Page 1 of 1

More Spam Since Upgrade - Poss Fix

Posted: 10 Nov 2015 13:24
by sharktech
Afternoon all

Since upgrading to v8, I've been getting spam coming from genuine companies. it ranges from 10-100 emails and will continue until i blacklist the domain even after reporting it.

As most of these companies dont use spf and other than blacklisting the domain is there anything else i can do?

Thanks

Re: More Spam Since Upgrade - Poss Fix

Posted: 10 Nov 2015 23:00
by shawniverson
Can you share an example spam report for us to help you with?

Re: More Spam Since Upgrade - Poss Fix

Posted: 16 Nov 2015 09:53
by sharktech
shawn

do you want the headers:

Received: from [139.190.21.129] (unknown [139.190.21.129])
by spam.domain.co.uk (Postfix) with ESMTP id E5A9BE005A
for <collection@domain.co.uk>; Tue, 10 Nov 2015 12:05:06 +0000 (GMT)
From: no-reply@clicktravel.com
To: collection@domain.co.uk
Message-ID: <0000014fd65010c3-86e5bc1d-b2fe-4448-aa1d-1e6b9e107de7-000000@email.amazonses.com>
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_Part_13300_1343575795.1442409615092"
Date: Tue, 10 Nov 2015 17:05:04 +0500
Subject: Itinerary #C003NS39

Received: from [2.50.51.110] (unknown [2.50.51.110])
by spam.domain.co.uk (Postfix) with ESMTP id C887BE28E4
for <paul@domain.co.uk>; Mon, 26 Oct 2015 14:01:18 +0000 (GMT)
MIME-Version: 1.0
From: "PHSOnline" <documents@phsonline.co.uk>
To: paul@domain.co.uk
Date: Mon, 26 Oct 2015 18:01:17 +0400
Subject: Your new PHS documents are attached
Content-Type: multipart/mixed;
boundary=--boundary_743_ffcb55fe-3ded-4a8e-a6ae-31e5484914ae
Message-ID: <auto-707021279383@domain.co.uk>
Envelope-To: <paul@domain.co.uk>

Re: More Spam Since Upgrade - Poss Fix

Posted: 18 Nov 2015 15:49
by shawniverson
Actually also the Spam Report when you open the messages...

i.e.

-1.90 BAYES_00 Bayes spam probability is 0 to 1%
0.00 HTML_MESSAGE HTML included in message
1.00 ImageCerberusPLG1
-0.70 RCVD_IN_DNSWL_LOW Sender listed at http://www.dnswl.org/, low trust
-0.01 RCVD_IN_MSPIKE_H3 Good reputation (+3)
-0.01 RCVD_IN_MSPIKE_WL Mailspike good senders
0.67 SPF_SOFTFAIL SPF: sender does not match SPF record (softfail)