Koozali.org: home of the SME Server

block all mail from .ru

Offline timlitw

  • **
  • 35
  • +0/-0
block all mail from .ru
« on: July 03, 2008, 07:02:12 PM »
Is there anyway that I can tell the smeserver to block/drop all smtp connections from .ru

Offline cactus

  • *
  • 4,880
  • +3/-0
    • http://www.snetram.nl
Re: block all mail from .ru
« Reply #1 on: July 03, 2008, 10:02:08 PM »
Is there anyway that I can tell the smeserver to block/drop all smtp connections from .ru

Yes perhaps using blacklists, but this is not the best method to fight spam, did you already implement other anti-spam measures available on SME Server?
Be careful whose advice you buy, but be patient with those who supply it. Advice is a form of nostalgia, dispensing it is a way of fishing the past from the disposal, wiping it off, painting over the ugly parts and recycling it for more than its worth ~ Baz Luhrmann - Everybody's Free (To Wear Sunscreen)

Offline TearGas

  • 2
  • +0/-0
Re: block all mail from .ru
« Reply #2 on: July 03, 2008, 10:06:17 PM »
Using Geoip works fine for me!
http://wiki.contribs.org/GeoIP

Offline mercyh

  • *
  • 824
  • +0/-0
    • http://mercyh.org
Re: block all mail from .ru
« Reply #3 on: July 03, 2008, 10:08:15 PM »
This panel gives you access from the server-manager to several different levels of white and blacklists including qpsmtpd badhelo and qmail badmailfrom.

http://wiki.contribs.org/Email#Email_WBL_server_manager_panel

Offline timlitw

  • **
  • 35
  • +0/-0
Re: block all mail from .ru
« Reply #4 on: July 03, 2008, 10:09:49 PM »
yes, and it generally works great but right now I am getting about 3500 fake bounce and other spams from russia per hour and I need to get qmail to drop them so spamassassin doesn't have to scan them.

Offline mercyh

  • *
  • 824
  • +0/-0
    • http://mercyh.org
Re: block all mail from .ru
« Reply #5 on: July 03, 2008, 10:17:34 PM »
Is this stuff really from russian IPs or is it just a spoofed from:address <spoofed_user@spoofed_domain.ru> ?

Offline timlitw

  • **
  • 35
  • +0/-0
Re: block all mail from .ru
« Reply #6 on: July 03, 2008, 10:37:41 PM »
I'm not the one receiving these. I'll see if that user will forward several to me.

Offline timlitw

  • **
  • 35
  • +0/-0
Re: block all mail from .ru
« Reply #7 on: July 03, 2008, 10:55:04 PM »
It looks like about 70% are Russia, 20% US and the rest scattered around the globe.

Offline mercyh

  • *
  • 824
  • +0/-0
    • http://mercyh.org
Re: block all mail from .ru
« Reply #8 on: July 03, 2008, 11:06:18 PM »
Did you check out TearGas' suggestion. It should at least get the russian ones and if you receive no legit mail from russia shouldn't cause a problem.

I am not sure if you can block all .ru domains with the qmail blacklist. (at least I can't find the format you would need to use.)

Offline timlitw

  • **
  • 35
  • +0/-0
Re: block all mail from .ru
« Reply #9 on: July 03, 2008, 11:20:21 PM »
Yes, I installed that.  It seems to be working very well.
in the last minute it has been
     12 FR
     15 GB
     23 BR
     23 PE
     29 TR
     38 PL
     84 US
    426 RU
So, I got rid of a few of those country codes also.  This is for a school and the only people they need to communicate with "per the principle" are their parents board and other local supplies and other schools. All US in other words.