Re: Finer control of header_checks

From: Paul Gardiner (no email)
Date: Wed Dec 01 2004 - 12:41:48 EST


From: "Robin Lynn Frank" <>
> On Wed, 2004-12-01 at 08:57, Paul Gardiner wrote:
>
> >
> > > Out of curiosity, what exactly are you trying to use to bypass on?
> >
> > I'm intending to introduce a "before queue" spam filter (probably using spampd).
> > I want to reject the spam using the header_checks facility (assuming that the reject
> > will work its way back through postfix, without turning into a bounce, which it
> > looks as though it will). But I have some email coming in via fetchmail, and I
> > don't want to reject that, because it will just mount up on my ISP's POP server.
> > I'm happy to have that come in and keep it in separate mail boxes.
> >
> > > Since
> > > all headers can be faked by a sender, there isn't much left in the
> > > headers to trust.
> >
> > That worries me a bit, but I think I'm ok. If someone fakes a positive Spam
> > header, then they deserve to have the email rejected. And faking of the header
> > generated by fetchmail is unlikely.
> >
> > Thanks for your interest. I need all the help I can get.
> >
> > Cheers,
> > Paul.
> First, before queue spam filtering is good only with low volume sites or
> with a spam filter that is really fast.

Yeah, that's ok: this is used only for my and few friend's mail.

> Second, man fetchmail shows the parameters necessary *not* to bounce
> rejected mail. It also clearly states that mail rejected with a 553
> will never be bounced by fetchmail. Although the 553 might be
> unorthodox, it will guarantee fetchmail won't bounce rejections if you
> can't achieve this any other way.

Thanks. That's useful to know. I'd rather let the mail in so I can check
for false postitives, but there should be very little coming in this way,
so dropping it is an option.

> Third, why would rejecting mail cause mail to "mount up" on your ISP's
> pop3?

Probably it wont. I thought that fetchmail didn't delete off the server
messages that it failed to deliver. I'd seen that behaviour but that was
probably failure with a 4xx code.

Help much appreciated.

Cheers,
    Paul.








Hosted Email Solutions

Invaluement Anti-Spam DNSBLs



Powered By FreeBSD   Powered By FreeBSD