<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="http://syndication.webwizguide.com/rss_namespace/">
 <channel>
  <title>Spam Filter ISP Forums</title>
  <link>http://www.logsat.com/spamfilter/forums/</link>
  <description>This is an XML content feed of; Spam Filter ISP Forums : Last 10 Posts</description>
  <pubDate>Wed, 07 Jan 2009 04:49:10 +0000</pubDate>
  <lastBuildDate>Wed, 07 Jan 2009 03:58:20 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 9.06</generator>
  <ttl>30</ttl>
  <WebWizForums:feedURL>www.logsat.com/spamfilter/forums/RSS_topic_feed.asp</WebWizForums:feedURL>
  <item>
   <title>Spam Filter ISP Support : Valid mail blocked by URL Scan</title>
   <link>http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6595&amp;PID=12554#12554</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.logsat.com/spamfilter/forums/member_profile.asp?PF=10" rel="nofollow">sirrar</a><br /><strong>Subject:</strong> Valid mail blocked by URL Scan<br /><strong>Posted:</strong> 07 January 2009 at 3:58am<br /><br /><P>Hi.</P><DIV>&nbsp;</DIV><DIV>When sending a mail with a link in it (signature) It says that its blacklisted by zen.spamhaus.org. When i do a manually check at <a href="http://www.spamhaus.org" target="_blank">www.spamhaus.org</A> it states that this ip is not listed in any block list</DIV><DIV>&nbsp;</DIV><DIV>Doesn't the query look wrong? The ip is typed backwards???</DIV><DIV>&nbsp;</DIV><DIV>X-Rejection-Reason: 27 - URL in the email resolved to a blacklisted IP : (<a href="http://www.com-it.dk" target="_blank">www.com-it.dk</A>) - 521 The IP 80.63.58.114 is Blacklisted by zen.spamhaus.org. <a href="http://www.spamhaus.org/query/bl?ip=114.58.63.80" target="_blank">http://www.spamhaus.org/query/bl?ip=114.58.63.80</A> -- 521 The IP 80.63.58.114 is Blacklisted by pbl.spamhaus.org. <a href="http://www.spamhaus.org/query/bl?ip=114.58.63.80" target="_blank">http://www.spamhaus.org/query/bl?ip=114.58.63.80</A> -- </DIV><DIV>&nbsp;</DIV><DIV>Please don't get confused when doing the wrong query (the query spamfilter performs) cause I have removed the wrong ip from the list (should'nt have done that) I thought at first&nbsp;that it was spamhaus which was wrong.</DIV><DIV>&nbsp;</DIV><DIV>When i do a manually query at spamhaus it looks like this</DIV><DIV><a href="http://www.spamhaus.org/query/bl?ip=80.63.58.114" target="_blank">http://www.spamhaus.org/query/bl?ip=80.63.58.114</A></DIV><DIV>&nbsp;</DIV><DIV>Running 4.1.2.796 Licensed</DIV><span style="font-size:10px"><br /><br />Edited by sirrar - Today at 4:13am</span>]]>
   </description>
   <pubDate>Wed, 07 Jan 2009 03:58:20 +0000</pubDate>
   <guid isPermaLink="true">http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6595&amp;PID=12554#12554</guid>
  </item> 
  <item>
   <title>Spam Filter ISP Support : AutoWhiteList Force Delivery error</title>
   <link>http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6593&amp;PID=12553#12553</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.logsat.com/spamfilter/forums/member_profile.asp?PF=1091" rel="nofollow">Ed_K</a><br /><strong>Subject:</strong> AutoWhiteList Force Delivery error<br /><strong>Posted:</strong> 06 January 2009 at 8:40pm<br /><br />Hello,<br><br>We're encountering a very similar issue at one of my clients who uses SpamFilter ISP. Our OS and build are identical to the OP's except we are using Standard as opposed to Enterprise. <br><br>In this instance, the offending spam is spoofing the recipient's email address. This client's DNS provider does not allow SPF or TXT records in their DNS (I've strongly recommended that they change providers) so instead I've enabled the 'Reject if "Mail From" = "Mail To"' option under Filter Settings. <br><br>I expected that to fix it, so when it didn't, I started looking at the headers. Here is an excerpt:<br><br>X-SF-WhiteListedReason: AutoWhiteList Force Delivery<br>X-Rejection-Reason: 8 - 557 <i>client's custom SPAM message</i><br><br>I'm not sure exactly what AutoWhiteList is, but I don't see any rule in any of our White List settings that should be allowing this mail. I found that we were not logging, so I have just turned it on and will restart the service after production hours. I'll gladly forward the logs I gather to support unless a resolution is proposed in the meantime. Thanks a lot! -Ed<br><span style="font-size:10px"><br /><br />Edited by Ed_K - Yesterday at 8:41pm</span>]]>
