thank you for answering even though the que4stion was not sieve related.
mymiab.net was just a place holder for the actual domain name as i
wanted to omit that.
Anyway I can happily report there is nothing wrong with the sieve filter
syntax and things are running really well in the meantime.
THe problem was I sieve filter that ran before this custom one that had
a stop command in it. Meaning that this custom filter actually never got
to do it's work.
Great work this sieve. have a great day all.
On 27-08-2022 17:53, Дилян Палаузов wrote:
> Hello,
>
> your question is not related to the SIEVE-IEFT mailing list, as it is
> not connected to standardization process.
>
> Please refer to your Sieve vendor/implementation/provider. It might
> have broken implementation, or who knows.
>
> The domain mymiab.net is currently not registered in DNS. At your
> place I would either reject emails during the SMTP dialog for
> "[email protected]" and ,"[email protected]" instead of discarding them.
> If you are 120% sure this is spam, like the addresses are
> spamtrap/honeypot, then it is better to train the anti-spam filter with
> them, instead of discarding them.
>
> You could get the actual receiving email address (destination) using
> envelope test:
> if envelope :contains "from" ["...mymiab.net"] {discard;}
>
> The reason for your problem might be, that there is a stop-action
> before the excerpt you posted; conflicting actions (like discard and
> fileinto "SPAM" at the same time) in the same run of the script; your
> email provider does not apply Sieve scripts, in case your email address
> is not in the To:/CC: header.
>
> Immediately after «Content-Transfer-Encoding: 8bit» from your example,
> there is a missing new line.
>
> All in all, refer to your email provider, this (dead) mailing list is
> not for such stuff.
>
> Greetings
> Dilyan
>
> On Fri, 2022-07-29 at 16:33 +0200,
> [email protected] wrote:
>> Please forgive me if this is not the correct mailing list.
>> I tried days ago on the mail in a box forum but my question falls on
>> deaf ears there.
>>
>> I am mailing here in the tiny chance the issue is sieve related.
>>
>> Please consider the following sieve filter
>>
>> --------------
>> # rule:[discard SPAM to old leaked/compromised aliases]
>> if header :contains ["Received", "To"]
>> [
>> "[email protected]"
>> ,"[email protected]"
>> ]
>> {
>> discard;
>> }
>> --------------
>>
>> when testing it using the sieve filter found here
>> https://www.fastmail.com/cgi-bin/sievetest.pl
>>
>> using the following headers
>>
>>
>> --------------
>> Return-Path: <[email protected]>
>> Delivered-To: [email protected]
>> Received: from box.mymiab.net ([127.0.0.1])
>> by box.mymiab.net with LMTP id cJdVEakZ4WJEPwAAs4i54A
>> for <[email protected]>; Wed, 27 Jul 2022 12:55:37 +0200
>> X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on
>> box.mymiab.net
>> X-Spam-Flag: YES
>> X-Spam-Level: ********
>> X-Spam-Status: Yes, score=8.3 required=5.0
>> tests=DATE_IN_PAST_03_06,DMARC_NONE,
>> FSL_BULK_SIG,HTML_IMAGE_RATIO_06,HTML_MESSAGE,MIME_HTML_ONLY,
>> PYZOR_CHECK,SPF_FAIL,SPF_HELO_NEUTRAL autolearn=no
>> autolearn_force=no
>> version=3.4.2
>> X-Spam-Report:
>> * 5.0 SPF_FAIL SPF check failed
>> * 0.1 DMARC_NONE DMARC record not found
>> * 1.1 DATE_IN_PAST_03_06 Date: is 3 to 6 hours before Received:
>> date
>> * 0.0 SPF_HELO_NEUTRAL SPF: HELO does not match SPF record
>> (neutral)
>> * 0.0 HTML_MESSAGE BODY: HTML included in message
>> * 0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
>> * 0.0 HTML_IMAGE_RATIO_06 BODY: HTML has a low ratio of text to
>> image
>> * area
>> * 2.0 PYZOR_CHECK Listed in Pyzor
>> * (https://pyzor.readthedocs.io/en/latest/)
>> * 0.0 FSL_BULK_SIG Bulk signature with no Unsubscribe
>> X-Spam-Score: 8.3
>> X-Greylist: delayed 3601 seconds by postgrey-1.36 at box.mymiab.net;
>> Wed, 27 Jul 2022 12:55:34 CEST
>> Authentication-Results: box.mymiab.net; dmarc=none (p=none dis=none)
>> header.from=schnellerversand.com
>> Authentication-Results: box.mymiab.net; spf=fail
>> [email protected]
>> Authentication-Results: box.mymiab.net; dkim=none;
>> dkim-atps=neutral
>> Received: from skullandbonesskateboards.com (pp9p.com [69.12.64.248])
>> by box.mymiab.net (Postfix) with ESMTP id F2FC640018
>> for <[email protected]>; Wed, 27 Jul 2022 12:55:34 +0200 (CEST)
>> To: [email protected]
>> Subject: Jahrelange Garantie auf unser Set >> Zwei z. Preis von einem
>> Message-ID: <[email protected]>
>> Date: Wed, 27 Jul 2022 07:32:04 +0200
>> From: "Deutsche Werkzeughandel" <[email protected]>
>> Reply-To: [email protected]
>> MIME-Version: 1.0
>> Content-Type: text/html; charset="UTF-8"
>> Content-Transfer-Encoding: 8bit
>> --------------
>>
>>
>>
>> the result is
>>
>> ///
>> Adding ending newline to email
>> discarding message
>> ///
>>
>>
>> Great, the filter looks like it is constructed correctly. So it
>> should
>> be working.
>>
>> However the emails still end up either in my inbox, when not marked
>> as
>> SPAM. Or end up in my SPAM box. Both should not happen.
>>
>> It there anything I can do to pinpoint where things are going wrong?
>>
>> The reasoning for looking in both Received and To headers is because
>> sometimes I am getting SPAM via a BCC. So then the To header does not
>> contain anything related to the filter. But the Received always does
>> so
>> theoretically I should be able to only use the Received header but
>> that
>> also does not work ;(
>>
>>
>> Could anyone please advice me on how to proceed getting to the bottom
>> of
>> this?
>>
>> _______________________________________________
>> sieve mailing list
>> [email protected]
>> https://www.ietf.org/mailman/listinfo/sieve
_______________________________________________
sieve mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/sieve
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.