1 |
Hello, |
2 |
|
3 |
Lot of thing are done for fighting spam : dnssec, dane, spf, dkim, |
4 |
dmarc... All of this for "trusting real sender". |
5 |
Some of them break smtp built in fonctionnality : spf break forwarding [1]. |
6 |
|
7 |
If you beleive in spf (gentoo.org have an spf dns entry) , two ways need |
8 |
to be looked at : |
9 |
- fixing real sender with SRS [1]. |
10 |
- stop forwarding mail and do POP (gmail can do it) or IMAP from your |
11 |
favorite (web)mail client. |
12 |
|
13 |
Dmarc dns entry with report activated can help you understand why google |
14 |
blacklist you. |
15 |
|
16 |
[1] http://www.openspf.org/SRS |
17 |
|
18 |
Regards, |
19 |
Charles Nérot |
20 |
|
21 |
Le 11/05/2015 06:26, Robin H. Johnson a écrit : |
22 |
> TL;DR: As of May 17, @gentoo.org will drop incoming spammy mail instead of |
23 |
> delivering it. Speak now or hold your peace. |
24 |
> |
25 |
> Hi all, |
26 |
> |
27 |
> As past long-standing practice, @Gentoo.org system-level mail handling for |
28 |
> incoming mail was officially to tag everything, and delete nothing. |
29 |
> |
30 |
> All deletion decisions were left to developers, via procmail/sieve/etc. |
31 |
> |
32 |
> This was a good early policy, as Gentoo was a much more reliable host than |
33 |
> email providers a decade ago. This isn't true anymore, with the meteoric rise |
34 |
> and success of gmail. |
35 |
> |
36 |
> A LOT of developers forward their mail now, to systems that refuse/temporarily |
37 |
> blacklist the forwarding system because there is a lot of spam. Gmail is |
38 |
> particularly strict in this regard, throttling mail to any recipient from the |
39 |
> forwarding source. |
40 |
> |
41 |
> This is particularly acute, because more than 40% of the outgoing mail goes to |
42 |
> Google (the 25% of destinations below is heavily represented because the very |
43 |
> active devs send their mail to google). |
44 |
> |
45 |
> This unfortunate combination means that ~40% of mail sits in a backlog for a |
46 |
> long time, and the active devs that use Gmail don't get their mail in a timely |
47 |
> fashion. |
48 |
> |
49 |
> Unless there are any major objections, as of May 17th, Infra will start |
50 |
> dropping mail that scores more than 10.0 points in Spamassassin. |
51 |
> |
52 |
> If that is successful, I propose to drop the score point by 1 point every month |
53 |
> until it hits a score of 5.0 (so by mid-October, it will be dropping mail that |
54 |
> scores more than 5.0). |
55 |
> |
56 |
> Stats on how mail is handled: |
57 |
> ----------------------------- |
58 |
> ~260 active devs |
59 |
> ~180 .forward files |
60 |
> |
61 |
> This breaks down to: |
62 |
> ~70 procmail users |
63 |
> ~10 sieve users |
64 |
> 2 users with both forward and procmail |
65 |
> 1 maildrop user |
66 |
> ~100 devs that send mail outside of @gentoo.org (in their .forward) |
67 |
> |
68 |
> I didn't analyze the procmail/sieve/maildrop accounts further. |
69 |
> |
70 |
> I did break down the other forwarding destinations by domain: |
71 |
> ~50 devs that forward directly to @gmail or @googlemail addresses |
72 |
> ~10 devs that have their own domain hosted at gmail/googlemail |
73 |
> ~40 devs with some other provider. |
74 |
> 0 devs with yahoo, hotmail or msn domains as destinations :-). |
75 |
> |
76 |
> As a result, about 25% of dev mail destinations are actually Google. |
77 |
> |
78 |
> Amavis stats: |
79 |
> ------------- |
80 |
> Here are the amavis summary stats for @gentoo.org incoming mail that was |
81 |
> scanned for content (this happens before exploding to aliases and multiple |
82 |
> recipients, so is a lot lower than you might otherwise expect). |
83 |
> |
84 |
> "SPAMMY" in this case is >= 5.5. |
85 |
> 26 May 3 Blocked INFECTED |
86 |
> 1609 May 3 Passed CLEAN |
87 |
> 1564 May 3 Passed SPAMMY |
88 |
> 35 May 4 Blocked INFECTED |
89 |
> 4129 May 4 Passed CLEAN |
90 |
> 2304 May 4 Passed SPAMMY |
91 |
> 2 May 4 Passed UNCHECKED |
92 |
> 42 May 5 Blocked INFECTED |
93 |
> 4458 May 5 Passed CLEAN |
94 |
> 3183 May 5 Passed SPAMMY |
95 |
> 4 May 5 Passed UNCHECKED |
96 |
> 43 May 6 Blocked INFECTED |
97 |
> 10 May 6 Blocked MTA-BLOCKED |
98 |
> 5027 May 6 Passed CLEAN |
99 |
> 3443 May 6 Passed SPAMMY |
100 |
> 47 May 7 Blocked INFECTED |
101 |
> 2 May 7 Blocked MTA-BLOCKED |
102 |
> 4657 May 7 Passed CLEAN |
103 |
> 3119 May 7 Passed SPAMMY |
104 |
> 2 May 7 Passed UNCHECKED |
105 |
> 35 May 8 Blocked INFECTED |
106 |
> 5025 May 8 Passed CLEAN |
107 |
> 2936 May 8 Passed SPAMMY |
108 |
> 21 May 9 Blocked INFECTED |
109 |
> 2497 May 9 Passed CLEAN |
110 |
> 1765 May 9 Passed SPAMMY |
111 |
> 16 May 10 Blocked INFECTED |
112 |
> 2059 May 10 Passed CLEAN |
113 |
> 2033 May 10 Passed SPAMMY |
114 |
> |
115 |
> Score analysis of 1 week of incoming mail to amavis: |
116 |
> ---------------------------------------------------- |
117 |
> ~51k unique mails were scored, with a rough breakdown as follows: |
118 |
> |
119 |
> ~17k < 0.0 |
120 |
> ~13k 0.0 - 5.0 |
121 |
> ~7k 5.0 - 10.0 |
122 |
> ~5k 10.0 - 20.0 |
123 |
> ~5k 20.0 - 30.0 |
124 |
> ~3k > 30.0 |
125 |
> |