ich habe auf meinem vServer Debian Sarge 3.1 laufen, Spamassassin 3.0.2 mit exim4, ClamAv und vexim.
Mit dem HowTo von debianhowto.de (http://www.debianhowto.de/howtos/de/exi ... sarge.html)
läuft der MTA auch schon ohne Probleme!
Kann per imap Mails empfangen und verschicken.
ClamAV erkennt die eicar-Testfile und stelle die e-Mail auch nicht weiter.
Das eigentlich Problem ist Spamassassin.
Spamassassin läuft und scannt auch die e-Mails - schreibt aber nix in den Header.
Das er scannt sehe ich an der syslog (vsxxxxx ersetzt)
Code: Select all
Mar 11 11:10:19 vsxxxxx spamd[32528]: connection from localhost.localdomain [127.0.0.1] at port 51469
Mar 11 11:10:19 vsxxxx spamd[32528]: info: setuid to vmail succeededMar 11 11:10:19 vsxxxxx spamd[32528]: checking message <20050311101011.9E7DB16022C@dd2338.kasserver.com> for vmail:99.Mar 11 11:10:22 vsxxxxx spamd[32528]: clean message (0.2/5.0) for vmail:99 in 3.0 seconds, 606 bytes.Mar 11 11:10:22 vsxxxxx spamd[32528]: result: . 0 - AWL,NO_REAL_NAME scantime=3.0,size=606,mid=<20050311101011.9E7DB16022C@dd2338.kasserver.com>,autolearn=disabled
Code: Select all
Mar 11 08:11:49 vsxxxxxx spamd[14781]: connection from localhost.localdomain [127.0.0.1] at port 33275
Mar 11 08:11:49 vsxxxxxx spamd[14781]: info: setuid to vmail succeeded
Mar 11 08:11:49 vsxxxxxx spamd[14781]: checking message <20050311071155.517B61601C6@dd2338.kasserver.com> for vmail:99.
Mar 11 08:11:52 vsxxxxxx spamd[14781]: identified spam (1001.0/5.0) for vmail:99 in 2.8 seconds, 597 bytes.
Mar 11 08:11:52 vsxxxxxx spamd[14781]: result: Y 1000 - AWL,GTUBE,NO_REAL_NAME,RAZOR2_CF_RANGE_51_100,RAZOR2_CHECK scantime=2.8,size=597,mid=<20050311071155.517B61601C6@dd2338.kasserver.com>,autolearn=disabled
In der /etc/exim4/vexim-acl-check-content.conf steht:
Code: Select all
deny senders = :
hosts = ! +relay_from_hosts
!acl = spf_from_acl
message = Your sender is not permitted (read spf.pobox.com)
deny message = This message contains a MIME error ($demime_reason)
demime = *
condition = ${if >{$demime_errorlevel}{2}{1}{0}}
deny message = This message contains an unwanted file extension ($found_extension)
demime = scr:vbs:bat:lnk:pif:bz2
warn message = This message contains malware ($malware_name)
malware = *
log_message = This message contains malware ($malware_name)
warn message = X-Spam-Score: $spam_score ($spam_bar)
spam = vmail:true
warn message = X-Spam-Report: $spam_report
spam = vmail:true
deny hosts = emi.mail.pas.earthlink.net
message = X-PH-FW: leaky forwarder, $dnslist_domain=$dnslist_value
set acl_m4 = ${if match {$h_received:}
{N[(d+).(d+).(d+).(d+)])s+.*by
emi.mail.pas.earthlink.netN}
{$4.$3.$2.$1}fail}
dnslists = sbl-xbl.spamhaus.org:list.dsbl.org:dynablock.njabl.org/$acl_m4
deny hosts = emi.mail.pas.earthlink.net
message = Please use your FQDN for HELO
condition = ${if match {$h_received:}{Nhelo=d+.d+.d+.d+N}{yes}{no} }
Code: Select all
rewrite_header Subject *****SPAM*****
report_safe 1
# trusted_networks 212.17.35.
# lock_method flock
use_bayes 0
Danke :)