Search found 69 matches: fraud
Searched query: fraud
- 06 Nov 2024 13:32
- Forum: 5.x Bugs
- Topic: eFa v5 bayes behaviour
- Replies: 18
- Views: 225650
Re: eFa v5 bayes behaviour
... DOS_BODY_MON,__DOS_BODY_TUE,__DOS_BODY_WED,__DOS_HAS_ANY_URI,__DOS_LINK,__DOS_RCVD_WED,__DOS_REF_TODAY,__E_LIKE_LETTER(320),__FILL_THIS_FORM_FRAUD_PHISH1,__FROM_FULL_NAME,__FROM_WORDY,__GB_FAKE_RF,__GB_TO_ADDR,__HAS_ANY_EMAIL,__HAS_ANY_URI,__HAS_DATE,__HAS_DKIM_SIGHD,__HAS_FROM,__HAS_HREF(23 ...
- 09 May 2023 07:59
- Forum: Feature Requests
- Topic: MailScanner link warning
- Replies: 1
- Views: 16337
MailScanner link warning
Highlight Phishing Fraud = yes, Highlight Hidden URLs = yes and Highlight Mailto Phishing = yes makes most of newsletters or orderconfirmations unreadable for the user as there are many links inside.
Is it possible to just add ONE notification at the beginning of the message like "Careful ...
Is it possible to just add ONE notification at the beginning of the message like "Careful ...
- 09 Aug 2022 07:38
- Forum: How-to
- Topic: MailScanner mailto: false positives
- Replies: 3
- Views: 3970
Re: MailScanner mailto: false positives
Hi,
I am getting false positives with bad URL for mailto: address links. An example:
MailScanner has detected a possible fraud attempt from "domain.com" claiming to be mailto:user@domain.com
The following was added to /etc/MailScanner/phishing.safe.sites.conf:
mailto:*
*.domain.com
This did ...
- 13 Jul 2022 15:20
- Forum: How-to
- Topic: MailScanner mailto: false positives
- Replies: 3
- Views: 3970
MailScanner mailto: false positives
Hi,
I am getting false positives with bad URL for mailto: address links. An example:
MailScanner has detected a possible fraud attempt from "domain.com" claiming to be mailto:user@domain.com
The following was added to /etc/MailScanner/phishing.safe.sites.conf:
mailto:*
*.domain.com
This did not ...
I am getting false positives with bad URL for mailto: address links. An example:
MailScanner has detected a possible fraud attempt from "domain.com" claiming to be mailto:user@domain.com
The following was added to /etc/MailScanner/phishing.safe.sites.conf:
mailto:*
*.domain.com
This did not ...
- 03 Feb 2021 08:16
- Forum: 4.x Bugs
- Topic: After Migration from EFA 3 can't import sa-learn.
- Replies: 6
- Views: 4648
Re: After Migration from EFA 3 can't import sa-learn.
... SPRM
Feb 4 11:37:25.315 [1430036] dbg: replacetags: replaced __YOUR_WEBCAM
Feb 4 11:37:25.316 [1430036] dbg: replacetags: replaced __FILL_THIS_FORM_FRAUD_PHISH1
Feb 4 11:37:25.331 [1430036] dbg: replacetags: replaced __PAY_ME
Feb 4 11:37:25.332 [1430036] dbg: replacetags: replaced SUBJECT_FUZZY_PENIS ...
Feb 4 11:37:25.315 [1430036] dbg: replacetags: replaced __YOUR_WEBCAM
Feb 4 11:37:25.316 [1430036] dbg: replacetags: replaced __FILL_THIS_FORM_FRAUD_PHISH1
Feb 4 11:37:25.331 [1430036] dbg: replacetags: replaced __PAY_ME
Feb 4 11:37:25.332 [1430036] dbg: replacetags: replaced SUBJECT_FUZZY_PENIS ...
- 12 Jun 2020 13:27
- Forum: How-to
- Topic: Using header_checks to remove bSMTP service provider
- Replies: 8
- Views: 5751
Re: Using header_checks to remove bSMTP service provider
... postfix/smtpd[32244]: disconnect from unknown[192.168.10.50] ehlo=1 quit=1 commands=2
Jun 12 15:06:35 mailgtw MailScanner[32437]: Found phishing fraud from https://www.covidopstart.nl/c-19/nl-NL/home?utm_source=handtekening&utm_medium=e-mail&utm_campaign=veenman claiming to be www.veenman.nl in ...
Jun 12 15:06:35 mailgtw MailScanner[32437]: Found phishing fraud from https://www.covidopstart.nl/c-19/nl-NL/home?utm_source=handtekening&utm_medium=e-mail&utm_campaign=veenman claiming to be www.veenman.nl in ...
- 16 Feb 2020 16:08
- Forum: Discussion
- Topic: Outgoing Signature content flagged as "possible fraud"
- Replies: 0
- Views: 4872
Outgoing Signature content flagged as "possible fraud"
... contains embedded URL's, one for my email address and the other to my web site. These are both getting flagged in my outbound as "potential fraud" and showing to the recipients as such.
