URIBL - Issues with false positives - Smartermail V 100
Question asked by Bryant Zimmerman - 1/7/2020 at 9:33 AM
Unanswered
Hi all... We just moved to the current version 100 from SM v 16

I need some understanding of how URIBL's work and why they are reading tons of false positives. 

I don't understand how the lookups are working. If I go to www.surbl.org and www.uribl.com and use their lookup functions against the from email address on the Received: or From: lines in the raw message content I most of the messages being listed with URIBL [count:#]: ## are not even listed in either of these lists. 

What am I missing here.  Things seemed to work ok in SM v16 but something has changed, and I have pissed off users. I am shutting down URIBL's for now, but I really want to get them working correctly. Andy ideas?

Thanks
Bryant

5 Replies

Reply to Thread
0
Bryant Zimmerman Replied
For multi.surbl.org and multi.uribl.com  what should the value/s be for "Required Lookup Values (comma separated)"


0
Employee Replied
Employee Post
Bryant,

Since your SmarterMail license key has active Maintenance and Support, you may want to submit a support ticket:


And an associated RSAA:


Then, one of our technicians can take a look.
0
Steve Norton Replied
URIBLs are used to lookup web links in the body of the email for compromised sites, if you have http links in the email try submitting those to the online lookup functions.
Required Lookup Values;
127.0.0.8,127.0.0.16,127.0.0.24,127.0.0.64,127.0.0.72,127.0.0.80,127.0.0.88,127.0.0.96,127.0.0.128,127.0.0.136,127.0.0.144,127.0.0.152,127.0.0.192,127.0.0.200,127.0.0.208,127.0.0.216
multi.uribl.com (we recommend splitting these in to Black, Grey and Red)
127.0.0.2,127.0.0.4,127.0.0.8,127.0.0.14
0
Bryant Zimmerman Replied
Steve 

Thank you for your post for some reason we have only ever had two entries in our uribl  lists. One for multi.surbl.org and one for multi.uribl.org.  The result ip slider is not slid on for either of ours.   I have never really played with these settings before they have always been what ever was installed by smartermail my guess is they have been ignored by updates and we would have to manually change them.   Thank you for your suggested settings I will enter them in. 
0
Bryant Zimmerman Replied
Steve 

Thanks a bunch your suggestions seem to be making the difference. Apparently the settings we had in there were just defaults from back in the day and they were just getting dragged froward without anyone knowing we needed to update them.

Reply to Thread