Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Hello,
- Upon investigation, I have located some information for you, hopefully that will clears up some of your confusion.
- Question One: No, all emails have a score. , see attachment
- (ScoreLess5Filtered.png)
- https://snag.gy/L5uXpE.jpg
- >>>This filtering is not caused by Spam Assassin. I have manually looked into the log for you.
- ==============================================j
- /var/log/exim_mainlog:2018-11-07 11:20:30 1gKBa6-0035aW-4T <= lwilliams@kewgardens.com.au H=mg-auso-alpha.mailguard.com.au [34.210.162.117]:40906 P=esmtps X=TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256 CV=no S=44273 id=E4C04157441160468756D89C1EC840D8091B375D@KGEX01.KG.local T="RE: AACG - KEW GARDENS - Run #10 Draft Audit Report" for bureau@softwarenorth.com.au
- [14:32:41 panel root@10675501 ~]cPs# grep '1gKBa6-0035aW-4T' /var/log/exim_mainlog
- 2018-11-07 11:20:30 1gKBa6-0035aW-4T H=mg-auso-alpha.mailguard.com.au [34.210.162.117]:40906 Warning: "SpamAssassin as software detected message as NOT spam (-1.6)"
- 2018-11-07 11:20:30 1gKBa6-0035aW-4T H=mg-auso-alpha.mailguard.com.au [34.210.162.117]:40906 Warning: Message has been scanned: no virus or other harmful content was found
- 2018-11-07 11:20:30 1gKBa6-0035aW-4T <= lwilliams@kewgardens.com.au H=mg-auso-alpha.mailguard.com.au [34.210.162.117]:40906 P=esmtps X=TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256 CV=no S=44273 id=E4C04157441160468756D89C1EC840D8091B375D@KGEX01.KG.local T="RE: AACG - KEW GARDENS - Run #10 Draft Audit Report" for bureau@softwarenorth.com.au
- 2018-11-07 11:20:30 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1gKBa6-0035aW-4T
- 2018-11-07 11:20:30 1gKBa6-0035aW-4T => /dev/null <bureau@softwarenorth.com.au> R=central_filter T=**bypassed**
- 2018-11-07 11:20:30 1gKBa6-0035aW-4T Completed
- [14:33:33 panel root@10675501 ~]cPs#
- ==============================================
- This line : 2018-11-07 11:20:30 1gKBa6-0035aW-4T => /dev/null <bureau@softwarenorth.com.au> R=central_filter T=**bypassed**
- This lines means the filtering system is caused by one of those global email filtering you have in placed. It did originally passed the test of Spam Assassin and you could see that Spam Assassin detected the email message as not spam. But toward the end, it was filtered out by "Central Filter" which is one of those filtered you have created.
- 2. Some emails have a scoreless that 5 but they were stopped by the
- filter, see attachment (NoSecoreFiltered.png)
- https://snag.gy/lAXOu6.jpg
- >>> This is not also caused by Spam Assassin.
- ==============================================
- 2018-11-07 11:24:20 1gKBdf-0035ts-8j <= manager.rockdale@carino.care H=mail-pu1apc01on0079.outbound.protection.outlook.com (APC01-PU1-obe.outbound.protection.outlook.com) [104.47.126.79]:22160 P=esmtps X=TLSv1.2:ECDHE-RSA-AES256-SHA384:256 CV=no S=2484531 id=TY2PR02MB28295D6E2FC4DA708ED54EAB9DC40@TY2PR02MB2829.apcprd02.prod.outlook.com T="FW: Payroll Adjustment Fortnight ending 6 Nov 18" for bureau@softwarenorth.com.au
- 2018-11-07 11:24:20 1gKBdf-0035ts-8j H=mail-pu1apc01on0079.outbound.protection.outlook.com (APC01-PU1-obe.outbound.protection.outlook.com) [104.47.126.79]:22160 Warning: Message has been scanned: no virus or other harmful content was found
- 2018-11-07 11:24:20 1gKBdf-0035ts-8j <= manager.rockdale@carino.care H=mail-pu1apc01on0079.outbound.protection.outlook.com (APC01-PU1-obe.outbound.protection.outlook.com) [104.47.126.79]:22160 P=esmtps X=TLSv1.2:ECDHE-RSA-AES256-SHA384:256 CV=no S=2484531 id=TY2PR02MB28295D6E2FC4DA708ED54EAB9DC40@TY2PR02MB2829.apcprd02.prod.outlook.com T="FW: Payroll Adjustment Fortnight ending 6 Nov 18" for bureau@softwarenorth.com.au
- 2018-11-07 11:24:20 cwd=/var/spool/exim 3 args: /usr/sbin/exim -Mc 1gKBdf-0035ts-8j
- 2018-11-07 11:24:20 1gKBdf-0035ts-8j => /dev/null <bureau@softwarenorth.com.au> R=central_filter T=**bypassed**
- 2018-11-07 11:24:20 1gKBdf-0035ts-8j Completed
- ==============================================
- This line : 2018-11-07 11:24:20 1gKBdf-0035ts-8j => /dev/null <bureau@softwarenorth.com.au> R=central_filter T=**bypassed**
- The same issue occurred, the filtering is coming from one of your global email filter system, instead of Spam Assassin.
- 3. Some emails score increases over time and have the 'bounces' word at
- the beginning of the from Address, see attachment
- (ScoreIncreasesAndBounces.png)
- https://snag.gy/fk47JX.jpg
- >>>As far as I am concern, Spam Assassin does not add the word bounce in the beginning of the email address. I noticed that all the emails that have the word bounce in the beginning is sent through Sendgrid. Is there anyway you can provide a complete email header for this to be investigate further?
- With that said, after the investigation on those email messages you have provided. It has appeared to me that your Global Email filtering system is configured rather aggressively. If you are missing important emails, I would recommend you to configure your global filtering system to have a higher spam score in order to have a looser tolerance. You can also consider removing the email filter and have Spam Assassin in place solely.
- I hope you found this information helpful. Please let me know if you have any additional questions or concerns.
- Best regards,
- --
- William Lam
- Technical Analyst 1
- cPanel LLC.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement