The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Wrong script in spam detection system

Discussion in 'General Discussion' started by Misiek, Oct 30, 2012.

  1. Misiek

    Misiek Well-Known Member

    Joined:
    Feb 23, 2004
    Messages:
    93
    Likes Received:
    0
    Trophy Points:
    6
    Hello,
    I think there is a mistake in /etc/cpanel_exim_system_filter
    I had in one of my client Spam score set to 5, then i recieved a notice that his clients get reject message :
    Code:
    The mail server detected your message as spam and has prevented delivery (10).
    
    Then i checked exim_mainlog why is that
    Code:
    1TRhWI-000156-6O cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    
    So i try to check what is the spam score of the message :

    Code:
    X-Spam-Status: No, score=1.4
    X-Spam-Score: 14
    X-Spam-Bar: +
    X-Ham-Report: Spam detection software, running on the system ********, has
     identified this incoming email as possible spam.  The original message
     has been attached to this so you can view it (if it isn't spam) or label
     similar future email.  If you have any questions, see the administrator of that system for details.
    
     Content analysis details:   (1.4 points, 10.0 required)
     
      pts rule name              description
     ---- ---------------------- --------------------------------------------------
     -0.0 SPF_PASS               SPF: sender matches SPF record
      0.9 SPF_HELO_SOFTFAIL      SPF: HELO does not match SPF record (softfail)
      0.7 HTML_IMAGE_ONLY_28     BODY: HTML: images with 2400-2800 bytes of words
      0.0 HTML_MESSAGE           BODY: HTML included in message
     -0.2 AWL                    AWL: From: address is in the auto white-list
    X-Spam-Flag: NO
    
    
    Code:
    X-Mailer: Apple Mail (2.1283)
    X-Spam-Status: No, score=1.9
    X-Spam-Score: 19
    X-Spam-Bar: +
    X-Ham-Report: Spam detection software, running on the system "*******", has
    identified this incoming email as possible spam.  The original message
    has been attached to this so you can view it (if it isn't spam) or label
    similar future email.  If you have any questions, see
    the administrator of that system for details.
    
    Content preview:  
    
    Content analysis details:   (1.9 points, 5.0 required)
    
     pts rule name              description
    ---- ---------------------- --------------------------------------------------
    -0.7 RCVD_IN_DNSWL_LOW      RBL: Sender listed at http://www.dnswl.org/, low
                                trust
                                [74.125.82.41 listed in list.dnswl.org]
     0.0 FREEMAIL_FROM          Sender email is commonly abused enduser mail provider
                                (guillaumedelebecque[at]gmail.com)
    -0.0 SPF_PASS               SPF: sender matches SPF record
     0.8 HTML_IMAGE_RATIO_02    BODY: HTML has a low ratio of text to image area
     0.0 HTML_MESSAGE           BODY: HTML included in message
     1.8 HTML_IMAGE_ONLY_08     BODY: HTML: images with 400-800 bytes of words
    X-Spam-Flag: NO
    
    So score is 1.4 spam score is 14 second case score 1.9 spam score 19 but the message should not be classified as spam but in /etc/cpanel_exim_system_filter i found this :

    Code:
    # The spam score is the "int" value.  For example a spam score of 2.5 would be 25
    # and a spam score of 5.0 would be 50
    
    if ($h_X-Spam-Score: matches \N^\d+$\N and $h_X-Spam-Score: is above 10)
    then
        fail text "The mail server detected your message as spam and has prevented delivery (10)."
    endif
    # END - Included from /usr/local/cpanel/etc/exim/sysfilter/options/fail_spam_score_over_int
    
    So the question now is Spam score is 14 or is it 1.4, in my opinion there is an error and should be is above 100 not above 10
     
    #1 Misiek, Oct 30, 2012
    Last edited: Oct 30, 2012
  2. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    14,455
    Likes Received:
    195
    Trophy Points:
    63
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    You might want to open a ticket about this to cPanel Technical Support. From in your WHM, top of any page on right is a small menu with a link to "Contact cPanel".
     
