• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.

Question Spamassasin not working

Thomas Dahl

New Pleskian
It is most likely that I am missing something basic... But here it goes.

I have added a lot of emails, some with wild cards (*@163.com) to the blacklist, but the spam email is getting through to my users. I have messed with various settings to no avail.

Does anyone have an idea of what I am doing wrong?

BTW: Is there a way to add to the black list from an online service?

We are drowning in SPAM... !

Cheers, everone. Thomas
 
Thanks. I will read this.

But why does it not simply work when I add a domain to the black list and select "server wide"..?

I am a bit of a Newby and am only using basic setting until I have learnt more.

Cheers and have a great w/e.
 
Hi,

you can check /var/maillog to see if the SPAM messages are bypassing the spamassassin SA_MAX_MAIL_SIZE param. If that's the case you will get many lines such as "skipped message, greater than max message size."

You can also implement more strict SPF rules.
 
Hi,

you can check /var/maillog to see if the SPAM messages are bypassing the spamassassin SA_MAX_MAIL_SIZE param. If that's the case you will get many lines such as "skipped message, greater than max message size."

You can also implement more strict SPF rules.
Golly.. How do i get to this log? And
Do the spam messages that get through contain the X-Spam-Flag: YES header?
I do not find this flag in the emails.. But I do see this:


Content-Transfer-Encoding: 8bit
X-antispameurope-sender: [email protected]
X-antispameurope-recipient: [email protected]
X-antispameurope-MSGID: 286ba13d3f0f1de4c4e2b6ba2f602ad9-9b6231e3ea9d471ac23bf6ab9df5ea86
X-antispameurope-body-digest: e8499d971d8511ab15c29eefcdd134a1
X-antispameurope-Virusscan: CLEAN
X-antispameurope-SPFRESULT: PASS
X-antispameurope-orig-ip: 209.85.216.42
X-antispameurope-orig-host: mail-pj1-f42.google.com
X-antispameurope-orig: ef9daad734907b32037622bfd54923e2
X-antispameurope-disclaimer: This E-Mail was scanned by www.antispameurope.com E-Mailservice on mx-gate09-hz2 with 51737D093A7
X-antispameurope-date: 1648192682
X-antispameurope: INCOMING:
X-antispameurope-Connect: mail-pj1-f42.google.com[209.85.216.42],TLS=1;EMIG=0
X-antispameurope-WC: 6:576:5:378816:2:200:0:0:1:1:0:0:1:0:2:4:1:16:179:16:0:0:1:0:0:79:0:0:0:1:0:0:0:0::3:1:0:0:0:0:0
X-antispameurope-detected-infomail: yes
X-antispameurope-Digest: 2c71ed4226b0ebe21d52a98d5533c597
X-antispameurope-Spamstatus: CLEAN
X-antispameurope-REASON: Score-b:-11.790612
 
Here is the whole email header..

