Page 1 of 1

Emails from new accounts being tagged as spam

Posted: 22 Jan 2010, 16:12
by teck
We've setup some new accounts on the server and emails between the various accounts on the same server are being tagged as spam: "Subject: {Spam?} Re: XXXXX"

I checked the new domain in the mailscanner reports and it's indeed there:

domain.com added to spam.scanning.rules
domain.com added to virus.scanning.rules
domain.com added to spam.action.rules
domain.com added to spamhigh.action.rules
domain.com added to virus.delivery.rules

I've done the SA fix back when it was posted in the blog on 1/1 but this issue is happening even today.

Any ideas?

Posted: 25 Jan 2010, 14:57
by teck
Here are the full headers. Any help will be greatly appreciated:

From: User <user@domain.com>
Subject: {Spam?} Website
Date: January 24, 2010 8:00:28 PM EST
To: User2 <user2@domain2.com>
Return-Path: <user@domain.com>
Envelope-To: user2@domain2.com
Delivery-Date: Sun, 24 Jan 2010 20:00:40 -0500
Received: from 12.sub-75-xxx-xxx.myvzw.com ([75.xxx.xxx.xxx]) by server.server.net with esmtps (TLSv1:AES256-SHA:256) (Exim 4.69) (envelope-from <user@domain.com>) id 1NZDJk-0001Py-1f for user2@domain2.com; Sun, 24 Jan 2010 20:00:36 -0500
Message-Id: <4B5CED2C.1070007@domain.com>
User-Agent: Thunderbird 2.0.0.23 (Windows/20090812)
Mime-Version: 1.0
Content-Type: multipart/mixed; boundary="------------090907040706020300010302"
X-Acl-Warn: {
X-server-Mailscanner-Information: Please contact the ISP for more information
X-server-Mailscanner-Id: 1NZDJk-0001Py-1f
X-server-Mailscanner: Found to be clean
X-server-Mailscanner-Spamcheck: spam, SpamAssassin (not cached, score=13.319, required 5, autolearn=spam, BAYES_40 -0.18, BOTNET 1.50, BOTNET_CLIENT 0.10, BOTNET_IPINHOSTNAME 0.10, FH_HELO_ALMOST_IP 5.42, FH_HOST_ALMOST_IP 1.89, HELO_DYNAMIC_SPLIT_IP 3.49, RCVD_IN_PBL 0.91, RDNS_DYNAMIC 0.10)
X-server-Mailscanner-Spamscore: sssssssssssss
X-server-Mailscanner-From: user@domain.com

Both domains are on the same server. I've checked the faq and I can't figure out what is wrong. Any help would be appreciated.

Posted: 25 Jan 2010, 15:30
by teck
I did a search and it looks like the user on the sending domain is using a isp on a rbl which may be the reason SA is tagging it as spam. Is there a way to have all domains local to the server bypass SA or mailscanner?

Posted: 07 Feb 2010, 10:28
by Sarah
No, there's no way to have local domains or local emails only bypassed by SA or MailScanner. Please see this FAQ entry:
http://www.configserver.com/techfaq/index.php?faqid=70