Topic: Fail2Ban and a honeypot email address
==== Required information ====
- iRedMail version: 0.8.7
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL
- Linux/BSD distribution name and version: CentOS 6.5
- Related log if you're reporting an issue:
====
Has anyone tried doing this, and if so how did you accomplish it?
I'm still working on getting all my antispam settings straight after moving to a new server last week, and I realized something, looking at the logs and the quarantine: there is a large (by my standards) amount of spam addressed to almost every account on the server. I'm filtering it and quarantining it (because it's not scoring high enough consistently to increase a SpamAssassin score to truly block it) but I had an idea.
Is it possible to write a Fail2Ban rule to automatically block an IP that sends to a specific email address? My thinking is to use a couple of these addresses just to collect spam (nothing legitimate seems to come to them) and then block the IP of any server sending to those addresses. If it works right, it should cut the spammer off after only a few messages.
Or, maybe this can be done in Postfix? I searched both this forum and Google, etc and couldn't find a definitive way to accomplish it either way.
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.