Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 01-04-2011, 03:31 PM
Senior Member
 
Posts: 58
Default [SOLVED] whitelist spam

Guys,

I setup a whitelist for my domain by adding a -10.0 rule in /opt/zimbra/conf/amavid.conf

Not knowing any better, I also whitelisted it through /opt/zimbra/conf/salocal.cf.in using "whitelist_from *@mydomain.com"

I did this because, for some reason some of my linux system reports were being flagged as spam (including the one that was coming from my Zimbra server).

Now all of my system reports are coming through, but I have spam that fakes the from: address coming through as well. In other words, I have a spammer that's connecting to my server and using valid to: email addresses and using one of my valid email addresses as the from: field. I looked at the message body and it's definitely coming from outside my environment (italy and brazil so far).

Did I overkill with one of those whitelist rules? Is there a way to prevent this from happening?

Thanks.....
Reply With Quote
  #2 (permalink)  
Old 02-17-2011, 09:27 AM
Senior Member
 
Posts: 58
Default I think I solved it

I left the -10.0 rule in amavisd.conf but I deleted the "whitelist_from" rule from salocal.cf.in.

I'm now getting my local emails and most of my spam seems to have gone away.


It still doesn't really answer the problem of how do you prevent a user from spoofing the "from" field to come from your domain, but ... I moved on :-)
Reply With Quote
  #3 (permalink)  
Old 03-03-2011, 01:42 PM
Moderator
 
Posts: 1,432
Default

You might have a look at this thread: Daily mail report going to Spam ?!

You also really shouldn't need to whitelist your whole domain like that. At most you might want to try to the workaround in this bug (maybe vote for the bug while you're at it).
__________________
Elliot Wilen
Berkeley, CA

Don't forget to enter your Zimbra version in your forum profile.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.