• The APS Catalog has been deprecated and removed from all Plesk Obsidian versions.
    Applications already installed from the APS Catalog will continue working. However, Plesk will no longer provide support for APS applications.
  • Please be aware: with the Plesk Obsidian 18.0.78 release, the support for the ngx_pagespeed.so module will be deprecated and removed from the sw-nginx package.

Question Plesk Spam Emails Issue

AK_learner

Basic Pleskian
Server operating system version
CloudLinux 8.10
Plesk version and microupdate number
18.0.76 #6
Hi Pleskians, @Kaspar @Sebahat.hadzhi @IgorG,

We have been facing sudden influx of spam emails on Plesk.
Most of them are chinese, japanese, korean based spam based mails with Spam score of 2 or sometimes even with 0 score.

How to block these emails?

Can you suggest any flexible configurations under which we can configure blocking settings on server level for domain based on patterns? Or any other suggestions?

/=\?utf-8\?B\?[56]/i

/=\?utf-8\?Q\?.*?(?:E38194|E38288|E383AD).*?\?=/i

/=\?utf-8\?q\?.*?=E3=81=94.*?\?=/i

/=\?utf-8\?q\?.*?\?=/i

/koi8-r|koi8-u|koi7|koi8/i

/charset="gb(k|2312)"/i

#/=\?GB(K|2312)\?/i

/=\?UTF-8\?Q\?.*=E[0-9A-F]{2}=[0-9A-F]{2}=[0-9A-F]{2}.*\?=/i

These are the patterns which I have found till now.

My end users are getting frustrated. Please suggest a solution.
 
There are numerous threads on this forum with suggestions on improving spam filtering or blocking. I am sure you'll find something useful if you use the forum search function.

If you don't want configure your server manually or need a good spamfilter solution quickly, I recommend using Warden Warden Antispam and Virus protection.
 
@AK_learner

Do you have SPF, DMARC, DKIM and alike properly defined?

The Plesk mail eco-environment is a bit buggy at the moment, with a lot of spam related issues that can cause major email delivery issues.

Nevertheless, simple solutions like DKIM often seem to help in a considerable way.

I would recommend to setup DKIM first and then, afterwards, analyse the issues that remain.

Kind regards........


PS There is also DANE support (which requires TLSA records) - it improves the situation, but it is not a solution
 
There are numerous threads on this forum with suggestions on improving spam filtering or blocking. I am sure you'll find something useful if you use the forum search function.

If you don't want configure your server manually or need a good spamfilter solution quickly, I recommend using Warden Warden Antispam and Virus protection.
@Kaspar

There is a systematic issue with Plesk mail delivery that is not related to "spam" at all.

One can add all Plesk extensions and all spam solutions and still spam will go through the Plesk server.

I did not find any conclusive / unambiguous root cause of the problem yet ......

...... but it seems to be introduced at the moment that Plesk allowed for issuing LE certificates on the "mail" subdomain (mail.domain.nl).

Stated differently, the nature of spam related issues was different before the option to add LE certs to the mail subdomain ..... and that (former) nature of spam related issues could have been easily solved with standard solutions and/or standard Plesk extensions.

Kind regards....
 
One can add all Plesk extensions and all spam solutions and still spam will go through the Plesk server.
That has not been my experience. But then again, I run a heavily modified SpamAssasin configuration. Which gets the jobs done, for me at least.
 
Back
Top