Return-Path: <SRS0=+y0k=UE=and-living.com=[email protected]>
X-Original-To: [email protected]
Delivered-To: [email protected]
Received: by a00538.host.tro.net (Postfix, from userid 30)
id 9C60728071F; Fri, 25 Mar 2022 08:18:09 +0100 (CET)
X-Original-To: [email protected]
Delivered-To: [email protected]
Received: from hsmx05.antispameurope.com (hsmx05.antispameurope.com [83.246.65.101])
by a00538.host.tro.net (Postfix) with ESMTPS id 5B35A280233
for <[email protected]>; Fri, 25 Mar 2022 08:18:09 +0100 (CET)
Received: from mail-pj1-f42.google.com (209.85.216.42) by mx-gate09-hz2.hornetsecurity.com;
Fri, 25 Mar 2022 08:18:08 +0100
Received: by mail-pj1-f42.google.com with SMTP id n7-20020a17090aab8700b001c6aa871860so7505849pjq.2
for <[email protected]>; Fri, 25 Mar 2022 00:17:59 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=and-living.com; s=google;
h=date:to:from:reply-to:subject:message-id:list-unsubscribe-post
:list-unsubscribe:list-unsubscribe:mime-version
:content-transfer-encoding;
bh=iH/x6ZkycL8jM63vAWFWIwFcI3wqMXns5tPswZeGmbg=;
b=OnlAqKWdBzy1CV1MStQoDQ01OrmNSmo6ALRlRQkrBedqd94N+/zdrLCL3uIY/7bNZP
41UVXo/bT/P7gcaM5uTO8I/HdfXZ5L4vR3BIzk7t6kHmbHWxtCmDkLv5rfHZGEjtXngE
nLhhc03DeQwxe5sHfONtJGcev2oGzHAkBlmLNtfPkqLxWxKlYPkR8pB0ROeg+qqAfpVa
8p6yg4wKxEp/cOJL+L3KKiTnFc259ZpjbWwjmdBUCR/5FwhHbNHC+7Me6jEh9o9bbH8u
UBXKoKKnvqCGmA1vnM231ShKZS0EejzmE0DvN9sVx9fstn9tSWMmFh9X5oi2Ec7dFZez
5e6g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20210112;
h=x-gm-message-state:date:to:from:reply-to:subject:message-id
:list-unsubscribe-post:list-unsubscribe:list-unsubscribe
:mime-version:content-transfer-encoding;
bh=iH/x6ZkycL8jM63vAWFWIwFcI3wqMXns5tPswZeGmbg=;
b=g3BUchbZp9kFIJHFEH3qcSJ0ryQh1WfEl5GnYwT/tr7mYTTgXAiRrbg96h8YO26OOs
YRzkEH4SZPE6eol7nF0qGslMx3+XlQZhS+ExjESrUsa2c+NrtwsQZ8VgZqKrDrUTpHVT
WZZKHg7ebBmhv5oRL0ZzYevqvtrGFxA1ZiTNRBuXV4a6U06ioo3NO7FfIB+Okyvtw5pZ
1S97LnenUHAjb10+o6pvtWOC7lXKlQxNnBoKL3oVuNAe0WEWoWVaz5VIZBR5qlE5a+U0
rj4Csv8lyKa7SDGBTtPc8BhmyGOYsAApuI6CC3OTk1Ar7pMF7LH8QYuy41VswO41zGvK
WHxA==
X-Gm-Message-State: AOAM531eIrCo0W1qJkjwv3/W9bUd7p5r/k0qMJlrczoF3NBlEhg7K15E
kL0u1AAHY+nfbiyRtwdKZSweUr5VxyPo0Q==
X-Google-Smtp-Source: ABdhPJzSgcMR0UimwsiamMpmzV+2+kQjzOAnkBCa31lbElWcdZI3MSdj1VfPm+Ruiyb37PeqVMqduw==
X-Received: by 2002:a17:902:6845:b0:153:9af1:3134 with SMTP id f5-20020a170902684500b001539af13134mr10133471pln.169.1648192677243;
Fri, 25 Mar 2022 00:17:57 -0700 (PDT)
Received: from and-living.com (4.146.203.35.bc.googleusercontent.com. [35.203.146.4])
by smtp.gmail.com with ESMTPSA id j14-20020a056a00174e00b004f66ce6367bsm6423863pfc.147.2022.03.25.00.17.56
for <[email protected]>
(version=TLS1 cipher=ECDHE-ECDSA-AES128-SHA bits=128/128);
Fri, 25 Mar 2022 00:17:56 -0700 (PDT)
Date: Fri, 25 Mar 2022 15:17:56 +0800
To: [email protected]
From: AND-LIVING COMPANY LIMITED <[email protected]>
Reply-To: AND-LIVING COMPANY LIMITED <[email protected]>
Subject: Invitation from Chinese supplier NEW WEBSITE
Message-ID: <[email protected]>
X-Priority: 3
X-Mailer: PHPMailer 5.2.7
List-Unsubscribe-Post: List-Unsubscribe=One-Click
List-Unsubscribe: <Unsubscribe>
List-Unsubscribe: <mailto:[email protected]?subject=Unsubscribe>
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="b1_faeda8690dbddad5ccbffbb5de92ee45"
Content-Transfer-Encoding: 8bit
X-antispameurope-sender: [email protected]
X-antispameurope-recipient: [email protected]
X-antispameurope-MSGID: 286ba13d3f0f1de4c4e2b6ba2f602ad9-9b6231e3ea9d471ac23bf6ab9df5ea86
X-antispameurope-body-digest: e8499d971d8511ab15c29eefcdd134a1
X-antispameurope-Virusscan: CLEAN
X-antispameurope-SPFRESULT: PASS
X-antispameurope-orig-ip: 209.85.216.42
X-antispameurope-orig-host: mail-pj1-f42.google.com
X-antispameurope-orig: ef9daad734907b32037622bfd54923e2
X-antispameurope-disclaimer: This E-Mail was scanned by www.antispameurope.com E-Mailservice on mx-gate09-hz2 with 51737D093A7
X-antispameurope-date: 1648192682
X-antispameurope: INCOMING:
X-antispameurope-Connect: mail-pj1-f42.google.com[209.85.216.42],TLS=1;EMIG=0
X-antispameurope-WC: 6:576:5:378816:2:200:0:0:1:1:0:0:1:0:2:4:1:16:179:16:0:0:1:0:0:79:0:0:0:1:0:0:0:0::3:1:0:0:0:0:0
X-antispameurope-detected-infomail: yes
X-antispameurope-Digest: 2c71ed4226b0ebe21d52a98d5533c597
X-antispameurope-Spamstatus: CLEAN
X-antispameurope-REASON: Score-b:-11.790612

