Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • 1 Votes
    1 Posts
    22 Views
    No one has replied
  • 0 Votes
    5 Posts
    187 Views
    L

    @necrevistonnezr said in MXtoolbox:

    Which site?

    Sorry, I forgot to include the link. I have updated the post now. mxtoolbox

  • 2 Votes
    16 Posts
    388 Views
    girishG

    @d19dotca right, the 30d one seems to be 54975 size. I have increased the size of the ipset now to 262144 elements. If these things are growing more, we can look into making this size dynamic .

  • Some emails going to spam

    Solved Support
    9
    3 Votes
    9 Posts
    312 Views
    C

    @THI_Staff Apologies for a late response on this. I haven't used this yet. I was grandfathered on some free monitoring elsewhere. That being said, some of the delivery reports tell you servers that attempted to send email on your behalf. That has helped me resolve some delivery issues where others were sending legitimate emails, but using one of our email addresses instead of theirs. That tripped a DMARC fail. I would start their service without and then see if you want more.

  • Further Locking Down Email

    Solved Support
    20
    0 Votes
    20 Posts
    382 Views
    girishG

    @MisterJD yeah, I have seen that some kernels have an upper limit. I haven't found a way to query this limit to show a proper error.

  • SCAMMING

    Solved Support
    9
    1 Votes
    9 Posts
    429 Views
    girishG

    Generally, we are able to manage posts which have spam content. Most existing users, they are quite benign. I think we are lucky so far with that we do little to no moderation (maybe only fixing some typos and moving to the right category) 🙂

    In this specific case, the issue was the profile page had spam content. This is a bit more elaborate and I am not sure how @SPRADEEP even came across it. I think if we have a script to clean up profiles which are over 2 weeks old and have not posted anything and have some junk profile, we can delete them. I can't imagine it's hard to spot junk in profiles with some basic word matching.

  • Sorbs Blocklist

    Solved Support
    5
    1 Votes
    5 Posts
    384 Views
    LanhildL

    @girish
    Cloudron shows IP as present on Sorbs dnsbl blocklist, even though it isn't. 2024-02-21_17-52-31.png
    2024-02-21_17-53-31.png

    Turns out I was too impatient, checks all green now.

  • 0 Votes
    10 Posts
    578 Views
    girishG

    Good notes to follow up when we look into email in the next release.

    IIRC, whitelist setting is a bit dangerous because it allows "spoofed" emails as it pretty much bypasses all the SPF/DMARC/DKIM checks. Meaning, Cloudron does not reject mail if those checks do not pass because there are too many misconfigured mail servers out there. Instead we tag the failures and allow spamassassin to score the rules. whitelisting makes spamassassin bypass the checks altogether.

  • 0 Votes
    7 Posts
    422 Views
    humptydumptyH

    @d19dotca Sadly, they do match. I'm guessing it's something with my current setup that's acting funny. I'll ignore it for now since I plan on migrating either to the new Contabo server that I got or upgrading my current one at DO to Ubuntu 20.04. I just thought it was a wrong setting on my part.

    Thank you for looking into this and for sharing the custom spam rules! I know you've put a lot of time into that 👍

    2443c4d7-ec13-4149-add3-28e1e7ad48ed-image.png

  • 0 Votes
    11 Posts
    1k Views
    A

    I end this thread because I now have a more specific one going.

  • 1 Votes
    11 Posts
    377 Views
    necrevistonnezrN

    @girish said in Anyone else see many connections denied due to "Mail from domain <domain> is not allowed from your host" repeatedly from spammy IPs?:

    @necrevistonnezr Ah, sorry! I misread. In my case, the sender is just spamming the hell out of me for video content. Sender is not trying to spoof. I guess you have to block by IP in the network firewall.

    Yeah, well, those IPs are never the same (see above) and even ranges are difficult to ascertain. Maybe an easy way to subscribe to a blocklist would help? 🙂 (as suggested in my old topic linked above…)

  • 9 Votes
    31 Posts
    3k Views
    murgeroM

    @d19dotca This looks pretty good. I am testing it now 🙂

  • 0 Votes
    2 Posts
    193 Views
    girishG

    There is a "Spam" filter type in next release - 6.4

  • 0 Votes
    5 Posts
    367 Views
    d19dotcaD

    Okay... I may be on the side of this working properly again. lol. Maybe I've been wrong this whole time in thinking it wasn't working correctly.

