Topic: Improve Spam Filtering?
I recently switched from a homebrew mail server cobbled together from various tutorials to iRedMail. Simply love how easy it was to get everything set up the way I like it.
However, one negative change is that my users are seeing a LOT more spam get through with iRedMail. One user went from receiving 1-2 messages / day to more than 100.
I have not done much of anything to mess with the spamassassin settings, other than to turn down the threshold where it will add the spam headers to his spammy mail so that I can see what scores he is getting. They are surprising. Here are a few headers from some messages he received today:
X-Spam-Flag: NO
X-Spam-Score: -6.611
X-Spam-Status: No, score=-6.611 tagged_above=-100 required=6.31 tests=[BAYES_00=-1.9, RCVD_IN_BL_SPAMCOP_NET=1.347, RCVD_IN_BRBL_LASTEXT=1.449, RDNS_NONE=0.793, SPF_PASS=-10, URIBL_DBL_SPAM=1.7] autolearn=no
X-Original-Helo: mx2.naptowncon.com (iRedMail: http://www.iredmail.org/)
X-Spam-Flag: NO
X-Spam-Score: -1.64
X-Spam-Status: No, score=-1.64 tagged_above=-100 required=6.31 tests=[BAYES_40=-0.001, RCVD_IN_BRBL_LASTEXT=1.449, RCVD_IN_PSBL=2.7, RCVD_IN_RP_RNBL=1.31, RDNS_NONE=0.793, SPF_PASS=-10, URIBL_DBL_SPAM=1.7, URIBL_JP_SURBL=0.4087] autolearn=no
X-Original-Helo: nullmx.liquidfaresucks.com (iRedMail: http://www.iredmail.org/)
X-Spam-Flag: NO
X-Spam-Score: -2.335
X-Spam-Status: No, score=-2.335 tagged_above=-100 required=6.31 tests=[BAYES_00=-1.9, RCVD_IN_BRBL_LASTEXT=1.449, RCVD_IN_CSS=1, RCVD_IN_PSBL=2.7, RDNS_NONE=0.793, SPF_PASS=-10, URIBL_DBL_SPAM=1.7, URIBL_JP_SURBL=0.4087, URIBL_RHS_DOB=1.514] autolearn=no
X-Original-Helo: webmail.uae-real-estate.net (iRedMail: http://www.iredmail.org/)
There are a few things that jump out at me:
1) All these have a spam score of < 1.
2) They all appear to be being sent from spammers who are using iredmail to configure their servers (unless I'm reading the X-Original-Helo incorrectly.
So, I have 2 questions:
a) Is there a setting somewhere that mucks around with the spam filters if the sending server is an iredmail setup?
b) How can I set up a way to train spamassassin for my endusers w/out using webmail? i.e., can I set up a special mailbox they forward their spam to in order to help train the filters? If so, how do I set that up?
Thanks in advance for any advice you can offer.
==== Provide required information ====
- iRedMail version and backend (LDAP/MySQL/PGSQL):
iRedMail 0.8.0
MySQL backend
- Linux/BSD distribution name and version:
Ubuntu Linux 12.04
- Any related log? Log is helpful for troubleshooting.
====
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.