Re: Lots of FN because of VALIDITY* rules

Matus UHLAR - fantomas <[email protected]>
Newsgroups gmane.mail.spam.spamassassin.general
Message-ID <[email protected]>
On 03.06.24 12:02, Matus UHLAR - fantomas wrote:
>On 03.06.24 07:26, postgarage Graz IT wrote:
>>A few days ago a lot of false negatives landed in our inboxes. As it 
>>turned out the reason was that the for nearly all mails the 
>>RCVD_IN_VALIDITY_CERTIFIED and RCVD_IN_VALIDITY_SAFE rules matched.

I forgot to add that I have "lowered" (increased to small negative number) 
scores for RCVD_IN_VALIDITY_*, RCVD_IN_DNSWL_* and RCVD_IN_IADB_*
because I has similar bad experience with them.

>>I now know that validity introduced a query limit which we hit, 
>>because I have to admit, I wasn't aware that I shouldn't use public 
>>DNS resolvers for blacklists
>
>I'd say you should not use public DNS resolvers with mailserver.
>
>>and therefore we got "Excessive Number of Queries" answers. I also 
>>found this patch 
>>https://bz.apache.org/SpamAssassin/show_bug.cgi?id=8244 which 
>>introduces new rules addressing the query limit.
>
>my current rules show that all RCVD_IN_VALIDITY_* rules check for blocked.
>
>>Those *BLOCKED rules where never applied because our spamassassin 
>>received an updated rule-set which was saved to 
>>/var/lib/spamassassin/4.000000/updates_spamassassin_org/ but never 
>>received an update for the active.list file located in 
>>/usr/share/spamassassin/
>
>>After I manually added the changes from the above mentioned patch to 
>>the active.list file it started to work.
>>
>>Now for my questions:
>>*) as is stated in active.list it should not be edited. What's the 
>>correct place to add the new rules to activate them? local.cf?
>
>you can use dns_query_restriction to restrict which DNS lists to query.
>
>further, you can tune uridnsbl_skip_domain to avoid lookups for 
>domains in URI* lists.
>
>>*) If I understand it correctly
>>/var/lib/spamassassin/4.000000/updates_spamassassin_org/ is updated 
>>by the SA update mechanism but it's the Linux distribution's 
>>responsibility to update /var/lib/spamassassin? In that case should 
>>I fill a Debian bug? Or should the SA updates also include the file 
>>active.list?
>
>reload spamd or amavis, the rules in /var/lib/spamassassin/ are used 
>by default.
>
>Maybe you need to enable cron job by setting CRON=1 in 
>/etc/default/spamassassin and it will happen automatically.
>
>...I have no idea how active.list works.

-- 
Matus UHLAR - fantomas, [email protected] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Enter any 12-digit prime number to continue.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.