考虑以下收到的垃圾邮件,其中收件人的地址与发件人的地址相同,但这个用户没有给他们发送自己的电子邮件,这是垃圾邮件;
(为了隐私起见,所有主机名和IP都已更改):
Return-Path: <someuser@lala.net>
X-Original-To: realuser_realdomain.com@vmail.mailplatform.com
Delivered-To: realuser_realdomain.com@vmail.mailplatform.com
Received: from mx1.mailplatform.net (mx1.mailplatform.net [1.2.3.47])
by mx1.mailplatform.net (Postfix) with ESMTP id 9F7DB8406E6;
Thu, 21 Jun 2012 08:11:54 +0100 (BST)
Received: from localhost (localhost [127.0.0.1])
by mx1.mailplatform.net (Postfix) with ESMTP id 66B6C27C6D1;
Thu, 21 Jun 2012 08:11:54 +0100 (BST)
X-Virus-Scanned: by Mailplatform Anti-Virus
Received: from mx1.mailplatform.net ([1.2.3.47])
by localhost (mx1.mailplatform.net [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id rOsEgrThepcJ; Thu, 21 Jun 2012 08:11:52 +0100 (BST)
Received: from dialup.user.some.isp.net (dialup.user.some.isp.net [5.5.5.5])
by mx1.mailplatform.net (Postfix) with ESMTP id 3AA3127C6C1;
Thu, 21 Jun 2012 08:11:51 +0100 (BST)
Message-ID: <4FE2D446.301090@realdomain.com>
Date: Thu, 21 Jun 2012 08:11:51 +0100
From: <allusers@realdomain.com>,
<realuser@realdomain.com>,
<realuser2@readldomain.com>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en; rv:1.9.2.12) Gecko/20101027 Thunderbird/3.1.6
MIME-Version: 1.0
To: <allusers@realdomain.com>,
<realuser@realdomain.com>,
<realuser2@realdomain.com>
Subject: Vacancy - apply online
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
X-Antivirus: avast! (VPS 120621-0, 21/06/2012), Inbound message
X-Antivirus-Status: Clean正如我们在这里看到的,电子邮件最初是由拨号用户提交给MX主机mx1的(正如反向PTR记录所表明的,所以垃圾邮件就在那里!)我无法理解的是为什么postfix没有做SPF查找,看到发送者不是此域的授权源(realdomain.com),并相应地调整评分。mx1是最终用户域"realdomain.com“的发送和接收主机。这是在后缀日志中;
Jun 21 08:11:51 mx1 meta-greylist[4080]: 5.5.5.5:dialup.user.some.isp.net is not in DB
Jun 21 08:11:51 mx1 meta-greylist[4080]: has_A_or_MX (A): dialup.user.some.isp.net RR A
Jun 21 08:11:52 mx1 meta-greylist[4080]: SPF result neutral/Please see http://www.openspf.org/why.html?sender=someuser@lala.net&ip=5.5.5.5&receiver=mx1.mailplatform.net
Jun 21 08:11:52 mx1 meta-greylist[4080]: suspect level 0
Jun 21 08:11:52 mx1 meta-greylist[4080]: 5.5.5.5:dialup.user.some.isp.net:lala.net set to whitelisted
Jun 21 08:11:52 mx1 meta-greylist[4080]: action=DUNNO
Jun 21 08:11:52 mx1 postfix/smtpd[3800]: 3AA3127C6C1: client=dialup.user.some.isp.net[5.5.5.5]
Jun 21 08:11:52 mx1 postfix/trivial-rewrite[3934]: warning: do not list domain readldomain.com in BOTH virtual_alias_domains and relay_domains抱歉,如果这听起来很荒谬,我才刚开始做后缀。如果我没有发布一些我显然应该拥有的东西(例如,一段日志),请告诉我,我会的。谢谢。
编辑更新:我想说的是,这是否通过了,因为发送用户使用了“someuser@lala.net”作为返回路径值,该值在某种程度上抛弃了后缀/amavis/spamassassin?
发布于 2012-06-21 13:08:53
对一个人来说,后缀不是一个垃圾邮件检测工具。这是一个MTA。因此,您需要运行一些软件与后缀,如垃圾邮件刺客检查。此外,后缀不会自动检查spf,这是您必须启用的其他东西,比如在ubuntu中的postfix-policyd-spf-perl。然后,您必须配置后缀以使用它进行检查。
https://serverfault.com/questions/400935
复制相似问题