What to do with spam sent to forwarding addresses

What to do with spam sent to forwarding addresses

Posted by: nate
Posted on: 2004-09-13 15:00:00

So one little oddness left with the current filter is that it isn't quite sure what to make of spam sent to addresses that just immediately forward to outside addresses...

Since we don't have a mailbox or login or anything for these addresses, quarantined mail is just sitting in the database, but there's no way for the user to know this or retrieve them.

It's non-trivial to give forwarding-only addresses logins and such for managing quarantined mail. And, I think, confusing and stupid.

I guess I'm leaning towards just not filtering messages destined to forward-only addresses. This seems dumb too.

Like I said, right now it's not behaving that much better. But odds are there aren't too many false-positives and it's probably nicer for the end-user to not deal with the spam.


nate.

Re: What to do with spam sent to forwarding addres

Posted by: Mark
Posted on: 2004-09-13 21:02:00

Perhaps another alternative would be to only tag the subject and add the X-Spam- headers for such addresses?

Re: What to do with spam sent to forwarding addres

Posted by: will
Posted on: 2004-09-13 22:14:00

We talked about that a little. The main problem with that is that we then still have all of that spam hitting our mail machines and getting sent out - and then we still have to deal with big providers seeing us as the "sender" of the spam and blocking us. A lot of the mail from our network reported as spam to AOL subscribers, for example, is spam forwarded THROUGH our machines and then marked as spam by the AOL user.

Re: What to do with spam sent to forwarding addresses

Posted by: bitjumper
Posted on: 2004-09-22 08:01:00

Hi Nate,

Please enable filtering on forwarded only addresses. My domain is my family name. Some of us in the family (myself included) would use DreamHost mailboxes and some would use forwarding. Currently I set my MX to another hosting company to manage our e-mail because they have this feature (they use www.nspasm.org's filter which I love).

What to do with spam to forwarded addresses? From my use of Spasm (www.nspasm.org), I'd say in order of importance:

1) Administrator choice if forwarded mail is filtered or not.
2) Per address configuration of what to do (for the domain admin): disable filtering for that address, reject spam to that address, tag spam to that address, etc.
3) Log everything rejected or tagged. Log the date, sender, recipient, filter which caught the spam, and disposition (tagged or rejected). Provide a web interface for the admin to view and clear the log. Be able to enable or disable logging. (This log aids tuning of filter settings.)
4) Per address configuration to log or not.
5) A domain wide quarantine feature. On a per address basis, rejected spam can be quarantined and selectively delivered by the administrator. Admin can clear the quarantine. It is auto-emptied over time.

I don't know if you are considering these options also (again in order of preference.)

1) Configuration of detailed filter options by the domain administrator.
2) Configuration of the detailed options on a per address basis.

Like I mentioned above my old host uses Spasm (www.nspasm.org). This is a very nice milter for domain hosting and I have grown very dependent on its feature set. It gives great control on an individual address basis of a multitide of filter settings, logging, and quarantine. I love this filter because I have been able to tune it to catch 99% of spam with no (knock on wood) false positives in 4 months. You might take a look. It has a decent web control panel too.

Erik

Re: What to do with spam sent to forwarding addresses

Posted by: bfaber
Posted on: 2004-09-22 10:53:00

And I'd like somebody to rub my back and tell me "YOU'RE THE MAN!" when spam gets by... or something

e.g... my god you guys have long wish lists.

:)

Re: What to do with spam sent to forwarding addres

Posted by: lrosenstein
Posted on: 2004-09-22 14:13:00

I'm not too keen on a solution that just drops messages. Even though false positives are rare, I do get them occasionally.

The suggestion of designating a particular user as the one to manage these quarantined messages would be fine. (Ideally, false positives could be released to the original forwarding address.)

Re: What to do with spam sent to forwarding addres

Posted by: bitjumper
Posted on: 2004-11-17 05:11:00

Hi...

So how did things end up? Are forwarded only addresses filtered? If not, is there any sort of workaround possible? (For instance, what if I create them a mailbox and also forward their mail? Will the filtering happen before forwarding?)

I've filtered forwarded addresses for years on my other hosting service such that I can't move hosting here to Dreamhost until I can do this.

Erik


Re: What to do with spam sent to forwarding addres

Posted by: Aleks
Posted on: 2004-11-17 12:14:00

From what I see, spam sent to email aliases IS being filtered. I'm not sure how they resolved this issue, though.

Tags: forwarding addressesmailspamguessfalse positivesloginsnateconfusingmailboxdumboddsstupidmessages