This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Spam coming through even being blacklisted

I am running a UTM1120 v5 (2GB) at home filtering my SMTP emails which are received by my Zarafa server on my Synology DS-713+ (expanded to 4GB).

My UTM120 is running on up-to-date version 9.309-3. I am using the following RBLs:

zen.spamhaus.org
cbl.abuseat.org
bl.spamcop.net
spam.dnsbl.sorbs.net
http.dnsbl.sorbs.net
socks.dnsbl.sorbs.net
misc.dnsbl.sorbs.net
smtp.dnsbl.sorbs.net
web.dnsbl.sorbs.net
block.dnsbl.sorbs.net
zombie.dnsbl.sorbs.net

Now I got (again) an email from "shoppingdistrict@dankeja.de" which is still blacklisted for a longer time in my sender addresses using the following string

*@dankeja.de

Under "Relaying" I entered my "upstream host/network" which is my 1&1 email server where my domain is hosted and which forwards emails:

moutng.kundenserver.de

This email came from another 1&1 server which shows up as "mout.kundenserver.de (212.227.126.187)". Does that now mean that I also have to add this one to my "upstream host/netzwork" list? Or is the astaro spamfilter malfunctioning???


This thread was automatically locked due to age.
Parents
  • I bet that checking all of those blacklists doesn't do much for you - have you measured that?  When I have, I've found that the recommended RBLs, black.RBL.ctipd.astaro.local and cbl.abuseat.org, account for 95+% and that bl.spamcop.net picks up the rest.  That may be different in Deutschland than in the USA.

    Yes, you will want to add all of those listed at Postmaster MailSecurity (1&1, Postmaster Mailsecurity).  It looks like two DNS Group definitions will suffice.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • I bet that checking all of those blacklists doesn't do much for you - have you measured that?  When I have, I've found that the recommended RBLs, black.RBL.ctipd.astaro.local and cbl.abuseat.org, account for 95+% and that bl.spamcop.net picks up the rest.  That may be different in Deutschland than in the USA.

    Yes, you will want to add all of those listed at Postmaster MailSecurity (1&1, Postmaster Mailsecurity).  It looks like two DNS Group definitions will suffice.

    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data