Our server scans all incoming email for viruses, and blocks any that it finds (SMTP reject, error code 554)
We also use the sanesecurity rules, along with 200+ of our own custom definitions to block spam using the antivirus engine.
These spam messages are treated as a virus because the source almost certainly has a virus infection of some form.
| 79x | Sanesecurity.Junk.38038.UNOFFICIAL |
| 74x | Sanesecurity.Spam.10730.UNOFFICIAL |
| 57x | Sanesecurity.Junk.38655.UNOFFICIAL |
| 50x | Sanesecurity.Junk.38615.UNOFFICIAL |
| 47x | Sanesecurity.Spam.11375.Dom.UNOFFICIAL |
| 44x | Sanesecurity.Junk.39015.UNOFFICIAL |
| 21x | Sanesecurity.Jurlbl.5809.UNOFFICIAL |
| 19x | Sanesecurity.Spam.11569.Ml.UNOFFICIAL |
| 18x | Sanesecurity.Spam.4559.UNOFFICIAL |
| 18x | Sanesecurity.Junk.38865.UNOFFICIAL |
Our server also checks incoming messages against various "DNS block lists", which help to identify spam sources. Any incoming message found to be from a known spam source will be rejected (SMTP reject, error code 553) with a note recommending a visit our DNSBL page for more information
If you find that a message you are trying to send is blocked by our DNSBL checks, please contact us to discuss possibilities; we do have local whitelisting capabilities.
Where a site repeatedly fails this test, they will be temporarily blocked at our firewall in order to save system resources
| 40 | from | 193.253.43.176 |
| 37 | from | 93.155.216.214 |
| 32 | from | 187.79.206.179 |
| 27 | from | 82.238.15.246 |
| 25 | from | 81.184.202.145 |
| 24 | from | 118.96.57.62 |
| 21 | from | 90.184.221.23 |
| 21 | from | 122.167.9.209 |
| 21 | from | 121.187.23.52 |
| 20 | from | 84.123.122.16 |
For clients who collect email directly from our server (ie POP3, not forwarding), we check all messages using spamassassin.
We have developed several custom rules which we prefix with either 'Y_' or 'AAS.' for identification
We also regularly update our test scoring to tag as much spam as possible without tagging non-spam messages.
We generally do not delete messages which spamassassin decides are spam, for the simple reason that it sometimes gets things wrong (false positives)
Some customers have found that our spam rules are accurate and the shear volume of spam they receive is too unwieldy to even attempt to check for false positives manually;
for this reason, we have an email admin facility where customers can opt to file suspected spam into a seperate mailbox and/or directly delete messages.
To cut down on the most spam possible, we use several techniques and programs:
When a particular remote computer/server has sent a vast number of spam messages, or has tried to compromise our server some other way, we will block connections within our firewall. This is reserved for the most drastic cases and is not a measure we take lightly.
Our first main line of defense is to check incoming connections against DNS black lists (see above)
We then check messages using clamav for viruses and known significant spam signatures
For customers who have their email forwarded to another address, this is all we do (with a few exceptions).
For customers who collect directly from our server (POP3) however, we also check messages with spamassassin, including:
several custom rules and custom scoring,
checking the message with Vipul's razor (i.e. cloudmark),
the PDFInfo module to detect spam sent as a pdf attachment,
running OCR software to extract text from images, which is then checked against a black list.The OCR process was using a disproportionate amount of CPU, so it has now been disabled
Each test is assigned a score; if the total score is high enough then the message is tagged to make it easily identifiable and easily filtered.
A large proportion of our customers simply have a filter rule set up to delete all tagged messages, although we do recommend checking the deleted items for incorrectly tagged messages.
If any of our customers' legitimate email is tagged, we will look at ways of rectifying this, including whitelisting specific senders and recipients.
All tagged messages: 988
All razor2 tagged spam: 441