Page 1 of 1

Will sign up SpamHaus Professional improve EFA?

Posted: 12 Feb 2016 00:25
by yeak
Hi All,

I received this email as below. Is it a spam? :lol:

Before deciding to sign up commercial backend (appear to have many things to setup) I need to know if my EFA installation is using SpamHaus. In my postfix main.cf, I am not using SpamHaus. Mine is this,

Code: Select all

smtpd_client_restrictions = permit_sasl_authenticated, check_client_access hash:/etc/postfix/client_access, reject_rbl_client b.barracudacentral.org
In fact I tried not to use barracudacentral also but the amount of spam bots and attempt is astonishing! So at least that reduce some loads. Personally, I think SpamHaus has a lot of false positives...

However in spam.lists.conf file I see the definition of SpamHaus. But it is only a definition. My MailScanner.conf is not enabled to use it,

Code: Select all

Spam List = # spamhaus-ZEN # You can un-comment this to enable them
Anyone got good comments about making EFA more accurate (if you think it is not) by using those commercial service (will it)? Or just buy their box/solution (defeat the purpose of deploying EFA in the first place).

Thanks.


This letter is to formally notify you that you are utilizing the
Spamhaus Datafeed Free Service and has come to our attention that you do
not comply within the free usage terms of the datafeed service.

The following devices have been flagged by our system.

##.##.##.## xxx.xxx.xxx

The use of the Spamhaus DNSBLs by organizations and networks with email
traffic likely to exceed the Free Use limits, or by ISPs or commercial
spam filter services, requires a subscription to the Spamhaus DNSBL
Datafeed service designed for users with professional DNSBL
requirements.

Use of the Spamhaus DNSBLs via DNS queries to our public DNSBL servers
is free of charge if you meet all three of the following criteria:

1) Your use of the Spamhaus DNSBLs is non-commercial*,
and
2) Your email traffic is less than 100,000 SMTP connections
per day, and
3) Your DNSBL query volume is less than 300,000 queries
per day.

If you do not fit all three of these criteria then please do not use our
public DNSBL servers, instead see 'Professional Use'.

SpamHaus Datafeed service pricing is based on the organization type,
data filter type, and the total

number of users and would like to arrange a meeting with you and your
technical team to discuss

correct sizing for your organization. Non-response will result in
immediate termination of service

and may cause disruption to your network and services provided to your
users. If your payment has

already been sent to Spamhaus, please disregard this letter. However, if
you have not yet made

payment, kindly reply back by filling out the enclosed form or via email
at info@mxtools.com

immediately. We Value you as a customer and we look forward to hearing
from you.

For further reference with please follow the link below:

https://www.spamhaus.org/organization/dnsblusage/

As always, if you have any questions or concerns, please feel free to
contact us at
+81-3-5539-4377 or send us an email to info@mxtools.com.

Re: Will sign up SpamHaus Professional improve EFA?

Posted: 13 Feb 2016 10:52
by shawniverson
You can usually avoid this situation by enabling unbound to do full recursive dns.

What this does is cache the responses from DNSBLs and greatly reduce the number of queries hitting this service.

Looks like spamassassin, via KAM.cf, may be using SpamHaus...
KAM.cf: meta KAM_VERY_BLACK_DBL (URIBL_BLACK && URIBL_DBL_SPAM)
KAM.cf: describe KAM_VERY_BLACK_DBL Email that hits both URIBL Black and Spamhaus DBL
KAM.cf: score KAM_VERY_BLACK_DBL 5.0