Gentoo Archives: gentoo-project

From: "Robin H. Johnson" <robbat2@g.o>
To: gentoo-project@l.g.o, gentoo-dev@l.g.o
Subject: [gentoo-project] Anti-spam changes: proposal to drop spammy mail
Date: Mon, 11 May 2015 04:26:11
Message-Id: robbat2-20150511T030343-086083177Z@orbis-terrarum.net
1 TL;DR: As of May 17, @gentoo.org will drop incoming spammy mail instead of
2 delivering it. Speak now or hold your peace.
3
4 Hi all,
5
6 As past long-standing practice, @Gentoo.org system-level mail handling for
7 incoming mail was officially to tag everything, and delete nothing.
8
9 All deletion decisions were left to developers, via procmail/sieve/etc.
10
11 This was a good early policy, as Gentoo was a much more reliable host than
12 email providers a decade ago. This isn't true anymore, with the meteoric rise
13 and success of gmail.
14
15 A LOT of developers forward their mail now, to systems that refuse/temporarily
16 blacklist the forwarding system because there is a lot of spam. Gmail is
17 particularly strict in this regard, throttling mail to any recipient from the
18 forwarding source.
19
20 This is particularly acute, because more than 40% of the outgoing mail goes to
21 Google (the 25% of destinations below is heavily represented because the very
22 active devs send their mail to google).
23
24 This unfortunate combination means that ~40% of mail sits in a backlog for a
25 long time, and the active devs that use Gmail don't get their mail in a timely
26 fashion.
27
28 Unless there are any major objections, as of May 17th, Infra will start
29 dropping mail that scores more than 10.0 points in Spamassassin.
30
31 If that is successful, I propose to drop the score point by 1 point every month
32 until it hits a score of 5.0 (so by mid-October, it will be dropping mail that
33 scores more than 5.0).
34
35 Stats on how mail is handled:
36 -----------------------------
37 ~260 active devs
38 ~180 .forward files
39
40 This breaks down to:
41 ~70 procmail users
42 ~10 sieve users
43 2 users with both forward and procmail
44 1 maildrop user
45 ~100 devs that send mail outside of @gentoo.org (in their .forward)
46
47 I didn't analyze the procmail/sieve/maildrop accounts further.
48
49 I did break down the other forwarding destinations by domain:
50 ~50 devs that forward directly to @gmail or @googlemail addresses
51 ~10 devs that have their own domain hosted at gmail/googlemail
52 ~40 devs with some other provider.
53 0 devs with yahoo, hotmail or msn domains as destinations :-).
54
55 As a result, about 25% of dev mail destinations are actually Google.
56
57 Amavis stats:
58 -------------
59 Here are the amavis summary stats for @gentoo.org incoming mail that was
60 scanned for content (this happens before exploding to aliases and multiple
61 recipients, so is a lot lower than you might otherwise expect).
62
63 "SPAMMY" in this case is >= 5.5.
64 26 May 3 Blocked INFECTED
65 1609 May 3 Passed CLEAN
66 1564 May 3 Passed SPAMMY
67 35 May 4 Blocked INFECTED
68 4129 May 4 Passed CLEAN
69 2304 May 4 Passed SPAMMY
70 2 May 4 Passed UNCHECKED
71 42 May 5 Blocked INFECTED
72 4458 May 5 Passed CLEAN
73 3183 May 5 Passed SPAMMY
74 4 May 5 Passed UNCHECKED
75 43 May 6 Blocked INFECTED
76 10 May 6 Blocked MTA-BLOCKED
77 5027 May 6 Passed CLEAN
78 3443 May 6 Passed SPAMMY
79 47 May 7 Blocked INFECTED
80 2 May 7 Blocked MTA-BLOCKED
81 4657 May 7 Passed CLEAN
82 3119 May 7 Passed SPAMMY
83 2 May 7 Passed UNCHECKED
84 35 May 8 Blocked INFECTED
85 5025 May 8 Passed CLEAN
86 2936 May 8 Passed SPAMMY
87 21 May 9 Blocked INFECTED
88 2497 May 9 Passed CLEAN
89 1765 May 9 Passed SPAMMY
90 16 May 10 Blocked INFECTED
91 2059 May 10 Passed CLEAN
92 2033 May 10 Passed SPAMMY
93
94 Score analysis of 1 week of incoming mail to amavis:
95 ----------------------------------------------------
96 ~51k unique mails were scored, with a rough breakdown as follows:
97
98 ~17k < 0.0
99 ~13k 0.0 - 5.0
100 ~7k 5.0 - 10.0
101 ~5k 10.0 - 20.0
102 ~5k 20.0 - 30.0
103 ~3k > 30.0
104
105 --
106 Robin Hugh Johnson
107 Gentoo Linux: Developer, Infrastructure Lead
108 E-Mail : robbat2@g.o
109 GnuPG FP : 11ACBA4F 4778E3F6 E4EDF38E B27B944E 34884E85

Replies