I tried adding my domain into "phishing.safe.sites.conf" but they still get flagged... stopped and restart ...
I tried adding my domain into "phishing.safe.sites.conf" but they still get flagged... stopped and restart ...
- 10 Feb 2020 16:21
- Forum: Discussion
- Topic: How to get rid of fraud from field "From"
- Replies: 1
- Views: 2877
Re: How to get rid of fraud from field "From"
Checkout the "Highlight Phishing Fraud" option in /etc/MailScanner/MailScanner.conf
- 10 Feb 2020 09:11
- Forum: Discussion
- Topic: How to get rid of fraud from field "From"
- Replies: 1
- Views: 2877
How to get rid of fraud from field "From"
eFA 4.0.1:
In the field "From" usually when there is a "thread", mailscanner detects fraud attempt.
How can I get rid of it? -
"...From: Sender Name [MailScanner has detected a possible fraud attempt from "domain.com" claiming to be mailto:name@domain.com]
Note.: sometime, it shows also even if ...
In the field "From" usually when there is a "thread", mailscanner detects fraud attempt.
How can I get rid of it? -
"...From: Sender Name [MailScanner has detected a possible fraud attempt from "domain.com" claiming to be mailto:name@domain.com]
Note.: sometime, it shows also even if ...
- 03 Feb 2020 14:55
- Forum: How-to
- Topic: Outlook calendar invites broken
- Replies: 4
- Views: 12604
Outlook calendar invites broken
... dir%/toexternal_contentscanning.rules
Allow Partial Messages = no
Allow External Message Bodies = %rules-dir%/toexternal_bodies.rules
Find Phishing Fraud = yes
Also Find Numeric Phishing = %etc-dir%/numeric.phishing.rules
Use Stricter Phishing Net = yes
Highlight Phishing Fraud = yes
Highlight Hidden ...
Allow Partial Messages = no
Allow External Message Bodies = %rules-dir%/toexternal_bodies.rules
Find Phishing Fraud = yes
Also Find Numeric Phishing = %etc-dir%/numeric.phishing.rules
Use Stricter Phishing Net = yes
Highlight Phishing Fraud = yes
Highlight Hidden ...
- 17 Nov 2019 16:02
- Forum: How-to
- Topic: Rewrite URLs for inbound mail
- Replies: 6
- Views: 4818
Re: Rewrite URLs for inbound mail
... MTA based solutions, for several reasons that i will not list here.
Since mailscanner already does something similar (more or less) with "phishing fraud detection", where URLs got analyzed and plain text eventually added to mail, i thought that an higher level solution than postfix based rewrite ...
Since mailscanner already does something similar (more or less) with "phishing fraud detection", where URLs got analyzed and plain text eventually added to mail, i thought that an higher level solution than postfix based rewrite ...
- 03 May 2019 20:53
- Forum: 3.x Bugs
- Topic: RESOLVED: Missing Child Domain in From: Report Fields
- Replies: 6
- Views: 13335
Re: Missing Child Domain in From: Report Fields
I must re-visit this issue, because it has become a problem with the insane amount of scam/fraud messages coming through.
I took a deeper look and have determined that the web interface is working properly. The information has been populated incorrectly into the maillog table in the mailscanner ...
I took a deeper look and have determined that the web interface is working properly. The information has been populated incorrectly into the maillog table in the mailscanner ...
- 29 Jan 2019 16:45
- Forum: Discussion
- Topic: possible fraud attempt
- Replies: 1
- Views: 3336
Re: possible fraud attempt
Found the solution / viewtopic.php?f=14&t=530&hilit=fraud
- 29 Jan 2019 16:34
- Forum: Discussion
- Topic: possible fraud attempt
- Replies: 1
- Views: 3336
possible fraud attempt
Good day all, i am getting this notification at the bottom of my email "Mailscanner has detected a possible fraud attempt from "<my local ip address>" any ideas
- 22 Nov 2018 13:05
- Forum: How-to
- Topic: How to use phishing.safe.sites.custom ?
- Replies: 4
- Views: 7316
How to use phishing.safe.sites.custom ?
... in here to mitigate the problem that the global "bad" list lists onedrive.live.com and play.google.com by listing them inside phishing.safe.sites.custom - and yet even after restarting Mailscanner, these lists still get marked as phishing fraud.
Did anyone succeed and can explain how this works?
Did anyone succeed and can explain how this works?
- 09 Nov 2018 07:39
- Forum: 3.x Bugs
- Topic: Defective entries in phishing.bad.sites.conf
- Replies: 3
- Views: 7136
Re: Defective entries in phishing.bad.sites.conf
Thank you, that fixed these faulty entries.
Now these FQDNs are correctly marked as definitive fraud.
Thanks for the fast fix.
Now these FQDNs are correctly marked as definitive fraud.
Thanks for the fast fix.