   </description>
   <pubDate>Tue, 06 Jan 2009 20:40:10 +0000</pubDate>
   <guid isPermaLink="true">http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6593&amp;PID=12553#12553</guid>
  </item> 
  <item>
   <title>Spam Filter ISP Support : AutoWhiteList Force Delivery error</title>
   <link>http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6593&amp;PID=12552#12552</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8" rel="nofollow">LogSat</a><br /><strong>Subject:</strong> AutoWhiteList Force Delivery error<br /><strong>Posted:</strong> 06 January 2009 at 5:43pm<br /><br />rudaf,<br /><br />Did the domain "forgeddomain" actually implement SPF in their DNS? Please do note that SPF will be able to block forged spam only if the domain does have valid SPF records in their DNS.<br /><br />If that's affirmative, could you please zip and email us at support at logsat.com SpamFilter's activity logfile for a day this happened, along with the to/from email addresses involved?<br /><br />if the zip is over 5MB in size, I'll provide you with our FTP login info via a PM.]]>
   </description>
   <pubDate>Tue, 06 Jan 2009 17:43:25 +0000</pubDate>
   <guid isPermaLink="true">http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6593&amp;PID=12552#12552</guid>
  </item> 
  <item>
   <title>Spam Filter ISP Support : Using new filter resolving IP</title>
   <link>http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6594&amp;PID=12551#12551</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.logsat.com/spamfilter/forums/member_profile.asp?PF=22" rel="nofollow">Desperado</a><br /><strong>Subject:</strong> Using new filter resolving IP<br /><strong>Posted:</strong> 06 January 2009 at 4:24pm<br /><br /><P>Shade,</P><P>All you need to do is enable it.&nbsp; In the GUI, if you click on "Filter Settings" you will see a check box under Options.&nbsp; The rest is done by SpamFilter using the&nbsp;"MAPS Servers" &nbsp;specified under the Black Lists group.</P>]]>
   </description>
   <pubDate>Tue, 06 Jan 2009 16:24:24 +0000</pubDate>
   <guid isPermaLink="true">http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6594&amp;PID=12551#12551</guid>
  </item> 
  <item>
   <title>Spam Filter ISP Support : Using new filter resolving IP</title>
   <link>http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6594&amp;PID=12550#12550</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.logsat.com/spamfilter/forums/member_profile.asp?PF=230" rel="nofollow">Shade</a><br /><strong>Subject:</strong> Using new filter resolving IP<br /><strong>Posted:</strong> 06 January 2009 at 11:05am<br /><br />Dear All,<br><br>First of all, I wish a happy new year to all spamfilters's team and freaks <img src="http://www.logsat.com/spamfilter/forums/smileys/smiley1.gif" border="0" alt="Smile" /><br><br>Second, I have just upgraded to new version 4.1.2.796.<br>There is a new filter "created new filter that resolves to IPs all URLs embedded in emails,and then performs a lookup of those IPs in the MAPS RBL blacklists".<br>I'm using an entreprise edition, with MySQL database for domains.<br><br>How can I use this new filter ?<br><br>Thank you for reply !<br>Best regards,<br>Shade.<br>]]>
   </description>
   <pubDate>Tue, 06 Jan 2009 11:05:07 +0000</pubDate>
   <guid isPermaLink="true">http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6594&amp;PID=12550#12550</guid>
  </item> 
  <item>
   <title>Web Interface Mods : New WebUI supports MySQL &amp; SQL and Std an</title>
   <link>http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6112&amp;PID=12549#12549</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.logsat.com/spamfilter/forums/member_profile.asp?PF=1065" rel="nofollow">Karsten</a><br /><strong>Subject:</strong> New WebUI supports MySQL &amp; SQL and Std an<br /><strong>Posted:</strong> 06 January 2009 at 1:03am<br /><br />Hi<DIV>&nbsp;</DIV><DIV>Can you help me get it to work, I can install it and set the admin pw, but when I try to login to the site I get this error :</DIV><DIV>Cannot open the database specified by the installation. Please reinstall the Spam Filter Manager. UDL path = c:\inetpub\wwwroot\Spamweb\DbConn.udl</DIV><DIV>&nbsp;</DIV><DIV>but if I run the DbConn.udl and test the connection there is no problem ?</DIV><DIV>&nbsp;</DIV><DIV>Regards </DIV><DIV>Karsten</DIV>]]>
   </description>
