1
Spam making it though backup mx
Problem reported by Steve Reid - 10/7/2014 at 8:35 AM
Submitted
It seems that for whatever reason the spam scoring is not being handled properly between my backup mx and my main smartermail server.
 
Return-Path: <coltonortiz@fieldpaoli.oiloar.com>
Received: from mail.backupmx.com (mail.backupmx.com [backupIP]) by mail.mainmx.com with SMTP;
   Tue, 7 Oct 2014 11:13:03 -0400
Received: from fieldpaoli.oiloar.com (fieldpaoli.oiloar.com [mainIP]) by mail.backupmx.com with SMTP;
   Tue, 7 Oct 2014 11:12:52 -0400
Date: Tue, 07 Oct 2014 08:08:26 -0700
From: The Lazy workout with results <Ortiz@oiloar.com>
To: <steve@mainmx.com>
Reply-to: <Colton+Ortiz@reply.oiloar.com>
Message-ID: <20141007133844.19606.94931.7345.634@fieldpaoli.oiloar.com>
Subject: Flat-Stomach in Days
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
MIME-Version: 1.0
X-SmarterMail-SmartHostSpam: SPF_Pass, ISpamAssassin 1 [raw: 0], DK_None, DKIM_None
X-SmarterMail-SmartHostSpamWeight: 27
X-SmarterMail-SmartHostSpamSalt: 457321261
X-SmarterMail-SmartHostSpamKey: -1900592865
X-SmarterMail-Spam: SPF_Fail, Spamhaus - PBL2, Bayesian Filtering, ISpamAssassin 30 [raw: 12], SpamAssassin 94 [raw: 21], DK_None, DKIM_None, URIBL - Black:1
X-SmarterMail-SpamDetail: 0.7 DIET_1 Lose Weight Spam
X-SmarterMail-SpamDetail: 2.8 HELO_DYNAMIC_IPADDR2 Relay HELO'd using suspicious hostname (IP addr 2)
X-SmarterMail-SpamDetail: 2.4 FH_HELO_EQ_D_D_D_D Helo is d-d-d-d
X-SmarterMail-SpamDetail: 0.0 TVD_RCVD_IP
X-SmarterMail-SpamDetail: 2.6 RDNS_DYNAMIC Delivered to internal network by host with dynamic-looking rDNS
X-SmarterMail-SpamDetail: 4.3 HELO_DYNAMIC_HCC Relay HELO'd using suspicious hostname (HCC)
X-SmarterMail-SpamDetail: Content analysis details:   (21.5 points, 5.0 required)
X-SmarterMail-SpamDetail: pts rule name              description
X-SmarterMail-SpamDetail: ---- ---------------------- --------------------------------------------------
X-SmarterMail-SpamDetail: 3.3 RCVD_IN_PBL            RBL: Received via a relay in Spamhaus PBL
X-SmarterMail-SpamDetail: [backupIP listed in zen.spamhaus.org]
X-SmarterMail-SpamDetail: 3.5 BAYES_99               BODY: Bayes spam probability is 99 to 100%
X-SmarterMail-SpamDetail: [score: 0.9984]
X-SmarterMail-SpamDetail: 0.0 DIET_1                 BODY: Lose Weight Spam
X-SmarterMail-SpamDetail: 0.0 CK_HELO_DYNAMIC_SPLIT_IP Relay HELO'd using suspicious hostname
X-SmarterMail-SpamDetail: (Split IP)
X-SmarterMail-SpamDetail: 0.0 TVD_RCVD_IP            Message was received from an IP address
X-SmarterMail-SpamDetail: 2.5 URIBL_DBL_SPAM         Contains a spam URL listed in the DBL blocklist
X-SmarterMail-SpamDetail: [URIs: oiloar.com]
X-SmarterMail-SpamDetail: 1.7 URIBL_BLACK            Contains an URL listed in the URIBL blacklist
X-SmarterMail-SpamDetail: [URIs: oiloar.com]
X-SmarterMail-SpamDetail: 0.0 SPF_FAIL               SPF: sender does not match SPF record (fail)
X-SmarterMail-SpamDetail: [SPF failed: Please see http://www.openspf.org/Why?s=mfrom;id=coltonortiz%40fieldpaoli.oiloar.com;ip=backupIP;r=SS.int.mainmx.com]
X-SmarterMail-SpamDetail: 0.1 JAM_PHARMACY_BD        BODY: Body contains pharmacy, medication etc
X-SmarterMail-SpamDetail: 3.6 HELO_DYNAMIC_IPADDR2   Relay HELO'd using suspicious hostname (IP addr
X-SmarterMail-SpamDetail: 2)
X-SmarterMail-SpamDetail: 1.0 RDNS_DYNAMIC           Delivered to internal network by host with
X-SmarterMail-SpamDetail: dynamic-looking rDNS
X-SmarterMail-SpamDetail: 2.8 HELO_DYNAMIC_HCC       Relay HELO'd using suspicious hostname (HCC)
X-SmarterMail-SpamDetail: 3.0 HEXHASH_WORD           Multiple instances of word + hexadecimal hash
X-SmarterMail-TotalSpamWeight: 27
It's not adding the score properly. This email should have been deleted at 50.

Reply to Thread