This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Too much spam passes Astaro since v8

I realize that too much spam passes the Astaro since (I think) v8.200.

Today I got a mail with the word "vagina" in subject. Do we need to care about expressions now? We never had to care about expressions in the past, so we don´t have any word on the expression list until now.

What´s wrong there?

We use "Reject invalid HELO / missing RDNS", "Greylisting" and "Perform SPF check" and the following RBLs:

bl.spamcop.net
psbl.surriel.com
cbl.abuseat.org
dnsbl.ahbl.org
dul.maps.vix.com
rbl.maps.vix.com
blackholes.mail-abuse.org


What else can we do?


This thread was automatically locked due to age.
Parents
  • I get less than one a week of those, but, I get one or two related ones every day of the "Advance-fee fraud (Nigerian 419)" type.  They're related because the checksum of the messages hasn't yet been identified in the CommTouch database and the MTA that sends it to the Astaro has an IP with good reputation, also passing spf, RDNS/EHLO, etc.  In fact the message you got even passed your greylisting.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • I get less than one a week of those, but, I get one or two related ones every day of the "Advance-fee fraud (Nigerian 419)" type.  They're related because the checksum of the messages hasn't yet been identified in the CommTouch database and the MTA that sends it to the Astaro has an IP with good reputation, also passing spf, RDNS/EHLO, etc.  In fact the message you got even passed your greylisting.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data