lsh1003.lsh.siteprotect.com [64.71.32.13])
 (using TLSv1 with cipher AES256-SHA (256/256 bits))
 (No client certificate requested)
 by mx01.mfg.siteprotect.com (Postfix) with ESMTPS id 68BF32720027
 for <sales@estima.com>; Mon, 19 Nov 2012 13:17:21 -0600 (CST)
Received: from estima by lsh1003.lsh.siteprotect.com with local (Exim 4.72)
 (envelope-from <estima@lsh1003.lsh.siteprotect.com>)
 id 1TaWqO-00028c-9c
 for sales@estima.com; Mon, 19 Nov 2012 13:17:20 -0600
Date: Mon, 19 Nov 2012 13:17:20 -0600
Message-Id: <E1TaWqO-00028c-9c@lsh1003.lsh.siteprotect.com>
To: sales@estima.com
From: awren@alynx.in
Subject: Estima Registration
X-CTCH-RefID: str=0001.0A020201.50AA85C0.0165,ss=1,re=0.000,fgs=0
X-Mail-Filter-Gateway-ID: 58ADA8000E08.A0960
Mail-Filter-Gateway: Scanned OK
X-Mail-Filter-Gateway-SpamDetectionEngine: NOT SPAM,
 MailFilterGateway Engine (score=-1, required 4, autolearn=disabled,
 CTASD_SPAM_UNKNOWN -1.00)
X-Mail-Filter-Gateway-From: estima@lsh1003.lsh.siteprotect.com
X-Mail-Filter-Gateway-To: sales@estima.com
X-Spam-Status: No
X-Antivirus: avast! (VPS 121119-0, 11/19/2012), Inbound message
X-Antivirus-Status: Clean
SPAMBOT
X-PMFLAGS: 33570816 0 1 YV57SVQV.CNM                       

