Search found 69 matches: fraud

Searched query: fraud

by gregecslo
06 Nov 2024 13:32
Forum: 5.x Bugs
Topic: eFa v5 bayes behaviour
Replies: 18
Views: 225650

Re: eFa v5 bayes behaviour

... DOS_BODY_MON,__DOS_BODY_TUE,__DOS_BODY_WED,__DOS_HAS_ANY_URI,__DOS_LINK,__DOS_RCVD_WED,__DOS_REF_TODAY,__E_LIKE_LETTER(320),__FILL_THIS_FORM_FRAUD_PHISH1,__FROM_FULL_NAME,__FROM_WORDY,__GB_FAKE_RF,__GB_TO_ADDR,__HAS_ANY_EMAIL,__HAS_ANY_URI,__HAS_DATE,__HAS_DKIM_SIGHD,__HAS_FROM,__HAS_HREF(23 ...
by rightvision
09 May 2023 07:59
Forum: Feature Requests
Topic: MailScanner link warning
Replies: 1
Views: 16337

MailScanner link warning

Highlight Phishing Fraud = yes, Highlight Hidden URLs = yes and Highlight Mailto Phishing = yes makes most of newsletters or orderconfirmations unreadable for the user as there are many links inside.

Is it possible to just add ONE notification at the beginning of the message like "Careful ...
by pdwalker
09 Aug 2022 07:38
Forum: How-to
Topic: MailScanner mailto: false positives
Replies: 3
Views: 3970

Re: MailScanner mailto: false positives


Hi,

I am getting false positives with bad URL for mailto: address links. An example:

MailScanner has detected a possible fraud attempt from "domain.com" claiming to be mailto:user@domain.com

The following was added to /etc/MailScanner/phishing.safe.sites.conf:

mailto:*
*.domain.com

This did ...
by max_of_tl
13 Jul 2022 15:20
Forum: How-to
Topic: MailScanner mailto: false positives
Replies: 3
Views: 3970

MailScanner mailto: false positives

Hi,

I am getting false positives with bad URL for mailto: address links. An example:

MailScanner has detected a possible fraud attempt from "domain.com" claiming to be mailto:user@domain.com

The following was added to /etc/MailScanner/phishing.safe.sites.conf:

mailto:*
*.domain.com

This did not ...
by EnricoGTT
03 Feb 2021 08:16
Forum: 4.x Bugs
Topic: After Migration from EFA 3 can't import sa-learn.
Replies: 6
Views: 4648

Re: After Migration from EFA 3 can't import sa-learn.

... SPRM
Feb 4 11:37:25.315 [1430036] dbg: replacetags: replaced __YOUR_WEBCAM
Feb 4 11:37:25.316 [1430036] dbg: replacetags: replaced __FILL_THIS_FORM_FRAUD_PHISH1
Feb 4 11:37:25.331 [1430036] dbg: replacetags: replaced __PAY_ME
Feb 4 11:37:25.332 [1430036] dbg: replacetags: replaced SUBJECT_FUZZY_PENIS ...
by e-d-i-t
12 Jun 2020 13:27
Forum: How-to
Topic: Using header_checks to remove bSMTP service provider
Replies: 8
Views: 5751

Re: Using header_checks to remove bSMTP service provider

... postfix/smtpd[32244]: disconnect from unknown[192.168.10.50] ehlo=1 quit=1 commands=2
Jun 12 15:06:35 mailgtw MailScanner[32437]: Found phishing fraud from https://www.covidopstart.nl/c-19/nl-NL/home?utm_source=handtekening&utm_medium=e-mail&utm_campaign=veenman claiming to be www.veenman.nl in ...
by bikertrash
16 Feb 2020 16:08
Forum: Discussion
Topic: Outgoing Signature content flagged as "possible fraud"
Replies: 0
Views: 4872

Outgoing Signature content flagged as "possible fraud"

... contains embedded URL's, one for my email address and the other to my web site. These are both getting flagged in my outbound as "potential fraud" and showing to the recipients as such.

