ORF反垃圾邮件系统

邮件服务器-邮件系统-邮件技术论坛(BBS)

 找回密码
 会员注册
查看: 4023|回复: 6
打印 上一主题 下一主题

[求助] MD中一份难防止的垃圾邮件

[复制链接]
跳转到指定楼层
顶楼
发表于 2008-4-23 15:50:07 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
使用MD英文版9.0以上版本,其中有一份垃圾邮件很难处理,邮件的一些信息如下:
说明:ganyy@abc.com和hfl@abc.com都是公司真实的正常用户,目前在防止垃圾邮件方面,启用了白名单对自己的域用户即@abc.com;另外启用了DNSBL,如果发现某一个IP在DNSBL禁止库中且其邮件已经被识别为垃圾邮件(通过评分机制)邮件头含有垃圾邮件标示字符spam则删除该邮件。目前这个邮件处理难点是,因为其做了假,冒充是白名单域,故不会识别为垃圾邮件也就不会修改邮件头增加spam字段,虽然DNSBL识别了,但是因为不满足其删除条件,故不会删除,请高手指点


以下是邮件的邮件头:
Return-path: <c.meer@exert.nl>
X-Spam-Checker-Version: SpamAssassin 3.1.5 (2006-08-29)
X-Spam-Level:
X-Spam-Status: No, score=-79.1 required=5.0 tests=BAYES_99,HELO_DYNAMIC_HCC,
HELO_DYNAMIC_IPADDR2,MDAEMON_DNSBL,USER_IN_WHITELIST autolearn=no
version=3.1.5
X-Spam-Report:
*  4.1 HELO_DYNAMIC_HCC Relay HELO'd using suspicious hostname (HCC)
*  3.8 HELO_DYNAMIC_IPADDR2 Relay HELO'd using suspicious hostname (IP
*      addr 2)
*  3.0 MDAEMON_DNSBL MDaemon: marked by MDaemon's DNSBL
* -100 USER_IN_WHITELIST From: address is in the whitelist
*   10 BAYES_99 BODY: Bayesian spam probability is 99 to 100%
*      [score: 1.0000]
Authentication-Results: abc.com
[email=smtp.mail=c.meer@exert.nl]smtp.mail=c.meer@exert.nl[/email]; spf=neutral; ip-match=fail
Authentication-Results: abc.com
[email=header.from=c.meer@exert.nl]header.from=c.meer@exert.nl[/email]; domainkeys=neutral (not signed); dkim=neutral (not signed)
X-MDDK-Result: neutral (abc.com)
X-MDDKIM-Result: neutral (abc.com)
X-MDSPF-Result: none (abc.com)
Received-SPF: none (abc.com: c.meer@exert.nl does not
designate permitted sender hosts)
x-spf-client=MDaemon.PRO.v9.5.2
receiver=abc.com
client-ip=201.223.61.173
envelope-from=<c.meer@exert.nl>
helo=173-61-223-201.adsl.terra.cl
Received: from 173-61-223-201.adsl.terra.cl (173-61-223-201.adsl.terra.cl [201.223.61.173])
by abc.com (abc.com)
(MDaemon PRO v9.5.2)
with ESMTP id md50000977055.msg
for <hfl@abc.com>; Mon, 14 Apr 2008 13:43:34 +0800
X-Originating-IP: 182.168.230.99 by smtp.190.0.84.194;  Mon, 14 Apr 2008 01:41:49 -0500
Message-ID: <umflnBPLAVKganyy@abc.com>
From: "Maura Kendrick" <ganyy@abc.com>
Reply-To: "Maura Kendrick" <ganyy@abc.com>
To: ganyy@abc.com
Subject: Inexpensive Louis Vuitton bags
Date: Mon, 14 Apr 2008 01:41:49 -0500
Content-Type: text/plain;
Content-Transfer-Encoding: 7Bit
X-RBL-Warning: mail from 201.223.61.173 refused, see http://www.ordb.org/faq/
X-Lookup-Warning: MAIL lookup on c.meer@exert.nl does not match 201.223.61.173
X-MDRcpt-To: hfl@abc.com
X-Rcpt-To: hfl@abc.com
X-MDRemoteIP: 201.223.61.173
X-Return-Path: c.meer@exert.nl
X-Envelope-From: c.meer@exert.nl
X-MDaemon-Deliver-To: hfl@abc.com
X-Spam-Processed: abc.com, Mon, 14 Apr 2008 13:43:35 +0800
X-MDAV-Processed: abc.com, Mon, 14 Apr 2008 13:43:35 +0800

以下是邮件的正文:
The new Porsche Design watches originated from the novel Titanium Chronograph from the 1970's, an absolutely unique creation due to the perfection of its workmanship. Based on its design, the Porsche Design Company developed an appealing, stylish, sporty and highly accurate watch. Unfortunately, these timepieces come with a high price tag.
http://pugybyno56350.blogspot.com/
That's why a clever group of European manufacturers decided to offer the same exact functionality and style at greatly reduced prices: the Porsche Design replica watches. These replicas are so similar to the brand name pieces that it is practically impossible to tell them apart, other than by their price. They look the same, they function the same and they definitely don't have the same prices How would you like to browse through an amazing collection of these watches and marvel yourself with their low prices? Visit Prestige Replicas and see for yourself why sometimes replicas are so much better than the originals!
http://pugybyno56350.blogspot.com/

以下是发送方及接受方及主题:
发送方Maura Kendrick [ganyy@abc.com]
接受方ganyy@abc.com
主题Inexpensive Louis Vuitton bags
沙发
发表于 2008-4-23 15:55:23 | 只看该作者

回复 1楼 的帖子

本地域不需要加白名单的,默认SA设置为只要能通过ESMTP身份认证就自动跳过的,不需要手工加白名单。
藤椅
发表于 2008-4-23 19:22:53 | 只看该作者
国家863计划反垃圾邮件平台免费使用
参与条件:自建邮件服务器的企业用户
公益活动时间:2008年3月25日-2008年12月31日
更多详情请登录:tap.263.net
板凳
 楼主| 发表于 2008-4-25 14:49:26 | 只看该作者
回复wxhsh
谢谢你的回复

你的建议是否是这样:
1.在防止垃圾邮件设置的白名单中出掉邮件系统本地域用户也就是@abc.com
2.(默认SA设置为只要能通过ESMTP身份认证就自动跳过的)这个具体怎么设置不明白,还是不需要设置。
报纸
发表于 2008-4-25 14:52:59 | 只看该作者

回复 4楼 的帖子

1.对
2.不要设置,默认就是这个选项。
地板
 楼主| 发表于 2008-4-25 19:48:19 | 只看该作者
谢谢,我去修改一下,在来报告,呵呵
7
 楼主| 发表于 2008-4-28 10:27:34 | 只看该作者
这几天好像没有,继续观察一下
您需要登录后才可以回帖 登录 | 会员注册

本版积分规则

小黑屋|手机版|Archiver|邮件技术资讯网

GMT+8, 2024-11-18 22:41

Powered by Discuz! X3.2

© 2001-2016 Comsenz Inc.

本论坛为非盈利中立机构,所有言论属发表者个人意见,不代表本论坛立场。内容所涉及版权和法律相关事宜请参考各自所有者的条款。
如认定侵犯了您权利,请联系我们。本论坛原创内容请联系后再行转载并务必保留我站信息。此声明修改不另行通知,保留最终解释权。
*本论坛会员专属QQ群:邮件技术资讯网会员QQ群
*本论坛会员备用QQ群:邮件技术资讯网备用群

快速回复 返回顶部 返回列表