Koozali.org: home of the SME Server

Obsolete Releases => SME Server 7.x => Topic started by: timlitw on July 03, 2008, 07:02:12 PM

Title: block all mail from .ru
Post by: timlitw on July 03, 2008, 07:02:12 PM
Is there anyway that I can tell the smeserver to block/drop all smtp connections from .ru
Title: Re: block all mail from .ru
Post by: cactus on July 03, 2008, 10:02:08 PM
Is there anyway that I can tell the smeserver to block/drop all smtp connections from .ru

Yes perhaps using blacklists, but this is not the best method to fight spam, did you already implement other anti-spam measures available on SME Server?
Title: Re: block all mail from .ru
Post by: TearGas on July 03, 2008, 10:06:17 PM
Using Geoip works fine for me!
http://wiki.contribs.org/GeoIP
Title: Re: block all mail from .ru
Post by: mercyh on July 03, 2008, 10:08:15 PM
This panel gives you access from the server-manager to several different levels of white and blacklists including qpsmtpd badhelo and qmail badmailfrom.

http://wiki.contribs.org/Email#Email_WBL_server_manager_panel
Title: Re: block all mail from .ru
Post by: timlitw on July 03, 2008, 10:09:49 PM
yes, and it generally works great but right now I am getting about 3500 fake bounce and other spams from russia per hour and I need to get qmail to drop them so spamassassin doesn't have to scan them.
Title: Re: block all mail from .ru
Post by: mercyh on July 03, 2008, 10:17:34 PM
Is this stuff really from russian IPs or is it just a spoofed from:address <spoofed_user@spoofed_domain.ru> ?
Title: Re: block all mail from .ru
Post by: timlitw on July 03, 2008, 10:37:41 PM
I'm not the one receiving these. I'll see if that user will forward several to me.
Title: Re: block all mail from .ru
Post by: timlitw on July 03, 2008, 10:55:04 PM
It looks like about 70% are Russia, 20% US and the rest scattered around the globe.
Title: Re: block all mail from .ru
Post by: mercyh on July 03, 2008, 11:06:18 PM
Did you check out TearGas' suggestion. It should at least get the russian ones and if you receive no legit mail from russia shouldn't cause a problem.

I am not sure if you can block all .ru domains with the qmail blacklist. (at least I can't find the format you would need to use.)
Title: Re: block all mail from .ru
Post by: timlitw on July 03, 2008, 11:20:21 PM
Yes, I installed that.  It seems to be working very well.
in the last minute it has been
     12 FR
     15 GB
     23 BR
     23 PE
     29 TR
     38 PL
     84 US
    426 RU
So, I got rid of a few of those country codes also.  This is for a school and the only people they need to communicate with "per the principle" are their parents board and other local supplies and other schools. All US in other words.