SYSTEM INFORMATION | |
---|---|
OS type and version Ubuntu Linux 22.04.2 | REQUIRED |
WEBMIN version 2.021 | |
SpamAssassin version 3.4.6 | |
Virtualmin version 7.7 | REQUIRED |
built new server, and webmin/virtualmin with spamassassin has been forwarding emails with my header modification [*** SPAM ***] just fine
but, i still get these emails spoofed as me.
MXtoolbox email health says I’m all good, i.e DKIM, SPF working ok
how can they do this ?
UID 1001 ? what does this mean ?
HEADER_FROM_DIFFERENT_DOMAINS - how do i block this ?
NO_DNS_FOR_FROM - how di I block this ?
Aug 8 18:16:36 server postfix/pickup[48365]: 34542346AB: uid=1001 from=
Aug 8 18:16:36 server postfix/cleanup[52298]: 34542346AB: message-id=20230808181636.34542346AB@server.abc.com
Aug 8 18:16:36 server postfix/qmgr[1194]: 34542346AB: from=abc@localhost.localdomain, size=882, nrcpt=1 (queue active)
Aug 8 18:16:58 server spamd[11147]: spamd: processing message 20230808181636.34542346AB@server.abc.com for info@abc.com:1003
Aug 8 18:17:02 server spamd[11147]: spamd: result: . 3 - FREEMAIL_FORGED_REPLYTO,FREEMAIL_REPLYTO_END_DIGIT,FROM_EXCESS_BASE64,HEADER_FROM_DIFFERENT_DOMAINS,NO_DNS_FOR_FROM,NO_RELAYS,T_PDS_PRO_TLD,URIBL_BLOCKED scantime=4.8,size=1024,user=info@abc.com,uid=1003,required_score=5.0,rhost=127.0.0.1,raddr=127.0.0.1,rport=39126,mid=20230808181636.34542346AB@server.abc.com,autolearn=no autolearn_force=no
Aug 8 18:17:02 server postfix/local[52299]: 34542346AB: to=<“info@abc.com”@localhost.localdomain>, orig_to=info@abc.com, relay=local, delay=27, delays=0.01/0/0/27, dsn=2.0.0, status=sent (delivered to command: /usr/bin/procmail-wrapper -o -a $DOMAIN -d $LOGNAME)
Aug 8 18:17:02 server postfix/cleanup[52298]: 3662933987: message-id=20230808181636.34542346AB@server.abc.com
Aug 8 18:17:02 server postfix/local[52299]: 34542346AB: to=<“info@abc.com”@localhost.localdomain>, orig_to=info@abc.com, relay=local, delay=27, delays=0.01/0/0/27, dsn=2.0.0, status=sent (forwarded as 3662933987)
Aug 8 18:17:02 server postfix/qmgr[1194]: 34542346AB: removed
Aug 8 18:17:25 server spamd[11147]: spamd: processing message 20230808181636.34542346AB@server.abc.com for qwerty@abc.com:1002
Aug 8 18:17:29 server spamd[11147]: spamd: result: . 3 - FREEMAIL_FORGED_REPLYTO,FREEMAIL_REPLYTO_END_DIGIT,FROM_EXCESS_BASE64,HEADER_FROM_DIFFERENT_DOMAINS,NO_DNS_FOR_FROM,NO_RELAYS,T_PDS_PRO_TLD,URIBL_BLOCKED scantime=4.5,size=1181,user=qwerty@abc.com,uid=1002,required_score=5.0,rhost=127.0.0.1,raddr=127.0.0.1,rport=39888,mid=20230808181636.34542346AB@server.abc.com,autolearn=no autolearn_force=no