Spamhaus & rspamd config on NS8

NethServer Version: Nethserver 8 - core 3.21.1
Module: Mail 1.8.0

I have a DNS Query Key from Spamhaus that I used for a long time with ClearOS. I saw that the Mail module got updated in the past 6+ months to include DNS Queries and use the rspamd from the discussions and from the github commits. I can see spamhaus listed in the Symbols in rspamd but am missing something conceptually as to how this should be set up. (Newbie home user alert)

This week I got an email from Spamhaus that I need to configure and use the service in the next 7 days or have my account deleted. So I have to finally finish this configuration.

I’ve been reading the docs and can’t find any info about how to configure and add my key to the postfix in Mail and how to configure rspamd to add the key there.

I did run this command from the docs:

# runagent -m mail1 podman exec rspamd rspamadm configdump rbl | grep "rbl = "
ERRO[0000] User-selected graph driver "overlay" overwritten by graph driver "vfs" from database - delete libpod local files ("/home/mail1/.local/share/containers/storage") to resolve.  May prevent use of images created by other tools
        rbl = "zen.spamhaus.org";
        rbl = "rep.mailspike.net";
        rbl = "bl.score.senderscore.com";
        rbl = "score.senderscore.com";
        rbl = "bl.spameatingmonkey.net";
        rbl = "bl.ipv6.spameatingmonkey.net";
        rbl = "list.dnswl.org";
        rbl = "bip.virusfree.cz";
        rbl = "bl.blocklist.de";
        rbl = "dwl.dnswl.org";
        rbl = "email.rspamd.com";
        rbl = "ebl.msbl.org";
        rbl = "multi.surbl.org";
        rbl = "hashbl.surbl.org";
        rbl = "multi.uribl.com";
        rbl = "uribl.rspamd.com";
        rbl = "dbl.spamhaus.org";
        rbl = "zen.spamhaus.org";
        rbl = "uribl.spameatingmonkey.net";
        rbl = "fresh15.spameatingmonkey.net";

The discussion thread appear to have happened before the updates to add the rspamd plugin and addition to Mail. Can you give some directions on how to find the docs on how to configure these two?

(AI has given some recommendations but I’m worried about implementing solutions from AI on our home mail server.)

Thank you.

Hi Nuke,

Good news on the NS8 side: this is already built into the Mail module, no manual Postfix config needed. It’s documented in the README: Rspamd plugin for Spamhaus DQS, and also listed in the Milestone 8.9 release notes — worth a read if you want the bigger picture of what changed recently on NS8, there’s a lot in there.

The NS8 steps (these I can confirm):

  1. Get a DQS token from Spamhaus (see below for caveats on this part).

  2. Edit the module’s state/rspamd.env file and add:

    RSPAMD_dqs_token=<MY_DQS_KEY>
    
  3. Restart Rspamd:

    systemctl --user restart rspamd
    

No separate Postfix configuration is needed — it’s handled entirely through this Rspamd plugin, thanks to @mrmarkuz and @pagaille. To disable it later, just remove that line and restart the service.

On the Spamhaus side, I can’t speak with authority — best to verify directly with Spamhaus support/docs whether your existing key carries over to a DQS token.

This is the discussion about this feature Rspamd DBL checks disabled because of the use of an open DNS?


BTW do you have Debian 13? I just replied about this warning in this thread Podman error in log: driver "overlay" overwritten

I think it’s great that you’re providing features like this, but why do I have to dig deep into the system to access them? Configuration settings like these belong in the GUI.

True that :slight_smile: Would be a nice improvement since that’s a basic setting.

Thank you @davidep . I’ve got some reading ahead of me but appreciate getting some directions on where to look and learn.

Yes, I’m running NS8 on Debian 13. I’ll review the post also to see what is what.

thanks again for your help.

Thank you @davidep , the addition of the DQS token looks to be working OK.
I’ve also fixed the ERRO[0000] . Yes, I used Debian 13 and upgraded from Debian 12. It would appear like something got missed in the update. I will add some comments to the other link later this weekend.

And @capote and @pagaille , I agree. If the rspamd module is installed it would be very nice to have access in the GUI.

OK, I added a post too quickly. Yes, it is running OK but spamhaus test is a fail.

Hmmm. Now I’m stuck until I do some more investigation.

That’s the SMTP test, which doesn’t work since NS8 doesn’t use rspamd at postfix level (might be a nice addition by the way). The content test should work (messages must go into SPAM folder).

I’m not sure.

Every email showed up in rspamd with a green “pass” and arrived in my inbox.

From reading the docs, I understood that you didn’t need to do anything to smpt/postfix as rspamd and module configuration would take care of everything.

I note also that before making the changes above, only slb-dqs-ip was red i.e. delivered. So in the default config somehow all tests were OK except for one pass through. Now I’ve added the DQS key and enabled rspamd spamhaus module and the result is worse.

