Community Discussions and Support
Transaction Filtering - Help Please

You can't with an SMTP transaction filter as it is the From: address in the message body.

The SMTP MAIL FROM that you are checking with your rule is <dobakyluo5078@telekom.hu> as reported in the Return-path: header

From transflt.mer:

[quote]# "operation" can be:
#
#    'H' for an expression applied to the client's "HELO" greeting
#    'D' for deferred HELO processing; these filters will only be
#        applied if the client does not issue a successful AUTH after
#        issuing HELO but before issuing any other command. Otherwise,
#        these filters are the same as 'H' filters. They allow a user
#        on a system that might otherwise be rejected to redeem the
#        connection by authenticating his identity.
#    'S' for an expression applied to the subject line of the message
#    'R' for an expression applied to each SMTP RCPT command
#    'M' for an expression applied to the SMTP MAIL FROM: command[/quote]

You can use a general filter rule during Core Processing to match the From: address in the body and delete it.

&lt;p&gt;You can&#039;t with an SMTP transaction filter as it is the From: address in the message body.&lt;/p&gt;&lt;p&gt; The SMTP MAIL FROM that you are checking with your rule is &amp;lt;&lt;a href=&quot;http://webmail.adslweb.co.uk/src/compose.php?send_to=dobakyluo5078%40telekom.hu&quot;&gt;dobakyluo5078@telekom.hu&lt;/a&gt;&amp;gt; as reported in the &lt;b&gt;Return-path:&lt;/b&gt; header&lt;/p&gt;&lt;p&gt;From transflt.mer:&lt;/p&gt;&lt;p&gt;[quote]# &quot;operation&quot; can be: # #&amp;nbsp;&amp;nbsp;&amp;nbsp; &#039;H&#039; for an expression applied to the client&#039;s &quot;HELO&quot; greeting #&amp;nbsp;&amp;nbsp;&amp;nbsp; &#039;D&#039; for deferred HELO processing; these filters will only be #&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; applied if the client does not issue a successful AUTH after #&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; issuing HELO but before issuing any other command. Otherwise, #&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; these filters are the same as &#039;H&#039; filters. They allow a user #&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on a system that might otherwise be rejected to redeem the #&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; connection by authenticating his identity. #&amp;nbsp;&amp;nbsp;&amp;nbsp; &#039;S&#039; for an expression applied to the subject line of the message #&amp;nbsp;&amp;nbsp;&amp;nbsp; &#039;R&#039; for an expression applied to each SMTP RCPT command #&amp;nbsp;&amp;nbsp;&amp;nbsp; &#039;M&#039; for an expression applied to the SMTP MAIL FROM: command[/quote]&lt;/p&gt;&lt;p&gt;You can use a general filter rule during Core Processing to match the From: address in the body and delete it. &lt;/p&gt;

Hi

I've created these 2 filters:

M, "*viagra*", RS, "'Viagra' encountered - connection dropped."
S, "*viagra*", RS, "'Viagra' encountered - connection dropped."

Yet I still get mail like this:

<nobr><tt><b>X-SPAMWALL:</b> Passed through antiSPAM test by Spamhalter 4.5.0.408 on TEST (390)<br></tt></nobr><nobr><tt><b>X-SPAMWALL:</b> probability - 100.0%<br></tt></nobr><nobr><tt><b>X-SPAMWALL:</b> SPAM detected!<br></tt></nobr><nobr><tt><b>X-CLAMWALL:</b> Passed through antiviral test by ClamWall 1.4.0.96 on TEST (87)<br></tt></nobr><nobr><tt><b>Return-path:</b> &lt;<a href="http://webmail.adslweb.co.uk/src/compose.php?send_to=dobakyluo5078%40telekom.hu">dobakyluo5078@telekom.hu</a>&gt;<br></tt></nobr><nobr><tt><b>Received:</b> from telekom.hu (188.36.35.54) by TEST (Mercury/32 v4.72)<br>     with ESMTP ID MG000A84; 26 Jan 2010 19:03:36 -0000<br></tt></nobr><nobr><tt><b>From:</b> "VIAGRA(c) Brand Store" &lt;<a href="http://webmail.adslweb.co.uk/src/compose.php?send_to=dobakyluo5078%40telekom.hu">dobakyluo5078@telekom.hu</a>&gt;<br></tt></nobr><nobr><tt><strong>To:</strong> <a href="mailto:User@TEST">User@TEST</a><br></tt></nobr><nobr><tt><b>Subject:</b> [** SPAM **] User site save 80% now<br></tt></nobr><nobr><tt><b>MIME-Version:</b> 1.0<br></tt></nobr><nobr><tt><b>Content-Type:</b> text/html; charset="ISO-8859-1"<br></tt></nobr><nobr><tt><b>Content-Transfer-Encoding:</b> 7bit<br></tt></nobr><nobr><tt><b>X-Blocked:</b> SORBS C 10-12 see http://www.dnsbl.us.sorbs.net/<br></tt></nobr><nobr><tt><b>X-CC-Diagnostic:</b> Not Header "Date" Exists (50)<br></tt></nobr><nobr><tt><b>X-PMFLAGS:</b> 34079360 0 5 06PCFTKB.CNM</tt></nobr>

Why doesn't the filter reject this type of email ??

