Configure o SPF e use alguma estrutura de verificação de spf no Postfix (tumgreyspf, postfix-policyd-spf-perl, ...).
Eu tenho um pequeno problema. Algum spammer está me enviando um e-mail do meu endereço.
aqui estão os cabeçalhos de e-mail:
From - Fri Aug 20 08:06:15 2010
X-Account-Key: account7
X-UIDL: 1201266183.2446
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
X-Mozilla-Keys:
Return-Path: <[email protected]>
Received: from mnl-latvia.lv ([unix socket])
by localhost (Cyrus v2.2.13-Debian-2.2.13-10) with LMTPA;
Fri, 20 Aug 2010 07:17:26 +0300
X-Sieve: CMU Sieve 2.2
X-Greylist: delayed 328 seconds by postgrey-1.27 at mnl-bck; Fri, 20 Aug 2010 07:17:20 EEST
Received: from 59.93.217.133 (unknown [59.93.217.133])
by mnl-latvia.lv (ESMTP daemon) with ESMTP id 0F8572E6970
for <[email protected]>; Fri, 20 Aug 2010 07:17:19 +0300 (EEST)
Received: (qmail 2323 by uid 603); Fri, 20 Aug 2010 08:11:00 +0400
Message-Id: <[email protected]>
From: [email protected]
To: [email protected]
Subject: [email protected] VIAGRA X Official Seller -77%
MIME-Version: 1.0
Content-Type: text/html; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Date: Fri, 20 Aug 2010 07:17:19 +0300 (EEST)
X-mnl-latvia.lv-MailScanner: Found to be clean
X-mnl-latvia.lv-MailScanner-From: [email protected]
X-mnl-latvia.lv-MailScanner-To: [email protected]
O servidor de correio está sendo executado no postfix, spamassasin. Em spamassasin é definido que todas as mensagens que estão indo de adices latvian são whitelisted.
spamassasin spam.whitelist.rules
From: *@*.lv yes
main.cf
smtpd_recipient_restrictions = hash:/etc/postfix/access,
permit_sasl_authenticated,
permit_tls_clientcerts,
permit_mynetworks,
check_policy_service inet:127.0.0.1:60000
reject_invalid_hostname,
reject_non_fqdn_sender,
reject_unknown_sender_domain,
reject_non_fqdn_recipient,
reject_unknown_recipient_domain,
reject_unauth_destination,
permit
a pergunta é: posso soltar e-mails no nível smtp se From for o mesmo que To e se o remetente não for autenticado?
no remetente de cabeçalhos de e-mail é:
Recebido: desde 59.93.217.133 (desconhecido [59.93.217.133])
por isso não é autenticado. Estou certo?
Tags postfix