LDA input validation

Stéphane Cottin stephane.cottin at vixns.com
Mon Jan 26 09:52:38 UTC 2015


> Le 26 janv. 2015 à 10:09, Reindl Harald <h.reindl at thelounge.net> a écrit :
> 
> 
> 
> Am 26.01.2015 um 08:52 schrieb Steffen Kaiser:
>> On Sun, 25 Jan 2015, Joseph Tam wrote:
>>> St?phane Cottin writes:
>> 
>>>> dspam already send errors to syslog, the point here is to never loose
>>>> email contents.  This was a wrong design, i'm now use a wrapper instead
>>>> ( see my previous post for details ).
>> 
>>> You're stilling going to lose contents.  If dspam fails, the mail
>>> is dumped, the LDA returns exit code 75, and the MTA will probably
>>> issue a bounce Email to the sender.
>> 
>> which would be OK, if "never loose email contents" means "no message is
>> discarded silently".
> 
> no, it is not OK to backscatter because the spamfilter fails
> 
> realize that 99% auf junk is using forged senders
> 
> recently i got each day some hundret such bounces from mailservers configured by fools reply to spam with forged senders and if i could i would have gone out for beat every responsible admin straight in the face
> 

I may discard emails based on RBLs, but I don't want to discard emails based on statistical fllters, I prefer deliver them in the Junk folder and let the user have a chance to reclassify using dovecot_antispam.
And yes, bounce spams to (forged or not) sender is useless.




More information about the dovecot mailing list