Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 08-30-2011, 02:10 PM
Special Member
 
Posts: 136
Default Antispam false positives skyrocketing

Greets,

I'm using 7.1.1 (licensed) and I'm seeing a huge increase in false positives in the junk folders.

Issues:
1. Users of the zimbra server sending to other users in the same domain on the same zimbra server are finding themselves getting marked as spam. For example, john@thedomain.com sent to accounting@thedomain.com and triggers: BAYES_50=0.8, HELO_NO_DOMAIN=0.001, RCVD_IN_PBL=3.335,
RDNS_NONE=0.793, TO_NO_BRKTS_DIRECT=3.483, TO_NO_BRKTS_NOTLIST=0.001
-- This doesn't make much sense to me.

2. I've whitelisted, filtered, and check over some external users sending into users on the Zimbra server but they still end up in the junk folders.

3. It appears as though the spam assassin is blocking on the sender's home/office/mobile IP instead of via their SMTP server's IP. For example, a user on verizon is getting blocked due to verizon being blacklisted, however they're sending out through a valid SMTP. This is triggering RCVD_IN_PBL=3.335 however if I look up the SMTP server it's not blacklisted!
-- This appears to be the case on a lot of mail servers lately. My understanding is blocking from the sender's home/office/mobile IP is incredibly unreliable and a terrible choice for filtering against.

4. For myself, I'm finding it nearly impossible to keep legit mail from sites like godaddy out of my junk folders, while some non-english clearly spam never seems to trigger any spam filters.

Is anyone else seeing this type of behaviour?
Reply With Quote
  #2 (permalink)  
Old 08-30-2011, 03:45 PM
Outstanding Member
 
Posts: 717
Default

In the past couple weeks, Zimbra's built in junk filtering system went to crap for us.

Sadly, I gave up on maintaining the antispam system in Zimbra.

We built out another server running MailScanner, and set up some automatic rule updates with a bunch of suggestions (razor/pyzor/dcc) from both the SpamAssassin and MailScanner site, and some additional custom tweaking.
__________________
01 Networks, LLC / Cybernetik.net
Zimbra NE and OSS Cloud Hosting
Shared Web Hosting
Consulting Services
Reply With Quote
  #3 (permalink)  
Old 08-30-2011, 04:02 PM
Special Member
 
Posts: 136
Default

Well that's encouraging!

Are you running your mailscanner server as a gateway for all your domains?
Reply With Quote
  #4 (permalink)  
Old 08-30-2011, 04:06 PM
Outstanding Member
 
Posts: 717
Default

Yes. I have a Network Edition server and an Open Source server, and have a single gateway being used for the both of them.
__________________
01 Networks, LLC / Cybernetik.net
Zimbra NE and OSS Cloud Hosting
Shared Web Hosting
Consulting Services
Reply With Quote
  #5 (permalink)  
Old 09-02-2011, 07:26 AM
Junior Member
 
Posts: 5
Default

Quote:
Originally Posted by Krishopper View Post
We built out another server running MailScanner, and set up some automatic rule updates with a bunch of suggestions (razor/pyzor/dcc) from both the SpamAssassin and MailScanner site, and some additional custom tweaking.
Perfect!
You can post a howto on this?

Thanks
Reply With Quote
  #6 (permalink)  
Old 09-02-2011, 09:06 AM
Moderator
 
Posts: 2,207
Default

It's been a couple of months (even more than a couple) that I do the mods from this page after each upgrade.
Increase in Spam Score After Upgrading to Version 6.0.7 - Zimbra :: Wiki

It's not about ZCS, it's about SpamAssassin scores.
Reply With Quote
  #7 (permalink)  
Old 09-02-2011, 09:19 AM
Special Member
 
Posts: 136
Default

Thanks for the info Klug.
That's terribly annoying. Certainly Zimbra dev. can set these to a proper level instead of leaving us with a high false-positive situation on every upgrade.
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.