Interestingly enough, rspamd starts OK, config is checked OK and there are no errors in the log. So why is this now worse? I have to think on it a bit.

Was it using the SMTP test or the contents test ?

Hi @pagaille . I ran both tests, SMTP and contents.

This is the SMTP test from before I made the suggested changes.

Yes, this is the SMTP test also. But it shouldn’t be worse after you add your Spamhaus key onto the rspamd module.

I am missing something I suspect.

Hmmm. This is interesting.

Perhaps I tested using the blocklist tester too quickly. There is activity and something is being blocked as the test results are inconclusive. However the test messages were still delivered.

Having said that, Spamhaus usage shows 143 for the last day. For months before it was zero. So something is working.

The messages that got through say something about MX configuration.
C: This is a Spamhaus BLT DQS content-test email which has been
C: crafted to be flagged as spam by properly configured mail systems. If
C: your MX is correctly configured to do content filtering for the
C: dbl-dqs-body-domain test, then this email should be flagged as spam (check the
C: headers) or rejected outright. If this email was delivered, and not
C: classified as spam, then your MX is not correctly configured for the
C: dbl-dqs-body-domain test; please see the BLT documentation at
C: https://blt.spamhaus.com/docs` for tips on configuring your MX.`

On to the next research.

Here is some more info from one of the content tests. I added the bold.

This email was delivered, but that doesn’t necessarily mean your MX is misconfigured, because this is a test of content-level filtering, and that often takes place after SMTP-level delivery. Please check if this test email really was delivered to an inbox, and if so check that it was flagged as spam. If it was not flagged as spam, then your MX it not configured to use content filtering for the block list for this test.

I’m searching for some info about MX configuration but haven’t found it yet.

Here is what I see from rspamd. The test emails should have been blocked.

and

Given this, I think the rspamd isn’t quite working correctly.

Working on my side.

Please provide the X-SPAMD headers.

Here are mine for the BLT DQS Content Test Email (81628:997153:dbl-dqs-body-domain)

X-Spamd-Result: default: False [14.59 / 15.00];
DBL_SPAM(7.00)[``dbltest-dqs.com``:url];
BAYES_SPAM(6.99)[99.97%];
MX_INVALID(0.50);
MIME_GOOD(-0.10)[text/plain];
BAD_REP_POLICIES(0.10);
ONCE_RECEIVED(0.10);
RCPT_COUNT_ONE(0.00)[1];
ARC_NA(0.00);
MIME_TRACE(0.00)[0:+];
NEURAL_SPAM(0.00)[0.939];
ASN(0.00)[asn:54054, ipnet:199.168.88.0/22, country:US];
MISSING_XM_UA(0.00);
RCVD_COUNT_ZERO(0.00)[0];
R_DKIM_NA(0.00);
TO_DN_NONE(0.00);
FROM_EQ_ENVFROM(0.00);
R_SPF_ALLOW(0.00)[+ip4:199.168.89.101/32:c];
TO_MATCH_ENVRCPT_ALL(0.00);
MID_RHS_MATCH_FROMTLD(0.00);
DMARC_NA(0.00)[``spamhaus.net``];
FROM_HAS_DN(0.00)

Hi @pagaille .

I have been working on it for some time now. Yes the X-Spamd-Result showed that the test was not enabled. I think the script somewhere that creates the local.d/rbl.conf missed this:

spamhaus_zrd {
    ...
    urls = true;
    ...
}

After adding this, it looks like it is “greylisting” but in anycase it is as good as rejected.

The test shows this now:

I’ll check it again tomorrow and see what happens overnight.

Thanks for checking back in and giving guidance. It’s appreciated!

Hi @Nuke, do you have any new findings that you’d like to share ? I’m curious about this spamhaus_zrd config setting. I’m still wondering if you are interpreting the tests results correctly : the real test result is whether the test emails are landing as ham or spam.

Hi @pagaille . Thank you for the follow-up.

I forgot to come back and update. Since I made the change to the configuration file, Spamhaus content filters are working. When I run the content test, rspamd is “greylisting” rather than rejecting outright. I think it should be “rejecting” but greylisting also works as these messages are sent once.

I think I will still try to add the postfix spamhaus lists for completeness but generally I am happy with the result now as many spam emails that used to get through are now rejected. There are considerably more “reject” in the rspamd GUI.

Now I’ll be updating the mail app as I see there is an update. We’ll see if my edits to the config survive the update. :grinning:

Actually “Delivered” doesn’t means that the email gets to the inbox… It ends up in the spam folder, which is the idea, isn’t it ?
I’m not sure that this Zero Reputation Domain (ZRD) has anything to do with that. Don’t let the result of the test mislead you : it works.

Still the postfix level filter would be a nice addition, isn’t it @davidep ?

Rspamd is actually already wired into Postfix as a milter. What do you mean by “postfix level filter”?