November 25, 2024, 09:48:31 AM

News : LinuxSolved.com Linux Help Community Forum..


Author Topic: Header Checks File Not Working in postfix to block spam mail  (Read 7559 times)

Offline rajesh.bahl

  • Linux Learner
  • ***
  • Posts: 86
Header Checks File Not Working in postfix to block spam mail
« on: January 29, 2008, 08:04:13 AM »
We are using Postfix as mail server. Because of heavy spam coming in we wanted to ban mails from certain domains. We put these in the "header_checks" file ( the file in use is shown below ) . Surprisingly the mails from domains entered in the file are still getting in. Even the /var/log/maillog file does not show any entry for "DISCARDED" mail.

Can someone suggest what is wrong with this file or modifications (if any) required to make it more useful ?
The header_checks file is as under:-

/^Subject:.*Make Money Fast !!!/    DISCARD
/^Subject:.*Join Your Friends at Christian Mingle/    DISCARD
/^Subject:.*Pharma* /    DISCARD
/^Subject:.*Your New ICQ Password/    DISCARD
/^From:.*Doctor /     DISCARD
/^Subject:.*The Ultimate Online Pharmaceutical/      DISCARD
/^Subject:.*Buy OEM Software/      DISCARD
/^To:.*Undisclosed Recipients:;/   DISCARD
/^Subject:.*Large Gains Expected/  DISCARD
/^From:.*@blue-ondulation.com /    DISCARD
/^From:.*@altransnak.com  /        DISCARD
/^From:.*@jumpanda.com /           DISCARD
/^Subject:.*Your 10-day sample pack is ready/    DISCARD
/^Subject:.*Software* /             DISCARD
/^Subject:.*Online Pharmacy* /       DISCARD
/^Subject:.*Mortg* /             DISCARD 
/^Subject:.*wife* /                DISCARD
/^Subject:.*pleasure* /            DISCARD
/^Subject:.*her*  /         DISCARD
/^Subject:.*EM Software* /         DISCARD
/^Subject:.*singles* /             DISCARD
/^Subject:.*Re
  • *  /              DISCARD

