Backscatter mails not catched by Mail2?

v7
mail2
rspamd

(Michael Kicks) #21

Ok, maybe i am the dumb one now.
@stephdl, in your opinion, what’s wrong, during the first connection during delivery, with a “temporary reject”?


(Davide Principi) #22

I guess graylist does not help in this case because the backscatter source will try the delivery again after the temporary rejection.

Unless it gets blacklisted in the meantime… But we cannot rely on this event.


(Joel Clendineng) #23

I just ended up disabling rspamd, as it sent almost everything to spam folder :smiley: probable as well as reject. It blocked online bill pay alerts, newsletters, you know, important emails. I just need to figure out how to get rspamd to learn from good emails it has marked as spam. I tried allowing the sender in the web gui but that did not work.


(Markus Neuberger) #24

To learn ham it should be enough to just move the good mails to the inbox. You need 200 hams to make the filter work.

http://docs.nethserver.org/en/v7/mail.html#anti-spam


(Joel Clendineng) #25

Thanks, I will give that a try!


(Michael Kicks) #26

I agree. But also I can’t totally rely on that every backscatter source will try again the delivery.

Get into a Blacklist is a matter of time. Therefore, during backscatter firetime i am not sure than all the spam sources will manage the delivery according to RFC and best practices for email servers.

I think (and maybe i’m wrong :slight_smile: ) that SPF could ease at least 30% of backscatter sources. So, still not absolute weapon but… maybe another little brick into the “keep the thrash out of servers” wall.


(Joel Clendineng) #27

Do I need to port forward sieve port since my mail server is behind a gateway? 200 spams/hams is an awful lot. I will keep on though!


(Markus Neuberger) #28

It depends, if you use webmail it shouldn’t be necessary. Not local clients like thunderbird may need it.


(Joel Clendineng) #29

ok I will add it…I use all non-local imap clients (bluemail on android and windows mail on windows).


(Filippo Carletti) #30

NethServer does not bounce emails.
NethServer does not create backscatter.
To fight backscatter received by NethServer (sent by other mail servers) you need to know which mail servers can send email for your domain and discard messages not sent by them, or you will lose legitimate bounces. This can not be done automatically.

ATM, my only idea is to use http://www.backscatterer.org/ to refuse messages from server known to send backscatter.


(Matthieu Gaillet) #31

Hi @filippo_carletti,

Reading the mail headers again, I believe that in that case you’re right : my user is actually victim of a backscatter mail, and therefore nethserver isn’t the culprit here. I misinterpreted the non delivery notification.

However I’m pretty sure that nethserver does send non deliveries in case of spam. Please read again that thread : Postfix sending non-deliveries notifications because of spam?


(Filippo Carletti) #32

NethServer answers with smtp error code 554, you can check it sending you a gtube (http://spamassassin.apache.org/gtube/).


(Matthieu Gaillet) #33

I see. I thought that a 554 could generate backscatter but it looks like it is actually not the case.

However, I’m positive that still there is a case where nethserver answers back to spammer, which triggers the anti spam policy of my smarthost. I’ll report back next time it happens.


(Matthieu Gaillet) #34

Ehi @filippo_carletti

Regarding this backscatter potential issue. Look at this mail queue on a live system :

The recipients are obviously not connected in any way to our business. MAILER-DAEMON indicates that it is our server that tries to answer them some delivery report… for a mail we never sent.

How do you interpret this ? Personally I interpret this as the result of a backscatter attack involving our server.

Thanks for your insight.