&lt;P&gt;Hi&lt;/P&gt; &lt;P&gt;I&#039;ve created these 2 filters:&lt;/P&gt; &lt;P&gt;M, &quot;*viagra*&quot;, RS, &quot;&#039;Viagra&#039; encountered - connection dropped.&quot; S, &quot;*viagra*&quot;, RS, &quot;&#039;Viagra&#039; encountered - connection dropped.&quot;&lt;/P&gt; &lt;P&gt;Yet I still get mail like this:&lt;/P&gt; &lt;P&gt; &lt;TABLE class=&quot;&quot; cellSpacing=0 cellPadding=2 width=&quot;99%&quot; align=center border=0&gt; &lt;TBODY&gt; &lt;TR&gt; &lt;TD class=&quot;&quot;&gt;&lt;NOBR&gt;&lt;TT&gt;&lt;B&gt;X-SPAMWALL:&lt;/B&gt; Passed through antiSPAM test by Spamhalter 4.5.0.408 on&amp;nbsp;TEST (390) &lt;/TT&gt;&lt;/NOBR&gt;&lt;NOBR&gt;&lt;TT&gt;&lt;B&gt;X-SPAMWALL:&lt;/B&gt; probability - 100.0% &lt;/TT&gt;&lt;/NOBR&gt;&lt;NOBR&gt;&lt;TT&gt;&lt;B&gt;X-SPAMWALL:&lt;/B&gt; SPAM detected! &lt;/TT&gt;&lt;/NOBR&gt;&lt;NOBR&gt;&lt;TT&gt;&lt;B&gt;X-CLAMWALL:&lt;/B&gt; Passed through antiviral test by ClamWall 1.4.0.96 on&amp;nbsp;TEST (87) &lt;/TT&gt;&lt;/NOBR&gt;&lt;NOBR&gt;&lt;TT&gt;&lt;B&gt;Return-path:&lt;/B&gt; &amp;lt;&lt;A href=&quot;http://webmail.adslweb.co.uk/src/compose.php?send_to=dobakyluo5078%40telekom.hu&quot;&gt;dobakyluo5078@telekom.hu&lt;/A&gt;&amp;gt; &lt;/TT&gt;&lt;/NOBR&gt;&lt;NOBR&gt;&lt;TT&gt;&lt;B&gt;Received:&lt;/B&gt; from telekom.hu (188.36.35.54) by&amp;nbsp;TEST (Mercury/32 v4.72) &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; with ESMTP ID MG000A84; 26 Jan 2010 19:03:36 -0000 &lt;/TT&gt;&lt;/NOBR&gt;&lt;NOBR&gt;&lt;TT&gt;&lt;B&gt;From:&lt;/B&gt; &quot;VIAGRA(c) Brand Store&quot; &amp;lt;&lt;A href=&quot;http://webmail.adslweb.co.uk/src/compose.php?send_to=dobakyluo5078%40telekom.hu&quot;&gt;dobakyluo5078@telekom.hu&lt;/A&gt;&amp;gt; &lt;/TT&gt;&lt;/NOBR&gt;&lt;NOBR&gt;&lt;TT&gt;&lt;STRONG&gt;To:&lt;/STRONG&gt; &lt;A href=&quot;mailto:User@TEST&quot;&gt;User@TEST&lt;/A&gt; &lt;/TT&gt;&lt;/NOBR&gt;&lt;NOBR&gt;&lt;TT&gt;&lt;B&gt;Subject:&lt;/B&gt; [** SPAM **] User site save 80% now &lt;/TT&gt;&lt;/NOBR&gt;&lt;NOBR&gt;&lt;TT&gt;&lt;B&gt;MIME-Version:&lt;/B&gt; 1.0 &lt;/TT&gt;&lt;/NOBR&gt;&lt;NOBR&gt;&lt;TT&gt;&lt;B&gt;Content-Type:&lt;/B&gt; text/html; charset=&quot;ISO-8859-1&quot; &lt;/TT&gt;&lt;/NOBR&gt;&lt;NOBR&gt;&lt;TT&gt;&lt;B&gt;Content-Transfer-Encoding:&lt;/B&gt; 7bit &lt;/TT&gt;&lt;/NOBR&gt;&lt;NOBR&gt;&lt;TT&gt;&lt;B&gt;X-Blocked:&lt;/B&gt; SORBS C 10-12 see http://www.dnsbl.us.sorbs.net/ &lt;/TT&gt;&lt;/NOBR&gt;&lt;NOBR&gt;&lt;TT&gt;&lt;B&gt;X-CC-Diagnostic:&lt;/B&gt; Not Header &quot;Date&quot; Exists (50) &lt;/TT&gt;&lt;/NOBR&gt;&lt;NOBR&gt;&lt;TT&gt;&lt;B&gt;X-PMFLAGS:&lt;/B&gt; 34079360 0 5 06PCFTKB.CNM&lt;/TT&gt;&lt;/NOBR&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt; &lt;P&gt;Why doesn&#039;t the filter reject this type of email ??&lt;/P&gt;

Your transfilter is looking at the SMTP mail from: & subject, neither of which contain the word viagra. Well, you can't tell from those headers, but the ones I get don't.

Your transfilter is looking at the SMTP mail from: &amp;amp; subject, neither of which contain the word viagra. Well, you can&#039;t tell from those headers, but the ones I get don&#039;t.

What about:
From: "VIAGRA(c) Brand Store" <dobakyluo5078@telekom.hu>

How do I match against that ?

&lt;p&gt;What about: &lt;b&gt;From:&lt;/b&gt; &quot;VIAGRA(c) Brand Store&quot; &amp;lt;&lt;a href=&quot;http://webmail.adslweb.co.uk/src/compose.php?send_to=dobakyluo5078%40telekom.hu&quot;&gt;dobakyluo5078@telekom.hu&lt;/a&gt;&amp;gt; &lt;/p&gt;&lt;p&gt;How do I match against that ? &lt;/p&gt;
live preview
enter atleast 10 characters
WARNING: You mentioned %MENTIONS%, but they cannot see this message and will not be notified
Saving...
Saved
With selected deselect posts show selected posts
All posts under this topic will be deleted ?
Pending draft ... Click to resume editing
Discard draft