   <pubDate>Tue, 06 Jan 2009 01:03:40 +0000</pubDate>
   <guid isPermaLink="true">http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6112&amp;PID=12549#12549</guid>
  </item> 
  <item>
   <title>Spam Filter ISP Support : AutoWhiteList Force Delivery error</title>
   <link>http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6593&amp;PID=12548#12548</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.logsat.com/spamfilter/forums/member_profile.asp?PF=729" rel="nofollow">rudaf</a><br /><strong>Subject:</strong> AutoWhiteList Force Delivery error<br /><strong>Posted:</strong> 05 January 2009 at 6:43pm<br /><br />SFE 4.0.1.785<DIV>SQL SERVER 2000 STD</DIV><DIV>OS WIN 2KSVR SP4</DIV><DIV>&nbsp;</DIV><DIV>We are subjected to domain forgery spam. months ago we successfully implemented SPF rules.</DIV><DIV>&nbsp;</DIV><DIV>Now a lot of forged domains and accounts spam is passing SFE (eg. <a href="mailto:forgedaccount@forgeddomain" target="_blank">forgedaccount@forgeddomain</A> to <a href="mailto:forgedaccount@forgeddomain" target="_blank">forgedaccount@forgeddomain</A>) even if the SPF filter is enabled.</DIV><DIV>&nbsp;</DIV><DIV>The log reported AutoWhiteList Force Delivery since in the autowhite list there&nbsp;was the rule <a href="mailto:*@MYDOMAIN" target="_blank">*@MYDOMAIN</A> | <a href="mailto:*@MYDOMAIN" target="_blank">*@MYDOMAIN</A></DIV><DIV>&nbsp;</DIV><DIV>Although useful to avoid intra domain false positive, we removed such a rule throuh SFE configuration control panel,&nbsp; but forged mails keep to pass the filters (AutoWhiteList Force Delivery), even if the log reports SPF Fail and mail destinated to be quatantined.</DIV><DIV>&nbsp;</DIV><DIV>Any idea?</DIV><DIV>&nbsp;</DIV><DIV>&nbsp;</DIV>]]>
   </description>
   <pubDate>Mon, 05 Jan 2009 18:43:06 +0000</pubDate>
   <guid isPermaLink="true">http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6593&amp;PID=12548#12548</guid>
  </item> 
  <item>
   <title>Spam Filter ISP Support : Table &#039;tblquarantine&#039; details</title>
   <link>http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6574&amp;PID=12547#12547</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8" rel="nofollow">LogSat</a><br /><strong>Subject:</strong> Table &#039;tblquarantine&#039; details<br /><strong>Posted:</strong> 30 December 2008 at 8:03am<br /><br />If the "expire" field is set to "1", this marks the message to be deleted the next time SpamFilter performs a database purge. The "purge" removes from the database all messages that are older than your retention period (the "number of days to store quarantine rejected emails" value in the database configuration tab in SpamFilter). The database purge occurs by default every 60 minutes.]]>
   </description>
   <pubDate>Tue, 30 Dec 2008 08:03:53 +0000</pubDate>
   <guid isPermaLink="true">http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6574&amp;PID=12547#12547</guid>
  </item> 
  <item>
   <title>Spam Filter ISP Support : Table &#039;tblquarantine&#039; details</title>
   <link>http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6574&amp;PID=12546#12546</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.logsat.com/spamfilter/forums/member_profile.asp?PF=997" rel="nofollow">suchi</a><br /><strong>Subject:</strong> Table &#039;tblquarantine&#039; details<br /><strong>Posted:</strong> 30 December 2008 at 12:19am<br /><br />ok.that is understood by me.<DIV>But what is the exact status of msg if 'deliver' field is set to '0' and 'expire' set to '1'...</DIV><DIV>I am bit confused about this.</DIV><DIV>&nbsp;</DIV><DIV>Thanks in advance.</DIV>]]>
   </description>
   <pubDate>Tue, 30 Dec 2008 00:19:29 +0000</pubDate>
   <guid isPermaLink="true">http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6574&amp;PID=12546#12546</guid>
  </item> 
  <item>
   <title>Spam Filter ISP Support : iPh&#111;nes and SMTP auth</title>
   <link>http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6190&amp;PID=12545#12545</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8" rel="nofollow">LogSat</a><br /><strong>Subject:</strong> iPh&#111;nes and SMTP auth<br /><strong>Posted:</strong> 24 December 2008 at 3:20pm<br /><br />Correct.]]>
   </description>
   <pubDate>Wed, 24 Dec 2008 15:20:38 +0000</pubDate>
   <guid isPermaLink="true">http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6190&amp;PID=12545#12545</guid>
  </item> 
 </channel>
</rss>