--b1_faeda8690dbddad5ccbffbb5de92ee45
Content-Type: multipart/alternative;
boundary="b2_faeda8690dbddad5ccbffbb5de92ee45"


--b2_faeda8690dbddad5ccbffbb5de92ee45
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

Attn: [email protected]: AND-LIVING COMPANY LIMITEDSubject: Invitation from Chinese supplier NEW WEBSITEplease kindly forgive us for any trouble we may bring to you. If you would like to stop receiving these emails, please click here .Hi My Valued Vustomer,How are you doing? On behalf of AND-LIVING COMPANY, We thank you for your attention and support as always.AND-LIVING is a professional supplier in kitchen knife & porcelain tableware.To give you a general idea of the various kinds of products now available for export, we have enclosed a catalogue and a price list. You may also visit our online company introduction at our website ( and-living.com ) which includes our latest product line.We look forward to your specific enquiries and hope to establish business relations with you in the future. http://plus.and-living.comThank you and best regards!AND-LIVING COMPANY [email protected], Jingang Road, Guangzhou, Guangdong, ChinaAND-LIVING COMPANY LIMITED, Kitchenware
Manufacturer & Supplier of China, is committed to design & manufacture of high quality porcelain tableware & stainless steel cutlery. Our main products are porcelain daily ware & kitchen knives, for both catering & household uses.and-living.com


--b2_faeda8690dbddad5ccbffbb5de92ee45
Content-Type: multipart/related;
boundary="b3_faeda8690dbddad5ccbffbb5de92ee45"


--b3_faeda8690dbddad5ccbffbb5de92ee45
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

