Looking at the logs from SpamHalter
I see:
D 20080121 235353.421 MG000C66 Mercury version >= 4.1
D 20080121 235353.421 MG000C66 jobfile: C:\MERCURY\QUEUE\MG000C66.QDF
D 20080121 235353.421 MG000C66 spamdir: C:\MERCURY\MAIL\spam
D 20080121 235353.421 MG000C66 nospamdir: C:\MERCURY\MAIL\nospam
D 20080121 235353.421 MG000C66 IP: 10.0.0.254
D 20080121 235353.421 MG000C66 > Match ACL
20080121 235353.421 MG000C66 from: <annettendkj@recherchesretrouvailles.com>
D 20080121 235353.421 MG000C66 > Local sender
D 20080121 235353.421 MG000C66 > for Whitelist
_ 20080121 235353.437 MG000C66 Correction request saved as: C:\MERCURY\MAIL\spam\ACU36YDP.CNM
Couple of things:
1. Has this been reported as Spam ? How do I tell ?
2. annettendkj@recherchesretrouvailles.com is not local, so why does it show as she is ?
I run SquirrelMail with Spam Buttons plugin, this allows a simple click to report the email as Spam or Not Spam.
One of the options is :
// When reporting via email, should the message be resent (leaving
// all message headers intact), or should it be sent as an attachment?
//
// resend = 'bounce'
// attach = 'attachment'
//
// $spam_report_email_method = 'bounce';
//
$spam_report_email_method = 'bounce';
If I set it to attachment the from in SpamHalters logs shows as me, but I get issues.
If I have it sent as bounce it shows as the remote end, but is it working ??
Thanks
Is 10.0.0.254 your webserver running squirrelmail?
This would be on Spamhalters 'local' ACL so is classified as a local send, and the RCPT TO: address (presumably spam@yourdomain) gets whitelisted.
This should not be a problem.
Don't know about Squirrelmail, sorry.
> Looking at the logs from SpamHalter
>
> I see:
>
> D 20080121 235353.421 MG000C66 Mercury version >= 4.1
> D 20080121 235353.421 MG000C66 jobfile: C:\MERCURY\QUEUE\MG000C66.QDF
> D 20080121 235353.421 MG000C66 spamdir: C:\MERCURY\MAIL\spam
> D 20080121 235353.421 MG000C66 nospamdir: C:\MERCURY\MAIL\nospam
> D 20080121 235353.421 MG000C66 IP: 10.0.0.254
> D 20080121 235353.421 MG000C66 > Match ACL
> 20080121 235353.421 MG000C66 from: <annettendkj@recherchesretrouvailles.com>
> D 20080121 235353.421 MG000C66 > Local sender
> D 20080121 235353.421 MG000C66 > for Whitelist
> _ 20080121 235353.437 MG000C66 Correction request saved as: C:\MERCURY\MAIL\spam\ACU36YDP.CNM
This means that the system has received the correction message from a local sender and it's being saved in the SPAM user directory as a new mail message.
>
>
>
> Couple of things:
>
> 1. Has this been reported as Spam ? How do I tell ?
It's been put in the spam directory for later processing, check out the log for this CNM file being processed. Here's the sample of the log showing a correction.
20080105 120434.323 MG000007 from: hoerner@ploughlane.co.uk
20080105 120434.323 MG000007 to: thomas@thomas
C 20080105 120434.354 MG000007 corrections to SPAM
C 20080105 120434.370 MG000007 FDGJQEM9.CNM
C 20080105 120434.386 MG000007 from: cmercadoei@skycn.com
C 20080105 120434.386 MG000007 Rounds: 1
20080105 120435.042 MG000007 Tokens: 60
S 20080105 120435.104 MG000007 SPAM! 1.0000
_ 20080105 120435.432 MG000007 Done. (1563)
> 2. annettendkj@recherchesretrouvailles.com is not local, so why does it show as she is ?
Did not say she say she was. It's coming from a local IP address.
>
> I run SquirrelMail with Spam Buttons plugin, this allows a simple click to report the email as Spam or Not Spam.
>
> One of the options is :
>
> // When reporting via email, should the message be resent (leaving
> // all message headers intact), or should it be sent as an attachment?
> //
> // resend = 'bounce'
> // attach = 'attachment'
> //
> // $spam_report_email_method = 'bounce';
> //
> $spam_report_email_method = 'bounce';
>
> If I set it to attachment the from in SpamHalters logs shows as me, but I get issues.
>
> If I have it sent as bounce it shows as the remote end, but is it working ??
You should bounce it to the spam user. If SquirrelMail and Mercury/32 are on the same system it will be coming in via the local IP address as a local sender.
>
> Thanks
>
>
>
>
Thanks All.
Thomas - Where do I find the logs for the CNM file ?? - PLEASE Ignore this bit found it !!
Just sent a test email:
D 20080122 105646.109 MG000D86 Mercury version >= 4.1
D 20080122 105646.109 MG000D86 jobfile: C:\MERCURY\QUEUE\MG000D86.QDF
D 20080122 105646.109 MG000D86 spamdir: C:\MERCURY\MAIL\spam
D 20080122 105646.109 MG000D86 nospamdir: C:\MERCURY\MAIL\nospam
D 20080122 105646.109 MG000D86 IP: 10.0.0.254
D 20080122 105646.109 MG000D86 > Match ACL
20080122 105646.109 MG000D86 from: <sharoncao@todaynic.com>
D 20080122 105646.109 MG000D86 > Local sender
D 20080122 105646.109 MG000D86 > for Whitelist
_ 20080122 105646.125 MG000D86 Correction request saved as: C:\MERCURY\MAIL\spam\ABCU6AA9.CNM
C 20080122 105942.156 MG000D87 corrections to SPAM
C 20080122 105942.156 MG000D87 ABCU6AA9.CNM
A 20080122 105942.250 MG000D87 BL+: sharoncao@todaynic.com
C 20080122 105942.312 MG000D87 from: sharoncao@todaynic.com
C 20080122 105942.328 MG000D87 Not needed!
