Spam blocklist SORBS closed by its owner, Proofpoint
theregister.com
theregister.com
With, like, 80+% of inbound SMTP traffic coming from Google, Microsoft, Amazon and assorted non-malicious transactional/list-based SaaSes, a simple 'I either like or dislike the sending IP' approach has been infeasible for many years.
And in 2009, filtering inbound SMTP traffic using a popular DNSBL or two was definitely effective (as was greylisting). Alas, no more.
But I probably misunderstand what you're saying?
Just do a challenge-response on incoming mail from new addresses on Gmail and Outlook. Send an auto-reply telling them they can get their mail through if they copy a code in the reply. That will kill most spams from those sources.
It'd be nice if Google did something about this. Until they do, I tell everyone that uses Google for email that they have to accept that they're hosting with one of the biggest sources of spam on the Internet that, as far as I'm aware, does absolutely nothing when spam from them is forwarded to their abuse addresses.
Never auto-reply to any email ever. You're only making the spam problem worse.
(Plus, if you think there are not actual persons behind most Outlook/Gmail spam, I've got news for you. They will reply, and beg you for another chance, sometimes in highly emotional terms).
"550 5.7.1 The recipient has set a policy that prohibits email from this sender" at the SMTP level is the only way forward here.
I see a few spam a week, have never seen a false positive. I think greylisting made the biggest difference after sane-sender checks.
Looking at just a random spam I have here, I see it passed both SPF and DKIM happily. But it was marked as spam in HostKarma, Spamhaus, Truncate and flagged as Bulk by Razor.
So I dropped it. Looking at heaps of my attempted Spam emails I see the same. It seems most spammers setup SPF before attempting, or are hijacking legit sites/mailservers to send the spam.
Pretty much the only Spam I find I reject based on DMARC as well is just the "I hacked your webcam" blackmail spam that tries to "prove" they hacked you by spoofing my email domain.
I think if I disabled all RBLs the other huristics rspam gives me would still catch 90% of the Spam, but the RBLs certainly help me still catch 99.9% of the Spam attempts I recieve.
Factually untrue. You are a teenager spouting self-important garbage.
I've had it setup with protonmail for a year now and it works very well, easily automated with providers such as AWS route53 for example. So technically I could have hosted my own email that whole time, just replace the protonmail senders with my own.
As long as I get a VPS IP without a tainted reputation.
This also involves promoting sender domains from 'DATA reject' to 'MAIL FROM reject' based on behavior, since most spammers see 'MAIL FROM accept' as a win, and won't check any further results.
Nothing prevents spammers from setting up their own domain with valid spf, dkim, dmarc.
One thing that does work to combat these SPF+DKIM+DMARC valid sources, I've found, is to reject all email from supposed email servers which either don't have working reverse DNS or which have reverse DNS which has a name that differs from the HELO / EHLO name.
It used to be enough to just insist on working reverse DNS that has matching forward DNS resolution, but recently I've been testing requiring that "Return-Path" has the same domain as the HELO / EHLO.
Another thing that I've noticed but I'm not sure how to check in sendmail is to reject email that has a "Return-Path", "From", "To", or "Reply-To" that's a Gmail address when the email isn't from Gmail. I'd like the same test with Outlook / Hotmail and Yahoo. I've found almost no instances of legitimate email sent this way.
Many things to consider, now that SORBS is one less tool to use!
These days, a list of 'compromised Azure tenant IDs' (or domains abusing the Gmail API, or dodgy Salesforce senders: Microsoft is by no means the only issue here) is way more useful than anything source-IP-related...
Where do I get such a thing?
A large portion of my incoming spam seems to be coming from "xxxxx.onmicrososoft.com", which sounds like it might be what you're talking about.
To get started: 41a71966-4fa6-4839-a87d-034d66bdda33 d931cb4a-3984-4328-9fb6-96d7d7fd51b0 e85f2c00-2730-4ca5-b8d8-609b15bd4746
(all seen-in-the-wild compromised instances in the past 14 days)
I have tried sending Microsoft reports, but have not heard back, and the spam continues.
But, if you can, record the `X-MS-Exchange-CrossTenant-Id` header value for the spam you receive. If it ends in 'aaaa', that means it comes from the public outlook.com/hotmail.com service, and you'll need to do text content/from-address filtering to get rid of spam.
But otherwise, deny-listing the GUID you get, will do wonders to eliminate future spam from that source...
https://gist.github.com/digitalresistor/03ea1b8798c519a71f06...
Edit: moved list to Gist.
I check my junk folder every other day to make sure that legitimate mail does not go through because I've set my rspamd config pretty tight.
So all of these are classified correctly as spam by human eyes.
These are not that easy to filter due to the risk of false positives, but in general, a sender with a From: header matching '.*\d{1,}@(outlook|gmail|aol|yahoo|hotmail)\.com`, no To: header matching the actual recipient, and a number of keywords in the message text can be safely rejected as bizdev/SEO spam.
The big-brand spam is actually pretty easy to filter, as there are always 'tells' in the message structure. Even just requiring a match between From: display names and domains yields pretty good results, especially if you normalize the display name to eliminate homoglyphs and nearly-similar spellings.