SpamAssasinの働き
SpamAssasin
SAが評価した
X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on pl74_1031.linet.jp X-Spam-Flag: YES X-Spam-Level: ************** X-Spam-Status: Yes, score=14.8 required=5.0 tests=FROM_SUSPICIOUS_NTLD, FROM_SUSPICIOUS_NTLD_FP,HTML_FONT_LOW_CONTRAST,HTML_MESSAGE, MIME_HTML_MOSTLY,MPART_ALT_DIFF,PDS_OTHER_BAD_TLD,RCVD_IN_SBL_CSS, RCVD_IN_VALIDITY_RPBL,SPF_HELO_NONE,SPF_NONE,T_KAM_HTML_FONT_INVALID, T_SCC_BODY_TEXT_LINE,URIBL_ABUSE_SURBL,URIBL_BLACK,XM_RECPTID autolearn=spam autolearn_force=no version=3.4.6
X-Spam-Status行に記録されているのが,
スパムと判定されたメールには,
Content analysis details: (14.8 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 3.6 RCVD_IN_SBL_CSS RBL: Received via a relay in Spamhaus SBL-CSS [5.196.119.97 listed in zen.spamhaus.org] 1.9 URIBL_ABUSE_SURBL Contains an URL listed in the ABUSE SURBL blocklist [URIs: awesomewebsites.click] 1.7 URIBL_BLACK Contains an URL listed in the URIBL blacklist [URIs: awesomewebsites.click] 1.3 RCVD_IN_VALIDITY_RPBL RBL: Relay in Validity RPBL, https://senderscore.org/blocklistlookup/ [5.196.119.97 listed in bl.score.senderscore.com] ... 2.0 PDS_OTHER_BAD_TLD Untrustworthy TLDs [URI: awesomewebsites.click (click)] ... 3.0 XM_RECPTID Has spammy message header
この表では,
ざっと見,
1.
少し飛ばして,
ちなみに,
最後の3.
SAでは,
$ ls /var/lib/spamassassin/3.004006/updates_spamassassin_org 10_default_prefs.cf 20_uri_tests.cf 60_awl.cf 10_hasbase.cf 20_vbounce.cf 60_bayes_stopwords.cf ... 20_porn.cf 50_scores.cf user_prefs.template 20_ratware.cf 60_adsp_override_dkim.cf
先に見たRCVD_
$ cat -n 20_dnsbl_test.cf ... 129 # CSS is the Spamhaus CSS Component of the SBL List: https://www.spamhaus.org/css/ 130 header RCVD_IN_SBL_CSS eval:check_rbl_sub('zen', '127.0.0.3') 131 describe RCVD_IN_SBL_CSS Received via a relay in Spamhaus SBL-CSS 132 tflags RCVD_IN_SBL_CSS net 133 reuse RCVD_IN_SBL_CSS ...
このルールでは,
SAの興味深い点は,
話は変わりますが,
Apr 19 09:49:44 localhost postfix/smtp[4079]: E806A1E7804D: to=<kojima3216@gmail.com>, relay=gmail-smtp-in.l.google.com[64.233.188.27]:25, delay=1.4, delays=0.17/0.01/0.49/0.74, dsn=5.7.26, status=bounced (host gmail-smtp-in.l.google.com[64.233.188.27] said: 550-5.7.26 This message does not have authentication information or fails to 550-5.7.26 pass authentication checks. To best protect our users from spam, the 550-5.7.26 message has been blocked. Please visit 550-5.7.26 https://support.google.com/mail/answer/81126#authentication for more 550 5.7.26 information. e15-20020a17090a7c4f00b001cd51f48295si674368pjl.174 - gsmtp (in reply to end of DATA command))
同様の現象は筆者以外にも起きているようで,
なりすましメールを防ぐためのSPF
SPFやDKIMはメールの転送処理と相性が悪い,
ロシアのウクライナ侵攻に便乗したサイバー攻撃が急増した結果,
SpamAssasinが,