I tried adding my domain into "phishing.safe.sites.conf" but they still get flagged... stopped and restart ...
by shawniverson
10 Feb 2020 16:21
Forum: Discussion
Topic: How to get rid of fraud from field "From"
Replies: 1
Views: 2877

Re: How to get rid of fraud from field "From"

Checkout the "Highlight Phishing Fraud" option in /etc/MailScanner/MailScanner.conf
by BarkingMail
10 Feb 2020 09:11
Forum: Discussion
Topic: How to get rid of fraud from field "From"
Replies: 1
Views: 2877

How to get rid of fraud from field "From"

eFA 4.0.1:
In the field "From" usually when there is a "thread", mailscanner detects fraud attempt.
How can I get rid of it? -

"...From: Sender Name [MailScanner has detected a possible fraud attempt from "domain.com" claiming to be mailto:name@domain.com]

Note.: sometime, it shows also even if ...
by mailfuntimes
03 Feb 2020 14:55
Forum: How-to
Topic: Outlook calendar invites broken
Replies: 4
Views: 12604

Outlook calendar invites broken

... dir%/toexternal_contentscanning.rules
Allow Partial Messages = no
Allow External Message Bodies = %rules-dir%/toexternal_bodies.rules
Find Phishing Fraud = yes
Also Find Numeric Phishing = %etc-dir%/numeric.phishing.rules
Use Stricter Phishing Net = yes
Highlight Phishing Fraud = yes
Highlight Hidden ...
by xprofetax
17 Nov 2019 16:02
Forum: How-to
Topic: Rewrite URLs for inbound mail
Replies: 6
Views: 4818

Re: Rewrite URLs for inbound mail

... MTA based solutions, for several reasons that i will not list here.
Since mailscanner already does something similar (more or less) with "phishing fraud detection", where URLs got analyzed and plain text eventually added to mail, i thought that an higher level solution than postfix based rewrite ...
by skoppes
03 May 2019 20:53
Forum: 3.x Bugs
Topic: RESOLVED: Missing Child Domain in From: Report Fields
Replies: 6
Views: 13335

Re: Missing Child Domain in From: Report Fields

I must re-visit this issue, because it has become a problem with the insane amount of scam/fraud messages coming through.

I took a deeper look and have determined that the web interface is working properly. The information has been populated incorrectly into the maillog table in the mailscanner ...
by omarioja
29 Jan 2019 16:45
Forum: Discussion
Topic: possible fraud attempt
Replies: 1
Views: 3336

Re: possible fraud attempt

by omarioja
29 Jan 2019 16:34
Forum: Discussion
Topic: possible fraud attempt
Replies: 1
Views: 3336

possible fraud attempt

Good day all, i am getting this notification at the bottom of my email "Mailscanner has detected a possible fraud attempt from "<my local ip address>" any ideas
by ovizii
22 Nov 2018 13:05
Forum: How-to
Topic: How to use phishing.safe.sites.custom ?
Replies: 4
Views: 7316

How to use phishing.safe.sites.custom ?

... in here to mitigate the problem that the global "bad" list lists onedrive.live.com and play.google.com by listing them inside phishing.safe.sites.custom - and yet even after restarting Mailscanner, these lists still get marked as phishing fraud.

Did anyone succeed and can explain how this works?
by paulo88
09 Nov 2018 07:39
Forum: 3.x Bugs
Topic: Defective entries in phishing.bad.sites.conf
Replies: 3
Views: 7136

Re: Defective entries in phishing.bad.sites.conf

Thank you, that fixed these faulty entries.
Now these FQDNs are correctly marked as definitive fraud.

