Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 03-05-2010, 10:49 AM
Senior Member
 
Posts: 73
Default Spoofed sender is causing AWL problems

Hello, we are getting hit pretty hard with SPAM that have spoofed sender headers. This is causing AWL to adjust with a high negative score, which is putting this below the spam threshold.

I see from past posts, that SPF is the 'preferred' method of dealing with this. We aren't huge fans of SPF, and don't want to implement it. Does anyone else have suggestions or things they have implemented to stop the sender forgery? Or adjustments to AWL, or SA?

Here is what a false-negative spam score is looking like from spoofed sender:

X-Spam-Status: No, score=2.41 tagged_above=-10 required=3.4 tests=[AWL=-6.431,
BAYES_95=3, LONGWORDS=1.803, RCVD_IN_PBL=0.905, RCVD_IN_XBL=3.033,
RDNS_NONE=0.1]

Thanks for the help.
__________________
Version: 5.0.13
Reply With Quote
  #2 (permalink)  
Old 03-06-2010, 03:12 AM
Moderator
 
Posts: 7,928
Default

Have a look at my post here :- my zimbra smtp used by someone

You may be able to use SpoofProtection.
__________________
Reply With Quote
  #3 (permalink)  
Old 03-09-2010, 10:19 AM
Senior Member
 
Posts: 73
Default

Thanks for the reply. I think we are going to adjust our outward facing MTA to reject mail from our own domain, unless it's via authenticated SMTP and SSL.
__________________
Version: 5.0.13
Reply With Quote
  #4 (permalink)  
Old 03-09-2010, 10:28 AM
Moderator
 
Posts: 7,928
Default

I have implemented it on our Zimra MTA proxy and it was fine. Only difference to my original post was that the path needed to be /opt/zimbra/postfix/conf. Next step will be to use a LDAP call so that when a new domain is added the hash file would not need to be updated.
__________________
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.