Re: Need advice on new mailserver and spam

From: Paul Howarth (paul_at_city-fan.org)
Date: 06/06/05

  • Next message: Phillip T. George: "Re: create a restricted user"
    Date: Mon, 06 Jun 2005 16:33:09 +0100
    To: For users of Fedora Core releases <fedora-list@redhat.com>
    
    

    Bob Brennan wrote:
    > I've been called in to solve some massive email problems in a company
    > that has about 30 employees and an external mailserver. They receive
    > on average about 100 legitimate emails per day and 3000+ spams plus
    > the usual virus and worm attacks.
    >
    > I am of course recommending FC with Sendmail, Procmail, SpamAssasin
    > and ClamAV on an inhouse mailserver, all of which I've had experience
    > and spectacular results with.
    >
    > Their spam problem, IMHO, comes from the mailserver they currently use
    > accepting all non-mailbox email into a postmaster@domain.com account
    > which has a quota of 1000 emails, which then sends over-quota
    > rejection notices to senders for all @domain.com incoming; effectively
    > shutting down all incoming email. My theory is that the reject notices
    > are taken as replies by spambots and encourages even more spam.
    > Short-term measures include emptying postmaster@ every 10 minutes and
    > filtering for valid mis-addressed emails, but even with that the
    > volume of incoming spam seriously slows down the service.
    >
    > My question is - long term - is it better to set up the mailserver to
    > reject all non-mailbox emails to cut down on the incoming processing
    > load; or to filter and bit-bucket the spam in the hopes that the
    > volume will decrease over time with no responses to the spam? Or any
    > other techniques any of you are using for such problems?
    >
    > Thanks in advance for opinions/suggestions,

    I would definitely advocate not having a catch-all mailbox, which I
    guess is what you mean by non-mailbox mail. It's a magnet for spammers
    doing dictionary attacks, and they do do this as I've seen it on my own
    server.

    Any rejections should of course be done at SMTP level rather than doing
    an accept-then-bounce arrangement, which only results in backscatter and
    actually contributing even further to the Internet-wide spam problem.

    Paul.

    I predict with 99% certainly that Scott H. will advise you to use
    greylisting too :-)

    -- 
    fedora-list mailing list
    fedora-list@redhat.com
    To unsubscribe: http://www.redhat.com/mailman/listinfo/fedora-list
    

  • Next message: Phillip T. George: "Re: create a restricted user"

    Relevant Pages

    • Re: Need advice on new mailserver and spam
      ... On Mon, 2005-06-06 at 11:22, Bob Brennan wrote: ... > that has about 30 employees and an external mailserver. ... > shutting down all incoming email. ... > are taken as replies by spambots and encourages even more spam. ...
      (Fedora)
    • Need advice on new mailserver and spam
      ... that has about 30 employees and an external mailserver. ... on average about 100 legitimate emails per day and 3000+ spams plus ... Their spam problem, IMHO, comes from the mailserver they currently use ... shutting down all incoming email. ...
      (Fedora)
    • [Full-Disclosure] [BU-NOSPAM] FYI: Visa abuse - equal to PayPal abuse
      ... Spam detection software, running on the system "chex.decru.com", has ... our site and applying for our Zero Liability program. ... communications to and from the Julius Baer Group may be monitored. ... Processing of incoming e-mails cannot be guaranteed. ...
      (Full-Disclosure)
    • [Full-Disclosure] FYI: Visa abuse - equal to PayPal abuse
      ... Spam detection software, running on the system "chex.decru.com", has ... The original message was not completely plain text, ... communications to and from the Julius Baer Group may be monitored. ... Processing of incoming e-mails cannot be guaranteed. ...
      (Full-Disclosure)
    • Re: SNORT: MAC Address Alert
      ... > of computers are gaining access to our network and picking arbitrary IP ... > addresses to send SPAM emails. ... own mail server and they are using that mailserver to send SPAM through ...
      (Focus-IDS)