Spam assassin configuration help for fake Sonic.net email

General discussions and other topics.
2 posts Page 1 of 1
by glowell » Wed Mar 14, 2018 9:43 pm
Hi -

How would I go about configuring spam assassin to block mail from a fake sonic address? I get occasional bouts of spam that have from addresses of the form user@[a-z].mx.sonic.net, while legitimate email from sonic looks like support@sonic.net. Whitelisting *@sonic.net and blacklisting *.mx.sonic.net didn't appear to work. Should it have ?

I see something in the documentation about a whitelisting_from option that would verify that mail is from the domain that it claims to be. It wasn't obvious to me how to set that up for sonic.

Any advice would be greatly appreciated.

Thanks,
Gary
by drew.phillips » Thu Mar 15, 2018 5:14 pm
Hi Gary,

If the from address was showing a hostname like user@n.mx.sonic.net, it means that the header was re-written because the value in the original header was invalid. For example, if you sent a message with a header like "From: bogususer" it would get re-written by sendmail on the MX host that received it (e.g. From: bogususer@n.mx.sonic.net). In theory you could blacklist this but it might cause unforeseen issues.

I would advise against whitelisting *@sonic.net. We have special filters in place that deal with spoofed support emails so you don't have to worry about that. If a Sonic account was compromised and happened to email you, chances are very high it'd get caught by outbound spam filters or inbound filters. If there are specific Sonic accounts you correspond with regularly and trust, it'd be better to whitelist each one explicitly if you would like. If someone was spoofing @sonic.net from the outside and the message would otherwise be caught as spam, your whitelist entry would allow it through.

I could make some suggestions for tuning Spam Assassin rules if you're seeing some messages getting through as well. These changes might solve what you're trying to accomplish with the mixed blacklist_from and whitelist anyway :)

Hope that helps! Let me know if I can assist further.
Drew Phillips
Programmer / System Operations, Sonic.net
2 posts Page 1 of 1

Who is online

In total there are 53 users online :: 0 registered, 0 hidden and 53 guests (based on users active over the past 5 minutes)
Most users ever online was 999 on Mon May 10, 2021 1:02 am

Users browsing this forum: No registered users and 53 guests