Re: Blacklisting the originating MTA

Doug Hardie <[email protected]> Tue, 28 Apr 2009 09:50:14 -0700
Newsgroups gmane.mail.spam.tmda.user
Message-ID <[email protected]>
In article <[email protected]>,
 Keith Roberts <[email protected]> wrote:

> On Mon, 27 Apr 2009, Doug Hardie wrote:
> 
> > To: [email protected]
> > From: Doug Hardie <[email protected]>
> > Subject: Re: Blacklisting the originating MTA
> > 
> > In article <[email protected]>,
> > Jeff LaCoursiere <[email protected]> wrote:
> >
> >> On Mon, 27 Apr 2009, Doug Hardie wrote:
> >>
> >>> In article <[email protected]>,
> >>> Keith Roberts <[email protected]> wrote:
> >>>
> >>>> Try viewing the full headers of the specific emails you want
> >>>> to block.
> >>>>
> >>>> You should be able to see the path the email has taken to
> >>>> reach you, from the original sender.
> >>>>
> >>>> You may then be able to block the emails using the
> >>>> domain name(s) in the headers.
> >>>
> >>> The TMDA documentation for filters seems to be saying that from-file
> >>> only checks the from email address and does not check the real domains
> >>> of the MTAs involved.
> >>>
> >>
> >> Use the "header" filter instead (this is in my .tmda/filters/incoming
> >> file):
> >>
> >> headers '^X-BeenThere: [email protected]' ok
> >>
> >> If you change the 'ok' to 'drop' it would blacklist all emails from this
> >> list :)
> >>
> >> The basic idea is if you can find something consistent in the headers, you
> >> can do whatever you like with it.
> >
> > That works, but it requires the user to be able to understand and build
> > filter rules.  Thats not something I can give out to most users.  They
> > simply would not understand how to make that work.  They can add to a
> > list (like blacklist) but they are never going to learn how to build
> > filter rules.
> >
> 
> Hi Doug.
> 
> Do you have alot of users?
> 
> What about if you setup a global tmda filter file, and 
> then tell your users to add that into their
> 
> ~/.tmda/filters/incoming
> 
> file?
> 
> Something like:
> 
> headers-file /tmda-global/filters/headers_reject drop
> 
> Then they can forward their spam to you as sys-admin, for 
> you to add the regex rules to that global filter file and 
> block on the MTA domain?

We have a few hundred users using TMDA.  The ones looking for this 
capability want to block MTAs that most of our users want to receive.  A 
global approach will cause more problems than it fixes.  There would 
probably be a few hundred such requests per day and I don't want to have 
to deal with that.


------------------------------------------------------------------------------
Register Now & Save for Velocity, the Web Performance & Operations 
Conference from O'Reilly Media. Velocity features a full day of 
expert-led, hands-on workshops and two days of sessions from industry 
leaders in dedicated Performance & Operations tracks. Use code vel09scf 
and Save an extra 15% before 5/3. http://p.sf.net/sfu/velocityconf
_______________________________________________
tmda-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/tmda-users