Attn: [email protected]<br/>From: AND-LIVING COMPANY LIMITED<br/>Subject: Invitation from Chinese supplier NEW WEBSITE<br/><br/><span style="color:#bbb;">please kindly forgive us for any trouble we may bring to you. If you would like to stop receiving these emails, please <a href="mailto:[email protected]?subject=Unsubscribe">click here</a> .</span><br/><br/><img src="cid:[email protected]" style="width:96%;max-width:600px;"/><br/><br/>Hi My Valued Vustomer,<br/>How are you doing? On behalf of AND-LIVING COMPANY, We thank you for your attention and support as always.<br/><br/>AND-LIVING is a professional supplier in kitchen knife & porcelain tableware.<br/>To give you a general idea of the various kinds of products now available for export, we have enclosed a catalogue and a price list. You may also visit our online company introduction at our website ( and-living.com ) which includes our latest product line.<br/><br/>We look forward to your specific
enquiries and hope to establish business relations with you in the future. <br/><b style="display:inline-block;background:#D4E6F1;border:1px solid #aaa;color:#34495E;padding:10px 20px;font-size:1.2em;"><span style="">http</span><span style="">://</span>plus<span style="">.</span>and-living<span style="">.</span>com</b><br/><br/><br/>Thank you and best regards!<br/><br/><span style="display:inline-block;vertical-align: middle;padding:4px 0px;">AND-LIVING COMPANY LIMITED</span><img src="cid:[email protected]" alt="AND-LIVING COMPANY LIMITED" style="vertical-align: middle;"/><br/>[email protected]<br/>Rm2-403, Jingang Road, Guangzhou, Guangdong, China<hr/>AND-LIVING COMPANY LIMITED, Kitchenware Manufacturer & Supplier of China, is committed to design & manufacture of high quality porcelain tableware & stainless steel cutlery. Our main products are porcelain daily ware & kitchen knives, for both catering & household uses.<br/>and-living.com<br/>


--b3_faeda8690dbddad5ccbffbb5de92ee45
Content-Type: image/jpeg; name="and-living_img_2.jpg"
Content-Transfer-Encoding: base64
Content-ID: <[email protected]>
Content-Disposition: inline; filename=and-living_img_2.jpg

/9j/4Ss3RXhpZgAATU0AKgAAAAgADAEAAAMAAAABAyAAAAEBAAMAAAABAnAAAAECAAMAAAADAAAA
ngEGAAMAAAABAAIAAAESAAMAAAABAAEAAAEVAAMAAAABAAMAAAEaAAUAAAABAAAApAEbAAUAAAAB
AAAArAEoAAMAAAABAAIAAAExAAIAAAAfAAAAtAEyAAIAAAAUAAAA04dpAAQAAAABAAAA6AAAASAA
CAAIAAgACvyAAAAnEAAK/IAAACcQQWRvYmUgUGhvdG9zaG9wIENDIChNYWNpbnRvc2gpADIwMjE6

etc etc
 
I have added a lot of emails, some with wild cards (*@163.com) to the blacklist, but the spam email is getting through to my users.
Which blacklist are you using? There are two email blacklist available in Plesk. One at Tools & Settings > Spam Filter Settings > Black List and another one at Tools & Settings > Mail Server Settings > Black List.
 
From the header you've posted it looks like Spamassassin did not process the email (because the Spamassassin headers are missing). This could be because the email size was larger then the size threshold set in Spamassassin (500KB by default) in which case Spamassassin skips the message. Or Spamassassin isn't enabled for your email address/account. Or Spamassassin isn't running at all. (Have a look at Tools & Settings > Services Management to see if Spamassassin is running).
 
Which blacklist are you using? There are two email blacklist available in Plesk. One at Tools & Settings > Spam Filter Settings > Black List and another one at Tools & Settings > Mail Server Settings > Black List.
What !! I just found the second one. The one I have been adding to is the one where Spamassasin is mentioned and under "Spam" and not Mailserver settings.

Why on earth do they have two ?? ..
 
From the header you've posted it looks like Spamassassin did not process the email (because the Spamassassin headers are missing). This could be because the email size was larger then the size threshold set in Spamassassin (500KB by default) in which case Spamassassin skips the message. Or Spamassassin isn't enabled for your email address/account. Or Spamassassin isn't running at all. (Have a look at Tools & Settings > Services Management to see if Spamassassin is running).
It is green and says it is running... I restarted it now. Maybe this helps.
 
What !! I just found the second one. The one I have been adding to is the one where Spamassasin is mentioned and under "Spam" and not Mailserver settings.

Why on earth do they have two ?? ..
It's confusing, but they operate differently. The first one (the one you have been using) is used for the SpamAssassin Black list and used purely for spam filtering. The other blacklist is used by Postfix and can be used to block senders (based on the enveloppe sender, i.e Return-Path).

It is green and says it is running... I restarted it now. Maybe this helps.
How big in size was the spam message?
 
Last edited:
Back
Top