- 08 Nov 2018 11:11
- Forum: 3.x Bugs
- Topic: Defective entries in phishing.bad.sites.conf
- Replies: 3
- Views: 7136
Defective entries in phishing.bad.sites.conf
... entries go like this:
bad.url.com
But some have ",http:" attached:
bad.url.com,http:
This seems to make the entry invalid as the definitive fraud is not correctly marked as such.
It is only marked as possible fraud, but when it is in this file it should be definitive.
Even the current online ...
bad.url.com
But some have ",http:" attached:
bad.url.com,http:
This seems to make the entry invalid as the definitive fraud is not correctly marked as such.
It is only marked as possible fraud, but when it is in this file it should be definitive.
Even the current online ...
- 24 Jan 2018 08:40
- Forum: 3.x Bugs
- Topic: Release Mail from Quarantine
- Replies: 1
- Views: 26623
Release Mail from Quarantine
... Dangerous Content Scanning /etc/MailScanner/rules/content.scanning.rules
Allow Partial Messages no
Allow External Message Bodies no
Find Phishing Fraud yes
Also Find Numeric Phishing yes
Use Stricter Phishing Net yes
Highlight Phishing Fraud yes
Phishing Safe Sites File /etc/MailScanner/phishing ...
Allow Partial Messages no
Allow External Message Bodies no
Find Phishing Fraud yes
Also Find Numeric Phishing yes
Use Stricter Phishing Net yes
Highlight Phishing Fraud yes
Phishing Safe Sites File /etc/MailScanner/phishing ...
- 27 Nov 2017 10:16
- Forum: Discussion
- Topic: Spam getting through with spamassasin score of 0.00
- Replies: 6
- Views: 7386
Re: Spam getting through with spamassasin score of 0.00
... outlook client https://www.extendoffice.com/documents/outlook/1346-outlook-attachment-in-body-of-email.html)
c) Mailscanner detected a possible fraud: please check these docs and then adapt your Mailscanner config:
https://www.mailscanner.info/MailScanner.conf.index.html#Find Phishing Fraud ...
c) Mailscanner detected a possible fraud: please check these docs and then adapt your Mailscanner config:
https://www.mailscanner.info/MailScanner.conf.index.html#Find Phishing Fraud ...
- 14 Oct 2017 12:05
- Forum: 3.x Bugs
- Topic: Some messages are being "defaced"
- Replies: 6
- Views: 7080
Re: Some messages are being "defaced"
/etc/MailScanner/MailScanner.conf
Code: Select all
# If a phishing fraud is detected, do you want to highlight the tag with
# a message stating that the link may be to a fraudulent web site.
# This can also be the filename of a ruleeset.
Highlight Phishing Fraud = no
- 13 Oct 2017 14:47
- Forum: 3.x Bugs
- Topic: Some messages are being "defaced"
- Replies: 6
- Views: 7080
Re: Some messages are being "defaced"
... has moved into a suspended state until the card is updated or the issue is fixed. You’ll want to head over to MailScanner has detected a possible fraud attempt from "via.intercom-mail-200.com" claiming to be moz.com/billing to update those card details!
I have also appended a little screenshot…
I have also appended a little screenshot…
- 28 Jun 2017 18:24
- Forum: Discussion
- Topic: MailScanner - fraud detection - turning it off
- Replies: 4
- Views: 7354
Re: MailScanner - fraud detection - turning it off
Hi swaniverson.
1st of all thank you for your reply.
I had that setting "Use Stricer Phishing Net" already set on NO.
I have just figured out where I had made "a noobish mistake".
Before editing /etc/MailScanner/MailScanner.conf I made a dumb copy:
cp /etc/MailScanner/MailScanner.conf /etc ...
1st of all thank you for your reply.
I had that setting "Use Stricer Phishing Net" already set on NO.
I have just figured out where I had made "a noobish mistake".
Before editing /etc/MailScanner/MailScanner.conf I made a dumb copy:
cp /etc/MailScanner/MailScanner.conf /etc ...
- 28 Jun 2017 17:29
- Forum: Discussion
- Topic: MailScanner - fraud detection - turning it off
- Replies: 4
- Views: 7354
Re: MailScanner - fraud detection - turning it off
Here's another setting, tried this one?
Code: Select all
Use Stricter Phishing Net = yes
- 28 Jun 2017 12:24
- Forum: Discussion
- Topic: MailScanner - fraud detection - turning it off
- Replies: 4
- Views: 7354
Re: MailScanner - fraud detection - turning it off
service mailscanner reload also does not change this behavour, hm ran out of ideas...
We are on latest 3.0.2.3 version. Is it a bug?
We are on latest 3.0.2.3 version. Is it a bug?
- 28 Jun 2017 12:13
- Forum: Discussion
- Topic: MailScanner - fraud detection - turning it off
- Replies: 4
- Views: 7354
Re: MailScanner - fraud detection - turning it off
Another thing, if I change also this settings in MailScanner.conf:
(from yes to no): Highlight Phishing Fraud = no
it does not reflect, because it's still higlights it, even after doing service mailscanner restart.
strange.
(from yes to no): Highlight Phishing Fraud = no
it does not reflect, because it's still higlights it, even after doing service mailscanner restart.
strange.