Topic: random SPAM getting through
==== Required information ====
- iRedMail version (check /etc/iredmail-release): 0.9.4
- Linux/BSD distribution name and version: CentOS 6.7 in LXC container on Proxmox 4.0
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): LDAP
- Web server (Apache or Nginx): nginx
- Manage mail accounts with iRedAdmin-Pro? no
- Related log if you're reporting an issue:
Apr 29 11:39:35 webmail postfix/smtpd[14095]: AE83161514: client=unknown[85.206.175.41]
Apr 29 11:39:36 webmail postfix/cleanup[13982]: AE83161514: message-id=<7F1CC1F74F311C4EA83711C3F5AEDC.21677427@bannerelkproperties.supernaturalatino.com>
Apr 29 11:39:36 webmail postfix/qmgr[9246]: AE83161514: from=<LiaKun@bannerelkproperties.supernaturalatino.com>, size=19017, nrcpt=1 (queue active)
Apr 29 11:39:40 webmail postfix/smtpd[14145]: 2438C6151B: client=localhost[127.0.0.1]
Apr 29 11:39:40 webmail postfix/cleanup[13982]: 2438C6151B: message-id=<7F1CC1F74F311C4EA83711C3F5AEDC.21677427@bannerelkproperties.supernaturalatino.com>
Apr 29 11:39:40 webmail postfix/qmgr[9246]: 2438C6151B: from=<LiaKun@bannerelkproperties.supernaturalatino.com>, size=19723, nrcpt=1 (queue active)
Apr 29 11:39:40 webmail amavis[14279]: (14279-04) Passed CLEAN {RelayedInbound}, [85.206.175.41]:46804 [85.206.175.41] <LiaKun@bannerelkproperties.supernaturalatino.com> -> <<MYEMAIL>@<MYDOMAIN>>, Message-ID: <7F1CC1F74F311C4EA83711C3F5AEDC.21677427@bannerelkproperties.supernaturalatino.com>, mail_id: LhE1K48yvmFp, Hits: 3.783, size: 18981, queued_as: 2438C6151B, 3788 ms
Apr 29 11:39:40 webmail postfix/smtp[14081]: AE83161514: to=<<MYEMAIL>@<MYDOMAIN>>, relay=127.0.0.1[127.0.0.1]:10024, delay=4.5, delays=0.67/0/0.01/3.8, dsn=2.0.0, status=sent (250 2.0.0 from MTA(smtp:[127.0.0.1]:10025): 250 2.0.0 Ok: queued as 2438C6151B)
Apr 29 11:39:40 webmail postfix/qmgr[9246]: AE83161514: removed
Apr 29 11:39:40 webmail postfix/pipe[14131]: 2438C6151B: to=<<MYEMAIL>@<MYDOMAIN>>, relay=dovecot, delay=0.1, delays=0.02/0/0/0.08, dsn=2.0.0, status=sent (delivered via dovecot service)
Apr 29 11:39:40 webmail postfix/qmgr[9246]: 2438C6151B: removed
====
Hello everyone,
I have just successfully migrated iRedMail from 0.9.0 to 0.9.4 (phew!) and though it's well, everything seeming to work OK, though I am seeing a lot of SPAM that doesn't appear to have been scanned by the system. SPAM filtering is occurring for the majority of messages but many are delivered to the INBOX with very low scores. The missed positives are flagged as SPAM if I run them through spamassassin manually on the command line like this:
spamassassin -t -D < [email_message]
Here is the message headers as delivered to INBOX:
================================================================================
Return-Path: <LiaKun@bannerelkproperties.supernaturalatino.com>
Delivered-To: <MYEMAIL>@<MYDOMAIN>
Received: from webmail.<MYDOMAIN> (localhost [127.0.0.1])
by webmail.<MYDOMAIN> (Postfix) with ESMTP id 2438C6151B
for <<MYEMAIL>@<MYDOMAIN>>; Fri, 29 Apr 2016 11:39:40 -0400 (EDT)
X-Virus-Scanned: amavisd-new at webmail.<MYDOMAIN>
X-Spam-Flag: NO
X-Spam-Score: 3.783
X-Spam-Level: ***
X-Spam-Status: No, score=3.783 tagged_above=-10 required=5.5
tests=[HTML_MESSAGE=0.001, PYZOR_CHECK=2.5, RDNS_NONE=1.274,
SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_REMOTE_IMAGE=0.01]
autolearn=no
Received: from webmail.<MYDOMAIN> ([127.0.0.1])
by webmail.<MYDOMAIN> (webmail.<MYDOMAIN> [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id LhE1K48yvmFp for <<MYEMAIL>@<MYDOMAIN>>;
Fri, 29 Apr 2016 11:39:36 -0400 (EDT)
Received: from bannerelkproperties.supernaturalatino.com (unknown [85.206.175.41])
by webmail.<MYDOMAIN> (Postfix) with ESMTP id AE83161514
for <<MYEMAIL>@<MYDOMAIN>>; Fri, 29 Apr 2016 11:39:35 -0400 (EDT)
Received: by bannerelkproperties.supernaturalatino.com id h4e03g0001gp for <<MYEMAIL>@<MYDOMAIN>>; Fri, 29 Apr 2016 11:34:09 -0400 (envelope-from <LiaKun@bannerelkproperties.supernaturalatino.com>)
To: <<MYEMAIL>@<MYDOMAIN>>
Reply-To: <daniel@supernaturalatino.com>
Message-ID: <7F1CC1F74F311C4EA83711C3F5AEDC.21677427@bannerelkproperties.supernaturalatino.com>
From: Discounted Cruises <daniel@supernaturalatino.com>
Subject: Unbought cruise rooms, 5 night 6 days
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="Hu51Hs7gXrGrQzLc7pAsJsH92sKoZ"
Date: Fri, 29 Apr 2016 11:39:36 -0400
--Hu51Hs7gXrGrQzLc7pAsJsH92sKoZ
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
I was very surprised when I entered the room,
<CUT>
================================================================================
And here's the same message as scanned on the command line:
================================================================================
Content analysis details: (16.5 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
3.6 RCVD_IN_SBL_CSS RBL: Received via a relay in Spamhaus SBL-CSS
[85.206.175.41 listed in zen.spamhaus.org]
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist
[URIs: supernaturalatino.com]
1.7 URIBL_BLACK Contains an URL listed in the URIBL blacklist
[URIs: supernaturalatino.com]
0.0 HTML_MESSAGE BODY: HTML included in message
2.5 PYZOR_CHECK Listed in Pyzor (http://pyzor.sf.net/)
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
5.0 KAM_VERY_BLACK_DBL Email that hits both URIBL Black and Spamhaus DBL
0.0 T_REMOTE_IMAGE Message contains an external image
================================================================================
As you see, there's a big difference!
Why would amavisd be bypassed for some messages and not others? Where do I begin to debug this? I'm kinda lost especially since everything else seems to be working so well and there is a LOT of SPAM being blocked otherwise.
Thanks for any insight you can provide.
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.