/^Subject:.*Need Cash*  /          DISCARD
/^Subject:.*Lo*se weight*  /       DISCARD
/^Subject:.*@indbs.com /           DISCARD
/^From:.*@email.de /                 DISCARD
/^From:.*@optician.com /           DISCARD
/^From:.*@ancestry.com /           DISCARD
/^From:.*@humour.com /             DISCARD
/^From:.*@email.cz /               DISCARD
/^From:.*@torchmail.com /          DISCARD
/^From:.*@plaza-cco.com.br /       DISCARD
/^From:.*@about.com /              DISCARD
/^From:.*@startribune.com /        DISCARD
/^From:.*@acmecity.com /           DISCARD
/^From:.*@cyberinbox.com /         DISCARD
/^From:.*@uymail.com /             DISCARD
/^From:.*@terra.cl /               DISCARD
/^From:.*@mailops.com /            DISCARD
/^From:.*@asianavenue.com /        DISCARD
/^From:.*@.online.no /             DISCARD
/^From:.*@liquidinformation.net /  DISCARD
/^From:.*@nmonline.com.cn /        DISCARD
/^From:.*@dreamer.com /            DISCARD
/^From:.*@la.com /                 DISCARD
/^From:.*@myself.com /             DISCARD
/^From:.*@sonicnet.com /           DISCARD
/^From:.*@mypcera.com /            DISCARD
/^From:.*@ukr.net /                DISCARD
/^From:.*@apexmail.com /           DISCARD
/^From:.*@kasparovch.com /         DISCARD
/^From:.*@mediomail.com /          DISCARD
/^From:.*@maktoob.com /            DISCARD
/^From:.*@compuserve.com /         DISCARD
/^From:.*@uolcat.com /             DISCARD
/^From:.*@overcmail.de /           DISCARD
/^From:.*@ningbo.net /             DISCARD
/^From:.*@tls-spedition.de /      DISCARD
/^From:.*@berkeleyheightspolice.com /   DISCARD
/^From:.*@roadtripfever.com /      DISCARD
/^From:.*@RX3Best.org /         DISCARD
/^From:.*@dieter-roehm.de /      DISCARD
/^From:.*@aymeric-ruiz.com /      DISCARD
/^From:.*@lamarette.com /      DISCARD
/^From:.*@eckman-danovitz.com /      DISCARD
/^From:.*@ivers.com /         DISCARD
/^From:.*@chello.fr /         DISCARD
/^From:.*@stanleyjordan.com /      DISCARD
/^From:.*@conspiracyboards.com /   DISCARD
/^From:.*@hmjagtiani.com /      DISCARD
/^From:.*@europills.com /      DISCARD
/^From:.*@documentarychannel.com /   DISCARD
/^From:.*@ubmindia.com /      DISCARD
/^From:.*@artel.com /         DISCARD
/^From:.*@webforall.dk /      DISCARD
/^From:.*@consumerinfoline.com /   DISCARD
/^From:.*@ponchatoulachamber.com /   DISCARD
/^From:.*@skicanadamag.com  /      DISCARD
/^From:.*@downsizeme.tv /      DISCARD
/^From:.*@consumerinfoline.com  /   DISCARD
/^From:.*@varitjournal.com  /      DISCARD
/^From:.*@ubmindia.com  /      DISCARD
/^From:.*@enterpriser.in  /      DISCARD
/^From:.*@channeltimes.com  /      DISCARD
/^From:.*@mixmail.com  /      DISCARD
/^From:.*@dojotoolkit.org  /      DISCARD
/^From:.*@time-blog.com  /      DISCARD
/^From:.*@switchzoo.com  /      DISCARD
/^From:.*@specialevents.com  /      DISCARD
/^From:.*@choosereport.org  /      DISCARD
/^From:.*@techtree.com  /      DISCARD
/^From:.*@wrigley.com   /      DISCARD
/^From:.*@channelworld.in  /      DISCARD
/^From:.*@zapakannounce.com  /      DISCARD
/^From:.*@foxnews.com  /      DISCARD
/^From:.*@newsday.com  /      DISCARD
/^From:.*@marinecorpstimes.com  /   DISCARD
/^From:.*@team2000.us  /      DISCARD
/^From:.*@lists.cybermedia.in  /   DISCARD
/^From:.*@asturianus.com  /      DISCARD
/^From:.*@flickr.com  /         DISCARD
/^From:.*@psychcentral.com  /      DISCARD
/^From:.*@mediamatters.org  /      DISCARD
/^From:.*@industrialheating.com  /   DISCARD
/^From:.*@heatreward.com  /      DISCARD
/^From:.*@icann.org  /         DISCARD
/^From:.*@myprofilepimp.com  /      DISCARD
/^From:.*@yahoo.fr  /         DISCARD
/^From:.*@selvesandothers.org  /   DISCARD
/^From:.*@serjicalstrike.com  /      DISCARD
/^From:.*@houses.com  /         DISCARD
/^From:.*@cp.com  /         DISCARD
/^From:.*@qx.com  /         DISCARD
/^From:.*@cifns.org  /         DISCARD
/^From:.*@123greetings.biz  /      DISCARD
/^From:.*@convergingworld.com  /   DISCARD
/^From:.*@pantaiwan.com.tw  /      DISCARD
/^From:.*@oembrowser.com  /      DISCARD
/^From:.*@cyberia.net.lb  /      DISCARD
/^From:.*@barbf.com  /         DISCARD
/^From:.*@boston.com  /         DISCARD
/^From:.*@aperfectgiftonline.com  /   DISCARD
/^From:.*@maya123.com  /      DISCARD
/^From:.*@aktyw.pl  /         DISCARD
/^From:.*@nh.com  /         DISCARD
/^From:.*@embryo-films.com  /       DISCARD
/^From:.*@qef.com  /         DISCARD
/^From:.*@bmglabtech.com  /      DISCARD
/^From:.*@zenitel.biz  /      DISCARD
/^From:.*@channelworld.in  /      DISCARD
/^From:.*@surfeador.com  /      DISCARD
/^From:.*@washingtonpost.com  /      DISCARD
/^From:.*@workingaussieosource.com  /   DISCARD
/^From:.*@age-of-bronze.com  /      DISCARD
/^From:.*@buyselltix.com  /      DISCARD
/^From:.*@mine-engineer.com  /      DISCARD

« Last Edit: January 29, 2008, 08:08:06 AM by Ricky »

Offline Ricky

  • LST CareTaker
  • Specially Skilled
  • *****
  • Posts: 2381
Re: Header Checks File Not Working in postfix to block spam mail
« Reply #1 on: January 29, 2008, 08:17:37 AM »
Did you enable header check in main.cf ?
YOu have to add following line in it :
Code: [Select]
header_checks = regexp:/etc/postfix/maps/header_checks
Also make sure rejection log is enabled.. can be done via :
Code: [Select]
smtpd_delay_reject = yesAlso, make sure you are using proper spaces etc..
eg.

/^Subject:  .*sensored/ REJECT

Offline rajesh.bahl

  • Linux Learner
  • ***
  • Posts: 86
Re: Header Checks File Not Working in postfix to block spam mail
« Reply #2 on: February 04, 2008, 07:42:18 AM »
 Both these things are implemented but still nothing is happening.

How can we check whether  postfix  is checking incoming mail for the domains defined in "header_checks" file ?

Do I need to install any additional packages ?



Regards
rajesh.bahl