4 ms·
I run my own mail server, and I get very little spam. Sometimes I go for days without a single spam message even getting through to my spam folder, much less my
by insertnickname 10y ago
I run my own mail server, and I get very little spam. Sometimes I go for days without a single spam message even getting through to my spam folder, much less my inbox. The last spam mail that got through to my spam folder was on November 25th. And it's not because spammers don't try, my server has rejected 206 mails in the last ~24 hours (and that's not counting the attempted open relay abuse).
My setup consists of Postfix with postscreen and SpamAssassin. Postscreen blocks clients on a certain type of protocol error that spammers are prone to (speaking out of turn) and based on DNSBLs[1], notably zen.spamhaus.org, which blocks most spammers.
SpamAssassin, in addition to the standard rules and bayes filtering, is configured with Pyzor, Razor2, DCC, and iXhash, and I have some custom rules as well.
I actually get far less spam with my self-hosted setup than I did when I used a paid e-mail service (although it was not Google).
Public IP reputation (DNSBLs) and spam fingerprint databases (Pyzor, Razor2, DCC, iXhash) make self-hosted spam filtering very feasible.
1: https://en.wikipedia.org/wiki/DNSBL https://en.wikipedia.org/wiki/DNSBL
- eps 10y agoMay want to throw postgrey in a mix. Incredulously, asking first-time senders to retry in a bit still filters out the vast majority of spam.
- insertnickname 10y agoI intend to switch to rspamd soon, which has built-in greylisting. However, in my test run with rspamd I did not get good enough results because my current SpamAssassin setup relies heavily on rejecting spam that hits two or more content filters (bayes, pyzor, etc.). I will need to implement at least a pyzor plugin for rspamd before I can switch. rspamd, in addition to bayes filtering, has it's own fuzzy fingerprinting system. You can use your own fingerprint db and/or a public one. The public one that is configured in rspamd by default didn't seem to catch any of the spam I get though.
- eps 10y agoDon't know about rspamd, but SpamAssassin used to be way too aggressive in its stock config. E.g., it had a default rule for some "MS-Outlook" headers that just happen to be in every email sent from Outlook via a non-Exchnage mail server. That created a ton of false positives - wasn't hard to fix, but still it was a hassle.
- garaetjjte 10y agoDon't do it. There is no reason why mail cannot be instant.
- insertnickname 10y agoAlso, greylisting has become less effective for stoppping spam.
- jrnichols 10y agoI ended up moving away from Postgrey because the delays (especially coming from Gmail) were a huge problem. Since the mail would come from some random IP in Google's massive server farm, each time it tried to get delivered, postgrey would delay it again.
- insertnickname 10y agoIn rspamd you can configure it so that it only greylists mails that it classifies as spam, but don't have a high enough score to reject it.