Hi Zhang,
Thanks for the reply. I will check/consider the suggested two options.
Just got the same kind of an email while ago but it straight came to ,y INBOX. See the header and the log (/var/log/mail.log). I also tried to check with header/body rule to stop these but it seems syntax is not correct.
The question is that it sometimes goes to Junk folder but sometimes misses it and comes to INBOX.
Do you think one of the two options you suggested help with this?
Return-Path: <neder@riopreto.net>
Delivered-To: user1@mydomain.com
Received: from mail.mydomain.com (localhost [127.0.0.1])
by mail.mydomain.com (Postfix) with ESMTP id 44cCXV4JwdzSjyw
for <user1@mydomain.com>; Sun, 7 Apr 2019 09:27:54 +1000 (AEST)
X-Virus-Scanned: Debian amavisd-new at mail.mydomain.com
X-Spam-Flag: NO
X-Spam-Score: 5.298
X-Spam-Level: *****
X-Spam-Status: No, score=5.298 tagged_above=2 required=6.2
tests=[ALL_TRUSTED=-1, HEADER_FROM_DIFFERENT_DOMAINS=0.001,
HTML_IMAGE_ONLY_04=0.342, HTML_MESSAGE=0.001,
LIST_PARTIAL_SHORT_MSG=2.499, LOCALPART_IN_SUBJECT=0.73,
MIME_HTML_MOSTLY=0.001, MPART_ALT_DIFF=0.724,
TO_NO_BRKTS_HTML_IMG=1.999, TVD_SPACE_RATIO=0.001]
autolearn=no autolearn_force=no
Received: from mail.mydomain.com ([127.0.0.1])
by mail.mydomain.com (mail.mydomain.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id EExNB1dZyP1b for <user1@mydomain.com>;
Sun, 7 Apr 2019 09:27:53 +1000 (AEST)
Received: from canela.sacola.com.br (_gateway [192.168.1.8])
by mail.mydomain.com (Postfix) with ESMTPS id 44cCXR0KzvzSjyV
for <user1@mydomain.com>; Sun, 7 Apr 2019 09:27:50 +1000 (AEST)
Received: from 177-73-8-22.hipernet.inf.br ([177.73.8.22]:57677 helo=[177-73-8-22.hipernet.inf.br])
by canela.sacola.com.br with esmtpsa (TLSv1:ECDHE-RSA-AES256-SHA:256)
(Exim 4.91)
(envelope-from <neder@riopreto.net>)
id 1hCQJZ-0002qd-RG
for user1@mydomain.com; Fri, 05 Apr 2019 11:59:45 -0300
Date: Fri, 5 Apr 2019 16:59:30 +0200
Message-ID:
<fhm6sz5qxapewcysor62grixt.jmq84bxig2.51492054873603.n4qmhqlo1g.r4wulllq@mail491.ifs94.riopreto.net>
Feedback-ID: 050468 caek upu a List(05680):8303789:xcakuq
From: <user1@mydomain.com>
Subject: user1
X-Complaints-To: abuse@mailer.riopreto.net
Errors-To: no-reply@riopreto.net
Content-Type: multipart/related;
boundary="irojfwweg-523511A2"
MIME-Version: 1.0
To: user1@mydomain.com
X-Sender: <neder@riopreto.net>
X-Abuse-Reports-To: abuse@mail.riopreto.net
List-Unsubscribe:
<https://riopreto.net/unsubscribe/es/280 … 2398391067>
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - canela.sacola.com.br
X-AntiAbuse: Original Domain - mydomain.com
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - riopreto.net
X-Get-Message-Sender-Via: canela.sacola.com.br: authenticated_id: neder@riopreto.net
X-Authenticated-Sender: canela.sacola.com.br: neder@riopreto.net
X-Source:
X-Source-Args:
X-Source-Dir:
Message Body
Apr 7 09:27:42 smtp postfix/postscreen[23885]: CONNECT from [192.168.1.8]:50062 to [192.168.1.20]:25
Apr 7 09:27:42 smtp postfix/postscreen[23885]: cache btree:/var/lib/postfix/postscreen_cache full cleanup: retained=1 dropped=0 entries
Apr 7 09:27:48 smtp postfix/postscreen[23885]: PASS OLD [192.168.1.8]:50062
Apr 7 09:27:48 smtp postfix/smtpd[23888]: connect from _gateway[192.168.1.8]