&lt;P&gt;I&#039;m getting roughly 20 emails an hour from a spambot that&#039;s mimicking the output from a registration form on our web site. Since it looks official, no simple spam halter rule will work. I assumed that I could simply add the &quot;From&quot; address to the black list and&amp;nbsp;Pegasus would take care of it. However, the e-mails seem to be making it through. (I also put the same filter&amp;nbsp;on Mercury, also to no avail). I&#039;ve included the message headers below. The blacklisted address is &lt;A href=&quot;mailto:awren@alynx.in&quot;&gt;awren@alynx.in&lt;/A&gt;. Is there any reason that this shouldn&#039;t work?&amp;nbsp;So far as I know, I don&#039;t&amp;nbsp;have anything earlier that would automatically white list this.&lt;/P&gt; &lt;P&gt;Tom Doan&lt;/P&gt; &lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt; &lt;P&gt;Received: from spooler by estima.com (Mercury/32 v3.32); 19 Nov 12 13:19:27 -0500 X-Envelope-To: sales Return-Path: &amp;lt;&lt;A href=&quot;mailto:estima@lsh1003.lsh.siteprotect.com&quot;&gt;estima@lsh1003.lsh.siteprotect.com&lt;/A&gt;&amp;gt; Delivered-To: &amp;lt;&lt;A href=&quot;mailto:sales@estima.com&quot;&gt;sales@estima.com&lt;/A&gt;&amp;gt; Received: from mf32.mfg.siteprotect.com ([192.168.31.235]) &amp;nbsp;by stor15.mfg.siteprotect.com (Dovecot) with LMTP id g3CzK4+EqlAObAAAOQD4lA &amp;nbsp;for &amp;lt;&lt;A href=&quot;mailto:sales@estima.com&quot;&gt;sales@estima.com&lt;/A&gt;&amp;gt;; Mon, 19 Nov 2012 13:17:17 -0600 Received: from mx01.mfg.siteprotect.com (unknown [192.168.33.97]) &amp;nbsp;by mf32.mfg.siteprotect.com (Postfix) with ESMTP id 58ADA8000E08 &amp;nbsp;for &amp;lt;&lt;A href=&quot;mailto:sales@estima.com&quot;&gt;sales@estima.com&lt;/A&gt;&amp;gt;; Mon, 19 Nov 2012 13:17:20 -0600 (CST) Received: from lsh1003.lsh.siteprotect.com (lsh1003.lsh.siteprotect.com [64.71.32.13]) &amp;nbsp;(using TLSv1 with cipher AES256-SHA (256/256 bits)) &amp;nbsp;(No client certificate requested) &amp;nbsp;by mx01.mfg.siteprotect.com (Postfix) with ESMTPS id 68BF32720027 &amp;nbsp;for &amp;lt;&lt;A href=&quot;mailto:sales@estima.com&quot;&gt;sales@estima.com&lt;/A&gt;&amp;gt;; Mon, 19 Nov 2012 13:17:21 -0600 (CST) Received: from estima by lsh1003.lsh.siteprotect.com with local (Exim 4.72) &amp;nbsp;(envelope-from &amp;lt;&lt;A href=&quot;mailto:estima@lsh1003.lsh.siteprotect.com&quot;&gt;estima@lsh1003.lsh.siteprotect.com&lt;/A&gt;&amp;gt;) &amp;nbsp;id 1TaWqO-00028c-9c &amp;nbsp;for &lt;A href=&quot;mailto:sales@estima.com&quot;&gt;sales@estima.com&lt;/A&gt;; Mon, 19 Nov 2012 13:17:20 -0600 Date: Mon, 19 Nov 2012 13:17:20 -0600 Message-Id: &amp;lt;&lt;A href=&quot;mailto:E1TaWqO-00028c-9c@lsh1003.lsh.siteprotect.com&quot;&gt;E1TaWqO-00028c-9c@lsh1003.lsh.siteprotect.com&lt;/A&gt;&amp;gt; To: &lt;A href=&quot;mailto:sales@estima.com&quot;&gt;sales@estima.com&lt;/A&gt; From: &lt;A href=&quot;mailto:awren@alynx.in&quot;&gt;awren@alynx.in&lt;/A&gt; Subject: Estima Registration X-CTCH-RefID: str=0001.0A020201.50AA85C0.0165,ss=1,re=0.000,fgs=0 X-Mail-Filter-Gateway-ID: 58ADA8000E08.A0960 Mail-Filter-Gateway: Scanned OK X-Mail-Filter-Gateway-SpamDetectionEngine: NOT SPAM, &amp;nbsp;MailFilterGateway Engine (score=-1, required 4, autolearn=disabled, &amp;nbsp;CTASD_SPAM_UNKNOWN -1.00) X-Mail-Filter-Gateway-From: &lt;A href=&quot;mailto:estima@lsh1003.lsh.siteprotect.com&quot;&gt;estima@lsh1003.lsh.siteprotect.com&lt;/A&gt; X-Mail-Filter-Gateway-To: &lt;A href=&quot;mailto:sales@estima.com&quot;&gt;sales@estima.com&lt;/A&gt; X-Spam-Status: No X-Antivirus: avast! (VPS 121119-0, 11/19/2012), Inbound message X-Antivirus-Status: Clean SPAMBOT X-PMFLAGS: 33570816 0 1 YV57SVQV.CNM&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;

a simple Newmail filter on the From: should catch this without problem and with an action set, delete it

Martin 

&lt;p&gt;a simple Newmail filter on the From: should catch this without problem and with an action set, delete it&lt;/p&gt;&lt;p&gt;Martin&amp;nbsp;&lt;/p&gt;

That worked. Thanks. Any reason why the blacklist route might not work?

That worked. Thanks. Any reason why the blacklist route might not work?

[quote user="Tom Doan"]Any reason why the blacklist route might not work?[/quote]
How are you attempting to employ the blacklist?

[quote user=&quot;Tom Doan&quot;]Any reason why the blacklist route might not work?[/quote] How are you attempting to employ the blacklist?

The Blacklist facility comes with Content Control. See menu Tools/Spam and Content Control. Select Content Control , then select the Basic Spam Detection, click Edit, and click the Exceptions tab and you will see a Blacklist.pml  (don't forget to Save any changes you make

 Martin 

&lt;p&gt;The Blacklist facility comes with Content Control. See menu Tools/Spam and Content Control. Select Content Control , then select the Basic Spam Detection, click Edit, and click the Exceptions tab and you will see a Blacklist.pml &amp;nbsp;(don&#039;t forget to Save any changes you make&lt;/p&gt;&lt;p&gt;&amp;nbsp;Martin&amp;nbsp;&lt;/p&gt;
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft