Recently (the last few months) I've been struggling with spam that has the From-address listed as myself. Of course, the spammer is spoofing the From-address, and this causes Spamhalter's auto-whitelisting to verify that the From-address is indeed on the whitelist, and it therefore labels it as "Whitelisted" and lets the email through as non-spam. Due to normal email habits (responding, forwarding, CC to self, etc), sooner or later, your own address ends up in the whitelist, which is why the spoofed-address spam gets thru.
This presents sort of a Catch-22... you certainly don't want your own address labeled as spam on your own system, hence the whitelist entry, and hence opening the door for that sort of spam. So I checked the "Ignore automatic white-black listing" box. This makes Spamhalter simply look at the statistical content of the email and score accordingly, thus closing the door of "having self in whitelist" spam/spoofing issue. But this defeats all the other valid and robust reasons for having the automatic white-black listing, i.e. for all the OTHER addresses in the lists.
So I got to thinking about the whole problem. I realized that it makes sense that a spammer would assume that your own address would probably be on a whitelist, but they wouldn't have an inkling of an idea about anyone else. Therefore, they can't spoof just anyone's address... they have to spoof your own. The auto-whitelisting concept only breaks down (loses it's robustness) for your own address.
As far as I can tell right now, the checkbox to ignore auto-list handling is an all or nothing control, and since I have to enable the control, I then have to manually add addresses into the whitelist (I assume this is what I will have to do).
With that in mind, I think Spamhalter's automatic white-black list handling should reflect entries other than your own address. If you want your own address in one of those lists, then that entry would be done manually. In my case, since I have several different email accounts, I think Spamhalter should have an editbox to allow me to enter one or more email-addresses that are exempt from automatic white-black list handling. This would let me add each of my own addresses for my different email accounts (at least in my case).
Is there some other mechanism to achieve the same result of still using the Automatic while-black listing, but have it omit my own set of addresses? Or do I not fully understand what Spamhalter is doing with the lists?
jjones
<p>Recently (the last few months) I've been struggling with spam that has the From-address listed as myself.&nbsp; Of course, the spammer is spoofing the From-address, and this causes Spamhalter's auto-whitelisting to verify that the From-address is indeed on the whitelist, and it therefore labels it as "Whitelisted" and lets the email through as non-spam.&nbsp; Due to normal email habits (responding, forwarding, CC to self, etc), sooner or later, your own address ends up in the whitelist, which is why the spoofed-address spam gets thru.
</p><p>This presents sort of a Catch-22... you certainly don't want your own address labeled as spam on your own system, hence the whitelist entry, and hence opening the door for that sort of spam.&nbsp; So I checked the "Ignore automatic white-black listing" box.&nbsp; This makes Spamhalter simply look at the statistical content of the email and score accordingly, thus closing the door of "having self in whitelist" spam/spoofing issue.&nbsp; But this defeats all the other valid and robust reasons for having the automatic white-black listing, i.e. for all the OTHER addresses in the lists.</p><p>So I got to thinking about the whole problem.&nbsp; I realized that it makes sense that a spammer would assume that your own address would probably be on a whitelist, but they wouldn't have an inkling of an idea about anyone else.&nbsp; Therefore, they can't spoof just anyone's address... <i>they have to spoof your own</i>.&nbsp; The auto-whitelisting concept only breaks down (loses it's robustness) for <i>your own </i>address.</p><p>As far as I can tell right now, the checkbox to ignore auto-list handling is an all or nothing control, and since I have to enable the control, I then have to manually add addresses into the whitelist (I assume this is what I will have to do).
</p><p>With that in mind, I think Spamhalter's automatic white-black list handling should reflect entries <i>other than </i>your own address.&nbsp; If you <i>want </i>your own address in one of those lists, then that entry would be done manually.&nbsp; In my case, since I have several different email accounts, I think Spamhalter should have an editbox to allow me to enter one or more email-addresses that are <span style="font-style: italic;">exempt </span>from automatic white-black list handling.&nbsp; This would let me add each of my own addresses for my different email accounts (at least in my case).
</p><p>Is there some other mechanism to achieve the same result of still using the Automatic while-black listing, but have it omit my own set of addresses?&nbsp; Or do I not fully understand what Spamhalter is doing with the lists?
</p><p>jjones
</p>