Thanks for the fast fix.
by paulo88
08 Nov 2018 11:11
Forum: 3.x Bugs
Topic: Defective entries in phishing.bad.sites.conf
Replies: 3
Views: 7136

Defective entries in phishing.bad.sites.conf

... entries go like this:
bad.url.com

But some have ",http:" attached:
bad.url.com,http:

This seems to make the entry invalid as the definitive fraud is not correctly marked as such.
It is only marked as possible fraud, but when it is in this file it should be definitive.

Even the current online ...
by benscha
24 Jan 2018 08:40
Forum: 3.x Bugs
Topic: Release Mail from Quarantine
Replies: 1
Views: 26623

Release Mail from Quarantine

... Dangerous Content Scanning /etc/MailScanner/rules/content.scanning.rules
Allow Partial Messages no
Allow External Message Bodies no
Find Phishing Fraud yes
Also Find Numeric Phishing yes
Use Stricter Phishing Net yes
Highlight Phishing Fraud yes
Phishing Safe Sites File /etc/MailScanner/phishing ...
by ovizii
27 Nov 2017 10:16
Forum: Discussion
Topic: Spam getting through with spamassasin score of 0.00
Replies: 6
Views: 7386

Re: Spam getting through with spamassasin score of 0.00

... outlook client https://www.extendoffice.com/documents/outlook/1346-outlook-attachment-in-body-of-email.html)
c) Mailscanner detected a possible fraud: please check these docs and then adapt your Mailscanner config:
https://www.mailscanner.info/MailScanner.conf.index.html#Find Phishing Fraud ...
by shawniverson
14 Oct 2017 12:05
Forum: 3.x Bugs
Topic: Some messages are being "defaced"
Replies: 6
Views: 7080

Re: Some messages are being "defaced"

/etc/MailScanner/MailScanner.conf

Code: Select all

# If a phishing fraud is detected, do you want to highlight the tag with
# a message stating that the link may be to a fraudulent web site.
# This can also be the filename of a ruleeset.
Highlight Phishing Fraud = no
by budy
13 Oct 2017 14:47
Forum: 3.x Bugs
Topic: Some messages are being "defaced"
Replies: 6
Views: 7080

Re: Some messages are being "defaced"

... has moved into a suspended state until the card is updated or the issue is fixed. You’ll want to head over to MailScanner has detected a possible fraud attempt from "via.intercom-mail-200.com" claiming to be moz.com/billing to update those card details!

I have also appended a little screenshot…
by bostjanc
28 Jun 2017 18:24
Forum: Discussion
Topic: MailScanner - fraud detection - turning it off
Replies: 4
Views: 7354

Re: MailScanner - fraud detection - turning it off

Hi swaniverson.
1st of all thank you for your reply.
I had that setting "Use Stricer Phishing Net" already set on NO.
I have just figured out where I had made "a noobish mistake".
Before editing /etc/MailScanner/MailScanner.conf I made a dumb copy:
cp /etc/MailScanner/MailScanner.conf /etc ...
by shawniverson
28 Jun 2017 17:29
Forum: Discussion
Topic: MailScanner - fraud detection - turning it off
Replies: 4
Views: 7354

Re: MailScanner - fraud detection - turning it off

Here's another setting, tried this one?

Code: Select all

Use Stricter Phishing Net = yes
by bostjanc
28 Jun 2017 12:24
Forum: Discussion
Topic: MailScanner - fraud detection - turning it off
Replies: 4
Views: 7354

Re: MailScanner - fraud detection - turning it off

service mailscanner reload also does not change this behavour, hm ran out of ideas...
We are on latest 3.0.2.3 version. Is it a bug?
by bostjanc
28 Jun 2017 12:13
Forum: Discussion
Topic: MailScanner - fraud detection - turning it off
Replies: 4
Views: 7354

Re: MailScanner - fraud detection - turning it off

Another thing, if I change also this settings in MailScanner.conf:
(from yes to no): Highlight Phishing Fraud = no
it does not reflect, because it's still higlights it, even after doing service mailscanner restart.
strange.