    So coincidentally I was checking the mail server logs and saw another example of the same message go through to the same recipient from the same mail server, it was listed in the logs as "just now" so I quickly checked mxtoolbox and found that only 4 at that time had been listed, none of which were ones I was using.

    Here is how it looked at the very moment I checked when it was "just now" in the logs:

    69bc5a02-12ca-420e-958a-27405c21f7ed-image.png

    07b937c4-4840-4c14-887b-7513acc87251-image.png

    Edit: Checking about 6 minutes later, I see the blocklists have aleady been updated for more (Spamhaus Zen in this case would have caught it if it were about 5 minutes earlier):

    4522d168-dc21-498f-845b-885cfe0a73a1-image.png

    So I guess we can probably mark this as resolved, as I now see conclusive evidence that the various blocklists used just didn't have it listed until a few minutes after the message was received. I guess in order for it to adapt so quickly this spam attack on one of my users from those mail servers must be right at the beginning of a spam wave. Kind of neat actually to see how real-time these lists are. haha.

  • 3 Votes
    10 Posts
    610 Views
    d19dotcaD

    @girish - this is not possible to do unfortunately in Cloudron it seems, but kindly tell me if I'm doing something wrong here.

    The redirect works for filtering out spam, in other words only non-spam messages get through to the endpoint email using a filter like this:

    # rule:[Forward non-spam messages] if allof (not header :contains "x-spam-status" "Yes,") { redirect "<externalEmailAddress>"; }

    However, all messages marked as spam still save in the mailbox regardless of any filters I set to discard them. In my case, I want the spam messages to be discarded/deleted automatically as there's no sense in them remaining in the "forwarding only" mailbox. It seems maybe there's a priority filter going on elsewhere in Cloudron that's overriding my sieve filter?

    Using a filter like this:

    # rule:[Discard spam messages on arrival] if allof (header :contains "x-spam-status" "Yes,") { discard; stop; }

    ... will still save the email in the Spam folder. I've tried variations of it too but no-dice. Basically I can't get any filters to work when it's an identified spam message, only filters when it's NOT spam.

    Here's a way to reproduce it:

    Set this filter in Roundcube: # rule:[Discard spam messages on arrival] if allof (header :contains "x-spam-status" "Yes,") { discard; stop; }

    Send a message to the email account using the GTUBE string which SpamAssassin automatically marks with 1000 points, it's basically a test for spam filters: XJS*C4JDBQADN1.NSBN3*2IDNEN*GTUBE-STANDARD-ANTI-UBE-TEST-EMAIL*C.34X

    See if the message is really discarded per the sieve filter or if it's still arriving in the Spam folder. In my cases, they still arrive in the Spam folder which seems to be incorrect behaviour.

    Edit: I wrote a dedicated bug for this instead: https://forum.cloudron.io/topic/5189/can-t-discard-spam-messages-on-arrival-using-sieve-filters/1

  • 0 Votes
    8 Posts
    752 Views
    danielreyes61D

    Nevermind, I did not realize sendgrid setup was only for sending email, I see the other parts to setup for receiving email now. Please disregard.

  • 1 Votes
    7 Posts
    411 Views
    ?

    @girish Will do

  • 2 Votes
    9 Posts
    532 Views
    jimcavoliJ

    I really like the blackllist checking being built-in. Frankly, I'd also be a fan of getting notifications about it. I suppose UX-wise, perhaps this is the appropriate sort of thing to trigger a yellow status on email.

  • Completely discard spam messages

    Solved Support
    11
    0 Votes
    11 Posts
    646 Views
    P

    @girish Ok

  • 2 Votes
    19 Posts
    1k Views
    P

    @marcusquinn Thank's Marcus, I'll follow your advice to check the reputation BEFORE, and if reputation is poor, just delete and purchase new one.

    Should be interesting that ISP's do themself this control and tell BEFORE the IP reputation.