Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 6 of 6
  1. #1
    Member dory36's Avatar
    Join Date
    Aug 2003
    Posts
    179

    Default New high rate of false positives in Mailscanner?

    Over the past week or two I have been getting a lot of false alarms on mail that had been handled fine for many months. By "a lot" I mean maybe a dozen a day, versus about 1 a week until recently.

    Bayes seems to be to blame for many, but not all.

    I have seen before, but can't find now, info on rebuilding the bayes database. Any pointers, or other suggestions?

  2. #2
    Member
    Join Date
    May 2004
    Posts
    45

    Default

    I too noticed an increase, and the those emails had Bayes_99 scoring, which scored those particular emails at 5 and marked them as Spam. I went looking for a way to rebuild the Bayes database but couldn't find it. So I disabled Bayes checking until I had some spare time to look into it further. It's stopped the false positives, and seems to be catching all the Spam without it, so I may leave it disabled. From what i've read Bayes adds a load to the server when checking.

  3. #3
    Member verdon's Avatar
    Join Date
    Nov 2003
    Location
    Northern Ontario, Canada
    Posts
    792

    Default

    Same for me, same cause. Seems more prominent in one domain, but it is a busy domain with a lot of users.

  4. #4
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    It's due to new rules included in the base set for SpamAssassin v3.2.0. Left running they can disrupt the bayesian database and you see an increase in false-positives. You can either:

    1. Do as graham_w suggests and disable bayes, though this can be a very useful resource

    2. Increase the default low scoring spam value, though that could allow through more flase-negatives

    3. Hunt down the rules causing the problems from the false-positive email headers and adjust their scores in a custom SA ruleset in /etc/mail/spamassassin/
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  5. #5
    Member verdon's Avatar
    Join Date
    Nov 2003
    Location
    Northern Ontario, Canada
    Posts
    792

    Default

    Here's one that's typical of some of the false positives I've been getting.

    cached not
    score=9.592
    8 required
    5.00 BAYES_99 Bayesian spam probability is 99 to 100%
    3.20 FROM_LOCAL_NOVOWEL From: localpart has series of non-vowel letters
    0.00 HTML_MESSAGE HTML included in message
    1.40 MIME_QP_LONG_LINE Quoted-printable line longer than 76 chars
    -0.00 SPF_PASS SPF: sender matches SPF record

    ... hard to know what to adjust. Other than the the BAYES_99 the bulk of the score is because of the from address which is not that odd of an address, mstrbjngls@ ... the message itself is pretty normal stuff

  6. #6
    Registered User
    Join Date
    Mar 2004
    Location
    UK
    Posts
    1

    Default

    I would just add the following to what chirpy has suggested:

    4. If it seems that your bayes database has been "poisoned" by the increase in false positives, remove the bayesian database and start over. Depending on your email traffic, it may take a few days before bayes has enough spam and non-spam tokens to start scoring email again (I think it needs 200 of each before it starts working). To wipe out the bayesian db, do the following:

    rm -Rvf /var/spool/mqueue/.spamassassin

Similar Threads & Tags
Similar threads

  1. assp, mailscanner, ... false positives?
    By babakb in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 03-19-2007, 07:58 AM
  2. % of false positives for default spamassassin implementation?
    By spaceman in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 08-01-2006, 06:49 AM
  3. False Positives in "Quick Security" and "Trojan Horse" Scan
    By dwh2 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 04-29-2005, 04:52 PM
  4. hacked or false positives?
    By elleryjh in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 03-07-2005, 03:17 PM
  5. anti-spam - is no 'false positives' achievable?
    By spaceman in forum cPanel and WHM Discussions
    Replies: 8
    Last Post: 01-18-2005, 01:10 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube