Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #11 (permalink)  
Old 04-21-2010, 08:14 AM
Moderator
 
Posts: 7,928
Default

Can you temporarily move BotNet.pm out of the way and do
Code:
su - zimbra
zmamavisdctl restart
and then send another test email to see if it still hits ?
__________________
Reply With Quote
  #12 (permalink)  
Old 04-21-2010, 08:16 AM
imx imx is offline
Special Member
 
Posts: 131
Default

Already tried this, was running for a few days without in dropped into the config - still fires RDNS_NONE, so i just had to tune it down to 0.001....
Reply With Quote
  #13 (permalink)  
Old 04-21-2010, 08:27 AM
Moderator
 
Posts: 7,928
Default

Hmmm very odd. Okay, how about creating a dummy email. You can use one of your test ones but remove all the SA and Amavis headers. Then use the same spamassassin command but without the --line and redirect the email into it. We can then see how SA is interpreting it.
__________________
Reply With Quote
  #14 (permalink)  
Old 04-21-2010, 08:53 AM
imx imx is offline
Special Member
 
Posts: 131
Default

Ok....i see conflicts:

Quote:
[17018] dbg: rules: ran header rule __RDNS_NONE ======> got hit: "[ ip=xx.xx.61.41 rdns= "
So rdns= nothing, however botnet see's it resolve but still flags a hit:

Quote:
[17018] dbg: Botnet: starting
[17018] dbg: Botnet: no trusted relays
[17018] dbg: Botnet: get_relay didn't find RDNS
[17018] dbg: Botnet: IP is 'xx.xx.61.41'
[17018] dbg: Botnet: RDNS is 'dsl.domain.com'
[17018] dbg: Botnet: HELO is ''
[17018] dbg: Botnet: sender ''
I can dig/dig -x, including +trace, forward and reverse records...i dont get it....
Reply With Quote
  #15 (permalink)  
Old 04-21-2010, 08:54 AM
imx imx is offline
Special Member
 
Posts: 131
Default

PS ive tried multiple DNS cache's - my ISP's, Google, AT&T Anycast...local bind..... same each time.
Reply With Quote
  #16 (permalink)  
Old 04-25-2010, 08:06 AM
imx imx is offline
Special Member
 
Posts: 131
Default

Anyone got any other ideas? :/
Reply With Quote
  #17 (permalink)  
Old 04-21-2011, 05:52 AM
Member
 
Posts: 13
Default Same here

We're seeing the same issue here, on 7.1.0.

Where do you alter the score on the rule?
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.