Gentoo Archives: gentoo-dev

From: "Charles Nérot" <charles@×××××.com>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Anti-spam changes: proposal to drop spammy mail
Date: Mon, 11 May 2015 13:27:36
Message-Id: 5550AE30.4060706@nerot.com
In Reply to: [gentoo-dev] Anti-spam changes: proposal to drop spammy mail by "Robin H. Johnson"
1 Hello,
2
3 Lot of thing are done for fighting spam : dnssec, dane, spf, dkim,
4 dmarc... All of this for "trusting real sender".
5 Some of them break smtp built in fonctionnality : spf break forwarding [1].
6
7 If you beleive in spf (gentoo.org have an spf dns entry) , two ways need
8 to be looked at :
9 - fixing real sender with SRS [1].
10 - stop forwarding mail and do POP (gmail can do it) or IMAP from your
11 favorite (web)mail client.
12
13 Dmarc dns entry with report activated can help you understand why google
14 blacklist you.
15
16 [1] http://www.openspf.org/SRS
17
18 Regards,
19 Charles Nérot
20
21 Le 11/05/2015 06:26, Robin H. Johnson a écrit :
22 > TL;DR: As of May 17, @gentoo.org will drop incoming spammy mail instead of
23 > delivering it. Speak now or hold your peace.
24 >
25 > Hi all,
26 >
27 > As past long-standing practice, @Gentoo.org system-level mail handling for
28 > incoming mail was officially to tag everything, and delete nothing.
29 >
30 > All deletion decisions were left to developers, via procmail/sieve/etc.
31 >
32 > This was a good early policy, as Gentoo was a much more reliable host than
33 > email providers a decade ago. This isn't true anymore, with the meteoric rise
34 > and success of gmail.
35 >
36 > A LOT of developers forward their mail now, to systems that refuse/temporarily
37 > blacklist the forwarding system because there is a lot of spam. Gmail is
38 > particularly strict in this regard, throttling mail to any recipient from the
39 > forwarding source.
40 >
41 > This is particularly acute, because more than 40% of the outgoing mail goes to
42 > Google (the 25% of destinations below is heavily represented because the very
43 > active devs send their mail to google).
44 >
45 > This unfortunate combination means that ~40% of mail sits in a backlog for a
46 > long time, and the active devs that use Gmail don't get their mail in a timely
47 > fashion.
48 >
49 > Unless there are any major objections, as of May 17th, Infra will start
50 > dropping mail that scores more than 10.0 points in Spamassassin.
51 >
52 > If that is successful, I propose to drop the score point by 1 point every month
53 > until it hits a score of 5.0 (so by mid-October, it will be dropping mail that
54 > scores more than 5.0).
55 >
56 > Stats on how mail is handled:
57 > -----------------------------
58 > ~260 active devs
59 > ~180 .forward files
60 >
61 > This breaks down to:
62 > ~70 procmail users
63 > ~10 sieve users
64 > 2 users with both forward and procmail
65 > 1 maildrop user
66 > ~100 devs that send mail outside of @gentoo.org (in their .forward)
67 >
68 > I didn't analyze the procmail/sieve/maildrop accounts further.
69 >
70 > I did break down the other forwarding destinations by domain:
71 > ~50 devs that forward directly to @gmail or @googlemail addresses
72 > ~10 devs that have their own domain hosted at gmail/googlemail
73 > ~40 devs with some other provider.
74 > 0 devs with yahoo, hotmail or msn domains as destinations :-).
75 >
76 > As a result, about 25% of dev mail destinations are actually Google.
77 >
78 > Amavis stats:
79 > -------------
80 > Here are the amavis summary stats for @gentoo.org incoming mail that was
81 > scanned for content (this happens before exploding to aliases and multiple
82 > recipients, so is a lot lower than you might otherwise expect).
83 >
84 > "SPAMMY" in this case is >= 5.5.
85 > 26 May 3 Blocked INFECTED
86 > 1609 May 3 Passed CLEAN
87 > 1564 May 3 Passed SPAMMY
88 > 35 May 4 Blocked INFECTED
89 > 4129 May 4 Passed CLEAN
90 > 2304 May 4 Passed SPAMMY
91 > 2 May 4 Passed UNCHECKED
92 > 42 May 5 Blocked INFECTED
93 > 4458 May 5 Passed CLEAN
94 > 3183 May 5 Passed SPAMMY
95 > 4 May 5 Passed UNCHECKED
96 > 43 May 6 Blocked INFECTED
97 > 10 May 6 Blocked MTA-BLOCKED
98 > 5027 May 6 Passed CLEAN
99 > 3443 May 6 Passed SPAMMY
100 > 47 May 7 Blocked INFECTED
101 > 2 May 7 Blocked MTA-BLOCKED
102 > 4657 May 7 Passed CLEAN
103 > 3119 May 7 Passed SPAMMY
104 > 2 May 7 Passed UNCHECKED
105 > 35 May 8 Blocked INFECTED
106 > 5025 May 8 Passed CLEAN
107 > 2936 May 8 Passed SPAMMY
108 > 21 May 9 Blocked INFECTED
109 > 2497 May 9 Passed CLEAN
110 > 1765 May 9 Passed SPAMMY
111 > 16 May 10 Blocked INFECTED
112 > 2059 May 10 Passed CLEAN
113 > 2033 May 10 Passed SPAMMY
114 >
115 > Score analysis of 1 week of incoming mail to amavis:
116 > ----------------------------------------------------
117 > ~51k unique mails were scored, with a rough breakdown as follows:
118 >
119 > ~17k < 0.0
120 > ~13k 0.0 - 5.0
121 > ~7k 5.0 - 10.0
122 > ~5k 10.0 - 20.0
123 > ~5k 20.0 - 30.0
124 > ~3k > 30.0
125 >

Replies

Subject Author
Re: [gentoo-dev] Anti-spam changes: proposal to drop spammy mail "C Bergström" <cbergstrom@×××××××××.com>
Re: [gentoo-dev] Anti-spam changes: proposal to drop spammy mail "Robin H. Johnson" <robbat2@g.o>