  3. Misiek

    Misiek Well-Known Member

    Joined:
    Feb 23, 2004
    Messages:
    93
    Likes Received:
    0
    Trophy Points:
    6
    I did that now but its more like a bug then a server specific error.
     
  4. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    14,455
    Likes Received:
    195
    Trophy Points:
    63
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    Would you mind posting the ticket ID here please? I'd like to follow along with it if I could.

    It's always best to log bugs into the system so that cPanel can track an issue against other similar issues, if needed.

    Either way, you're in good hands with the ticket. :)


    Thanks!
     
  5. Misiek

    Misiek Well-Known Member

    Joined:
    Feb 23, 2004
    Messages:
    93
    Likes Received:
    0
    Trophy Points:
    6
    Ticket ID : 3338151

    A little proof that im right :)

    Code:
    2012-10-30 12:46:10 1TTAGn-00081k-JC cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 12:50:11 1TTAKg-0000I9-TI cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 12:51:15 1TTALi-0000U0-AZ cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 12:52:34 1TTAMz-0000hw-Qn cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 12:54:26 1TTAOo-00014w-3E cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:02:08 1TTAWF-0002gM-U3 cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:04:19 1TTAY8-00036k-8P cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:06:39 1TTAac-0003cC-8U cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:08:02 1TTAby-0003pE-0d cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:09:28 1TTAdM-00046O-5C cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:14:22 1TTAhw-0004uK-Qm cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:15:55 1TTAjW-0005EV-C2 cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:17:44 1TTAlL-0005cs-Ud cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:18:29 1TTAm5-0005lG-4J cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:18:55 1TTAmR-0005ox-NL cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:19:37 1TTAnB-0005yC-2r cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:20:53 1TTAoO-0006CF-Qy cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:21:33 1TTAp3-0006LA-CX cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:25:56 1TTAtH-00076E-I0 cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:27:49 1TTAv7-0007U7-0A cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:28:00 1TTAvI-0007WN-9J cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:35:49 1TTB2r-0000h0-4H cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:35:49 1TTB2r-0000gz-60 cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:36:45 1TTB3l-0000rd-H1 cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:37:42 1TTB4g-00013M-3j cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:38:20 1TTB5G-0001AR-0n cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:38:47 1TTB5h-0001F3-Dw cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:40:49 1TTB7f-0001d4-Dw cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:40:56 1TTB7n-0001f4-G1 cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:41:08 1TTB80-0001h1-EB cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:41:08 1TTB80-0001h2-Hm cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:42:59 1TTB9m-0001y2-D1 cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:44:15 1TTBB0-0002BO-JN cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:44:47 1TTBBW-0002Hp-Ks cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:45:16 1TTBC0-0002OY-5o cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:48:54 1TTBFW-00032N-CI cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:51:45 1TTBIG-0003cK-Al cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    2012-10-30 13:52:17 1TTBIn-0003iY-L9 cancelled by system filter: The mail server detected your message as spam and has prevented delivery (10).
    
    At 14:02 i made changes to system filter :) All of above had SPAM Score lower then 10.0
     
    #5 Misiek, Oct 30, 2012
    Last edited: Oct 30, 2012
  6. nyjimbo

    nyjimbo Well-Known Member

    Joined:
    Jan 25, 2003
    Messages:
    1,125
    Likes Received:
    0
    Trophy Points:
    36
    Location:
    New York
    Just upgraded a 11.32 Centos machine to 11.34 and sure enough this damn thing came up again.

    "This message was created automatically by mail delivery software.

    A message that you sent could not be delivered to one or more of its
    recipients. This is a permanent error. The following address(es) failed:

    xxxxxx@xxxxx.com
    The mail server detected your message as spam and has prevented delivery (100)."

    Why do we have to keep dealing with this kind of nonsense.
     
  7. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    14,455
    Likes Received:
    195
    Trophy Points:
    63
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    nyjimbo, what do you have set here in the EXIM Configuration Editor:

    Filters > SpamAssassin™: bounce spam score threshold [?]
    Bounce mail when the spam score is above this number. (positive or negative, single digit after a decimal point allowed)
     
Loading...

Share This Page