D 20080122 105942.546 MG000D87 before parse
D 20080122 105942.546 MG000D87 before lookup
20080122 105942.578 MG000D87 Tokens: 262
W 20080122 105942.578 MG000D87 is on WH...
N 20080122 105942.578 MG000D87 noSPAM 0.0000
_ 20080122 105942.859 MG000D87 Done. (708)
This seems to show it as NOT SPAM, yet the original header shows:
X-SPAMWALL: Passed through antiSPAM test by SpamHalter 4.3.1 on domain.co.uk (336)
X-SPAMWALL: probability - 100.0%
X-SPAMWALL: SPAM detected!
Can you explain ??
[quote user="tomt"]
Thanks All.
Thomas - Where do I find the logs for the CNM file ?? - PLEASE Ignore this bit found it !!
Just sent a test email:
D 20080122 105646.109 MG000D86 Mercury version >= 4.1
D 20080122 105646.109 MG000D86 jobfile: C:\MERCURY\QUEUE\MG000D86.QDF
D 20080122 105646.109 MG000D86 spamdir: C:\MERCURY\MAIL\spam
D 20080122 105646.109 MG000D86 nospamdir: C:\MERCURY\MAIL\nospam
D 20080122 105646.109 MG000D86 IP: 10.0.0.254
D 20080122 105646.109 MG000D86 > Match ACL
20080122 105646.109 MG000D86 from: <sharoncao@todaynic.com>
D 20080122 105646.109 MG000D86 > Local sender
D 20080122 105646.109 MG000D86 > for Whitelist
_ 20080122 105646.125 MG000D86 Correction request saved as: C:\MERCURY\MAIL\spam\ABCU6AA9.CNM
C 20080122 105942.156 MG000D87 corrections to SPAM
C 20080122 105942.156 MG000D87 ABCU6AA9.CNM
A 20080122 105942.250 MG000D87 BL+: sharoncao@todaynic.com
C 20080122 105942.312 MG000D87 from: sharoncao@todaynic.com
C 20080122 105942.328 MG000D87 Not needed!
D 20080122 105942.546 MG000D87 before parse
D 20080122 105942.546 MG000D87 before lookup
20080122 105942.578 MG000D87 Tokens: 262
W 20080122 105942.578 MG000D87 is on WH...
N 20080122 105942.578 MG000D87 noSPAM 0.0000
_ 20080122 105942.859 MG000D87 Done. (708)
This seems to show it as NOT SPAM, yet the original header shows:
X-SPAMWALL: Passed through antiSPAM test by SpamHalter 4.3.1 on domain.co.uk (336)
X-SPAMWALL: probability - 100.0%
X-SPAMWALL: SPAM detected!
Can you explain ??
[/quote]
The only thing I can see that is causing this is that the message is whitelisted. Can you verify that sharoncao@todaynic.com or todaynic.com is not whitelisted?
[quote]The only thing I can see that is causing this is that the message is whitelisted. Can you verify that sharoncao@todaynic.com or todaynic.com is not whitelisted?[/quote]
Definitely not whitelisted..
[*-)]
[quote user="tomt"]
[quote]The only thing I can see that is causing this is that the message is whitelisted. Can you verify that sharoncao@todaynic.com or todaynic.com is not whitelisted?[/quote]
Definitely not whitelisted..
[*-)]
[/quote]
Ok, is this being forwarded by a whitelisted email address. Check the headers in the message as received.
As far as I can tell only this bit relates to the correction:
C 20080122 105942.156 MG000D87 corrections to SPAM
C 20080122 105942.156 MG000D87 ABCU6AA9.CNM
A 20080122 105942.250 MG000D87 BL+: sharoncao@todaynic.com
C 20080122 105942.312 MG000D87 from: sharoncao@todaynic.com
C 20080122 105942.328 MG000D87 Not needed!
The lines before & after relate to the processing of the (unrelated) message that triggered the correction process.
In my log I have NOSPAM corrections sandwiched between the SPAM classification of a trigger message (which was indeed SPAM).
20080108 | 093403.000 | MG0001E4 | from:
<chortles34@sandymatthewscpa.com> |
|
20080108 | 093403.000 | MG0001E4 | to: user@maxwood.co.nz | |
C | 20080108 | 093403.110 | MG0001E4 | corrections to NoSPAM |
C | 20080108 | 093403.110 | MG0001E4 | 23AE7FC7.CNM |
A | 20080108 | 093403.500 | MG0001E4 | WH+: hongyu.wanghy@spammy.looking.good.mail.com |
C | 20080108 | 093403.550 | MG0001E4 | from: hongyu.wanghy@spammy.looking.good.mail.com |
C | 20080108 | 093414.150 | MG0001E4 | Rounds: 21 |
20080108 | 093414.540 | MG0001E4 | Tokens: 10 | |
S | 20080108 | 093414.650 | MG0001E4 | SPAM! 1.0000 |
_ | 20080108 | 093414.650 | MG0001E4 | Done. (11647) |
Your previous draft for topic is pending
If you continue, your previous draft will be discarded.