Apr 7 09:27:49 smtp postfix/smtpd[23888]: Anonymous TLS connection established from _gateway[192.168.1.8]: TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)
Apr 7 09:27:51 smtp postfix/cleanup[23896]: warning: pcre map /etc/postfix/header_checks, line 16: out of range replacement index "2": skipping this rule
Apr 7 09:27:51 smtp postfix/cleanup[23896]: warning: pcre map /etc/postfix/body_checks.pcre, line 1: out of range replacement index "2": skipping this rule
Apr 7 09:27:51 smtp postfix/smtpd[23888]: 44cCXR0KzvzSjyV: client=_gateway[192.168.1.8]
Apr 7 09:27:51 smtp postfix/cleanup[23896]: 44cCXR0KzvzSjyV: message-id=<fhm6sz5qxapewcysor62grixt.jmq84bxig2.51492054873603.n4qmhqlo1g.r4wulllq@mail491.ifs94.riopreto.net>
Apr 7 09:27:53 smtp postfix/qmgr[23605]: 44cCXR0KzvzSjyV: from=<neder@riopreto.net>, size=267538, nrcpt=1 (queue active)
Apr 7 09:27:53 smtp postfix/smtpd[23888]: disconnect from _gateway[192.168.1.8] ehlo=2 starttls=1 mail=1 rcpt=1 data=1 quit=1 commands=7
Apr 7 09:27:54 smtp postfix/10025/smtpd[23904]: connect from localhost[127.0.0.1]
Apr 7 09:27:54 smtp postfix/10025/smtpd[23904]: 44cCXV4JwdzSjyw: client=localhost[127.0.0.1]
Apr 7 09:27:54 smtp postfix/cleanup[23896]: 44cCXV4JwdzSjyw: message-id=<fhm6sz5qxapewcysor62grixt.jmq84bxig2.51492054873603.n4qmhqlo1g.r4wulllq@mail491.ifs94.riopreto.net>
Apr 7 09:27:54 smtp postfix/qmgr[23605]: 44cCXV4JwdzSjyw: from=<neder@riopreto.net>, size=268444, nrcpt=1 (queue active)
Apr 7 09:27:54 smtp postfix/10025/smtpd[23904]: disconnect from localhost[127.0.0.1] ehlo=1 mail=1 rcpt=1 data=1 quit=1 commands=5
Apr 7 09:27:54 smtp amavis[20019]: (20019-02) Passed CLEAN {RelayedInbound}, [192.168.1.8]:50062 [177.73.8.22] <neder@riopreto.net> -> <user2@mydomain.com>, Queue-ID: 44cCXR0KzvzSjyV, Message-ID: <fhm6sz5qxapewcysor62grixt.jmq84bxig2.51492054873603.n4qmhqlo1g.r4wulllq@mail491.ifs94.riopreto.net>, mail_id: EExNB1dZyP1b, Hits: 5.298, size: 267538, queued_as: 44cCXV4JwdzSjyw, 1549 ms, Tests: [ALL_TRUSTED=-1,HEADER_FROM_DIFFERENT_DOMAINS=0.001,HTML_IMAGE_ONLY_04=0.342,HTML_MESSAGE=0.001,LIST_PARTIAL_SHORT_MSG=2.499,LOCALPART_IN_SUBJECT=0.73,MIME_HTML_MOSTLY=0.001,MPART_ALT_DIFF=0.724,TO_NO_BRKTS_HTML_IMG=1.999,TVD_SPACE_RATIO=0.001]
Apr 7 09:27:54 smtp postfix/amavis/smtp[23901]: 44cCXR0KzvzSjyV: to=<user2@mydomain.com>, relay=127.0.0.1[127.0.0.1]:10024, delay=4.4, delays=2.8/0.02/0/1.6, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 44cCXV4JwdzSjyw)
Apr 7 09:27:54 smtp postfix/qmgr[23605]: 44cCXR0KzvzSjyV: removed
Apr 7 09:27:54 smtp postfix/pipe[23905]: 44cCXV4JwdzSjyw: to=<user2@mydomain.com>, relay=dovecot, delay=0.15, delays=0.02/0.04/0/0.09, dsn=2.0.0, status=sent (delivered via dovecot service (doveconf: Warning: SSLv2 not supported by OpenSSL. Please consider removing it from ssl_protocols.))
Apr 7 09:27:54 smtp postfix/qmgr[23605]: 44cCXV4JwdzSjyw: removed
Mathew
ZhangHuangbin wrote:mathewfer wrote:How can we setup to discard these SPAM rather than sending to junk mail folder?
*) There's a sieve rule in /var/vmail/sieve/dovecot.sieve, it moves detected spam to Junk folder. You can change the action to discard it (WARNING: email will be discarded and you can not get it back.)
*) With iRedAdmin-Pro, you can choose to quarantine spams to SQL database, and manage (release or delete) them with iRedAdmin-Pro. FYI: https://docs.iredmail.org/quarantining.html#screenshots