1

Topic: spam problem - mostly from yahoo

==== Required information ====
- iRedMail version:
- Store mail accounts in which backend (LDAP/MySQL/PGSQL):
- Linux/BSD distribution name and version:
- Related log if you're reporting an issue:
==== Hi Zhang,


I'm having an issue with amavis and SA. I'm not quite sure why it is not cathing some obviously spam-like emails.

most of them are coming from yahoo.com

what do you think, is there any way to prevent or fine-tune SA?

Thanks

Tamás

Example mail:

Subj: BED TEEN STORIES about having mole wonderful nights
from: Alexa Carlill <gvguerrero45@yahoo.com>
to: sweeto0ogirl1@hotmail.com, ###AND MY E-mail address###

MSG BODY:
Alrite

Dori Stokes insect wants to MEET YOU at your place
    http://*******   (i removed the url)




---------------------------------------------------------------------
Part of header:
Received: from localhost (localhost [127.0.0.1]) by ******* (Postfix) with ESMTP id D40ED8CE1CA for <*******>; Thu,  9 Aug 2012 17:37:02 +0200 (CEST)
Received: from ******* ([127.0.0.1]) by localhost (******* [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gkc8A7fGDbVU for <*******>; Thu,  9 Aug 2012 17:36:56 +0200 (CEST)
Received: from nm20-vm7.bullet.mail.sg3.yahoo.com (nm20-vm7.bullet.mail.sg3.yahoo.com [106.10.149.134]) by dodo.omniweb.hu (Postfix) with SMTP id CA3E28CE1B0 for <*******>; Thu,  9 Aug 2012 17:36:54 +0200 (CEST)
Received: from [106.10.166.115] by nm20.bullet.mail.sg3.yahoo.com with NNFMP; 09 Aug 2012 15:32:06 -0000
Received: from [106.10.167.149] by tm4.bullet.mail.sg3.yahoo.com with NNFMP; 09 Aug 2012 15:32:06 -0000
Received: from [127.0.0.1] by smtp122.mail.sg3.yahoo.com with NNFMP; 09 Aug 2012 15:32:06 -0000
Received: from Victoria (gvguerrero45@180.248.255.69 with plain) by smtp122.mail.sg3.yahoo.com with SMTP; 09 Aug 2012 08:32:06 -0700 PDT
X-Virus-Scanned: Debian amavisd-new at *******
X-Spam-Flag: NO
X-Spam-Score: -0.636
X-Spam-Level:
X-Spam-Status: No, score=-0.636 tagged_above=-999 required=6.31 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, T_RP_MATCHES_RCVD=-0.01, UNPARSEABLE_RELAY=0.001, URI_HEX=1.122] autolearn=no
X-Original-Helo: nm20-vm7.bullet.mail.sg3.yahoo.com (iRedMail: http://www.iredmail.org/)
Received-Spf: None (no SPF record) identity=mailfrom; client-ip=106.10.149.134; helo=nm20-vm7.bullet.mail.sg3.yahoo.com; envelope-from=gvguerrero45@yahoo.com; receiver=*******
Dkim-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1344526326; bh=jNI3BNZTY6E+G6Nb4PaZCyi4Cv9N+4jk8kaypA1Ommw=; h=X-Yahoo-Newman-Id:Message-ID:X-Yahoo-Newman-Property:X-YMail-OSG:X-Yahoo-SMTP:Received:From:To:Date:Subject:MIME-Version:Content-Type:Content-Transfer-Encoding; b=YIGRZgUtIiiWUdKLkTXuI/hfnaox6G9X/0QZUyPIZww90+TYvUYSv4nifGU0wTg+QeRsnbFGGKbomlv+nJCxbKl1egKRBReroxuMxgH0BmhmPf1tcWJZFMTfhO+nQnYCsN+EZgkIexTJ0micHti+uNahQ2KlhoHIzoGI/CybI/A=
X-Yahoo-Newman-Id: 385840.95008.bm@smtp122.mail.sg3.yahoo.com
Message-Id: <385840.95008.bm@smtp122.mail.sg3.yahoo.com>
X-Yahoo-Newman-Property: ymail-3
X-Ymail-Osg: MvVG3UwVM1mUOBx81QpnZEmzvCiqvd1vo0CPu3ROUeJzlT0 iDWsECkYoc1ITjqlFZ_G6Ri6OGWi4Uuj2rrgI9L0CM350mL7h3a0jJ22ioQe 8KYHwtacK1Vj7k9t08ubIfpPmxVwCRqsrgZh3W38FUEZC.laJ3B71RKvnTTy 0OtXBC8kb0Fh9C9.vcqH2EPKGSPJbeq4t4rEl8ROEFzUyPfJmwA0VREsNTt9 uMVcQml7Kzo8.6Y06BQpijE9iiPXv6WRTSdCzpqo4_0epu2KoetlTAMVWmur sG8pEaplBqqkOUdgi.2KVWPmqED9wMbGHzP5lYAlbiPHUVO4e2uU0yqr1fTn JysFdKjiKjsFZJT16QT4zD6gFgjpw72OKNMHsKFPs1kE1mVwBa0Oprnw0kJM U52lF6EjolpyvCCFtKOMX1J6Hzgf27GF3xiVw0YhUOzsZuWSoH4YDs0SE2YY Ff2Q0ZSpG9rzUHBysjojk3IL_HP7Z1Wc7DxgyXWmlZJudpwhBt3NcMnwQ
X-Yahoo-Smtp: mfF1T4aswBAIVO8ym88wh_bMzfKS5fbkTQ--
Mime-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 7bit


==== Required information ====
- iRedMail version:  0.8.1
- Store mail accounts in which backend (LDAP/MySQL/PGSQL):  LDAP
- Linux/BSD distribution name and version: Debian Squeeze
- Related log if you're reporting an issue:
====

----

Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.

2

Re: spam problem - mostly from yahoo

tomek_hun wrote:

I'm having an issue with amavis and SA. I'm not quite sure why it is not cathing some obviously spam-like emails.

You have to tune your SA rules in /etc/mail/spamassassin/local.cf, e.g. increase score of matched mail header (BED TEEN STORIES).