Spam uptick?
Problem reported by MattyT - Today at 8:21 AM
Submitted
Has anyone else noticed an increase in spam getting through filters lately? For years, message sniffer was doing a pretty good job at filtering but lately the level of junk getting through has increased dramatically. I think it's time for me to revisit our solution. What are people doing these days for filtering that works reasonably well?

Thx,
Matt
Michael Replied
Yes. A lot of it.
We've been trying to write Regex rules to scan the Raw Content as workarounds.

On a related note, we're seeing a lot of our custom Antispam rules are not firing and can't be seen in message headers since last release. We'll likely need to open a ticket.
J. LaDow Replied
There has been an explosion of garbage coming from Google's cloud platform over the last couple weeks...

We've also seen an uptick from half a dozen other datacenters where the spammers are burning entire class-c's to send garbage out...

Search for HELO vs EHLO in your SMTP logs and you'll see the HELOs are 99.9% garbage...


MailEnable survivor / convert --
Emory Kempf Replied
Michael, do you do this in smartermail? How?
Douglas Foster Replied
Email is implemented with an indefensible security model.

Do  you allow random strangers to wander into your building, ignore your receptionist, set down at any open computer, and start typing?   I doubt it.

Yet we let unknown strangers from all over the world into our networks simply because we do not have enough data to prove that they are not dangerous.  Then we wonder why bad things happen.

For senders with unknown reputation, we have to adopt a policy of quarantine-by-default, instead of allow-by-default.  It is the only way to block all spam.   As many people have observed on many occasions, the attackers only need to succeed once, while we need to succeed every time.   I am working as fast as I can to figure out how to get to that operating mode.

Reply to Thread

Enter the verification text