3 ms·
This sounds like a great setup. Would you mind sharing the details?
by rwl 16y ago
This sounds like a great setup. Would you mind sharing the details?
- gst 16y agoI mostly use standard settings of Postfix and some extensions, nothing fancy. Some things that my mailserver's config does: - Wait 15 seconds until responding on the SMTP port. For real mailservers that's not a problem, but spammers typically use a very low timeout as lots of their mailadresses are invalid (and mailservers often don't even exist anymore). - Enforce some SMTP protocol characteristics. E.g., spammers often try to "pipeline" all their data directly after connection establishment. "Real" mailservers don't do this (at least not until the remote server explicitly states that it supports pipelining). So we can just reject the connection if this occurs. - Use Greylisting (http://en.wikipedia.org/wiki/Greylisting http://en.wikipedia.org/wiki/Greylisting). Disadvantage: Seems to cause problems with some mailservers. - Use zen.spamhaus.org blacklist. Disadvantage: There may be some false positives, but have not encountered them so far. You can mitigate disadvantages of Greylisting and the Spamhaus blacklist by not using the blacklist for a accept/reject decision, but for a greylisting/no-greylisting decision. So "good" IPs aren't greylisted, and dubious IPs must pass the Greylisting check. - Strictly enforce SPF if the sender's domain configured it with "-all". This blocks all the rolex.com spam. - Not yet, but I will use this soon: Add support for Spamhaus' SWL whitelist and do no further Spam checks for messages from trusted IPs. - If a message passes all those checks use Spamassassin for a content check. We can allow a pretty high Spamassassin here as most spam mails have been blocked in the previous steps. By using Spampd with Spamassassin, Spamassassin can reject messages during the SMTP dialog. In addition, Spamassassin is configured to use Razor, to detect "known" spam messages.