<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="http://syndication.webwiz.co.uk/rss_namespace/">
 <channel>
  <title>Spam Filter ISP Forums : spam passing filters</title>
  <link>https://www.logsat.com/spamfilter/forums/</link>
  <description><![CDATA[This is an XML content feed of; Spam Filter ISP Forums : Spam Filter ISP Support : spam passing filters]]></description>
  <pubDate>Wed, 11 Mar 2026 05:57:25 +0000</pubDate>
  <lastBuildDate>Fri, 07 Nov 2008 08:55:41 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 11.04</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://www.logsat.com/spamfilter/forums/RSS_post_feed.asp?TID=6575</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Spam Filter ISP Forums]]></title>
   <url>https://www.logsat.com/spamfilter/forums/forum_images/web_wiz_forums.png</url>
   <link>https://www.logsat.com/spamfilter/forums/</link>
  </image>
  <item>
   <title><![CDATA[spam passing filters : Sounds like a good solution to...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6575&amp;PID=12482&amp;title=spam-passing-filters#12482</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=261">StevenJohns</a><br /><strong>Subject:</strong> 6575<br /><strong>Posted:</strong> 07 November 2008 at 8:55am<br /><br />Sounds like a good solution to me, PLEASE do NOT limit it to one IP though.....<DIV>&nbsp;</DIV><DIV>Cheers</DIV>]]>
   </description>
   <pubDate>Fri, 07 Nov 2008 08:55:41 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6575&amp;PID=12482&amp;title=spam-passing-filters#12482</guid>
  </item> 
  <item>
   <title><![CDATA[spam passing filters : That is *exactly* what we had...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6575&amp;PID=12481&amp;title=spam-passing-filters#12481</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 6575<br /><strong>Posted:</strong> 07 November 2008 at 8:39am<br /><br />That is *exactly* what we had in mind as well  <img src="https://www.logsat.com/spamfilter/forums/smileys/smiley1.gif" border="0" align="middle" /><br /><br />We'll keep this thread updated if this is something that can be implemented in a reasonable amount of time.]]>
   </description>
   <pubDate>Fri, 07 Nov 2008 08:39:32 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6575&amp;PID=12481&amp;title=spam-passing-filters#12481</guid>
  </item> 
  <item>
   <title><![CDATA[spam passing filters : Robert,  Is it not possible...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6575&amp;PID=12478&amp;title=spam-passing-filters#12478</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=101">2CNL</a><br /><strong>Subject:</strong> 6575<br /><strong>Posted:</strong> 07 November 2008 at 2:43am<br /><br />Robert,<DIV>&nbsp;</DIV><DIV>Is it not possible to make a sort of doublecheckip entry in logsat ini file, combined with a filer, where the secondary SMTP server or other specific ip numbers are checked in the headerinfo.</DIV><DIV>I guess one of the reasons to not implement options like these is performance? If so,&nbsp;if it is only reserved for a sinlge or a few ip numbers the performance impactr would be less.</DIV><DIV>Just my 2c&nbsp; ;)</DIV><DIV>&nbsp;</DIV><DIV>&nbsp;</DIV><DIV>&nbsp;</DIV>]]>
   </description>
   <pubDate>Fri, 07 Nov 2008 02:43:24 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6575&amp;PID=12478&amp;title=spam-passing-filters#12478</guid>
  </item> 
  <item>
   <title><![CDATA[spam passing filters :    StevenJohns wrote:However,...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6575&amp;PID=12476&amp;title=spam-passing-filters#12476</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 6575<br /><strong>Posted:</strong> 06 November 2008 at 5:49pm<br /><br /><table width="99%"><tr><td class="BBquote"><img src="forum_images/quote_box.png" title="Originally posted by StevenJohns" alt="Originally posted by StevenJohns" style="vertical-align: text-bottom;" /> <strong>StevenJohns wrote:</strong><br /><br />However, only a fool and his dog would only have one email server, so it stands to reason that everyone should have a backup Mx server, and some people might want that to be hosted be their ISP. This in turn means that we MUST have a way of filtering the emails which come through the backup MX.</td></tr></table><br>Most admins who have multiple SMTP servers either have SpamFilter (or another product) running on their backup MX server as well, or use network load-balancing (ex. Cisco CSS switches, Windows load balancing, etc) to balance two servers behind a single IP (their primary MX record). We do have a growing number or admins however as yourself, who rely on their ISP to serve as their backup MX record. If the ISP is not running SpamFiltering, then the issues you bring up are indeed issues. We do always listen to everyone's feedback, which is partly why SpamFilter has become so powerful/flexible, as many many times we do implement user's request. We're evaluating this one to see how to proceed.<br><br><br><table width="99%"><tr><td class="BBquote"><img src="forum_images/quote_box.png" title="Originally posted by Bart" alt="Originally posted by Bart" style="vertical-align: text-bottom;" /> <strong>Bart wrote:</strong><br /><br />I never realy read the license agreement but is it legal toinstall SpamFilterISP enterprise on a second machine to be used asfall-back server or do i have to purchase a second license for a serverthat is online there in case something goes wrong ?</td></tr></table><br>SpamFilter requires a licens for every production server it is installed on. If the second server is used as a secondary MX record, or as a secondary server in a load-balance scenario, yes, a license is required on the 2nd server as well. If you have SpamFilter installed on a spare server, but the server does not process emails until you manually place it online, then in this case as it won't process emails until you manually intervene to replace your "down" server with this backup one, we will not require a second license.<br>]]>
   </description>
   <pubDate>Thu, 06 Nov 2008 17:49:59 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6575&amp;PID=12476&amp;title=spam-passing-filters#12476</guid>
  </item> 
  <item>
   <title><![CDATA[spam passing filters : I never realy read the license...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6575&amp;PID=12474&amp;title=spam-passing-filters#12474</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=979">Bart</a><br /><strong>Subject:</strong> 6575<br /><strong>Posted:</strong> 06 November 2008 at 10:40am<br /><br />I never realy read the license agreement but is it legal to install SpamFilterISP enterprise on a second machine to be used as fall-back server or do i have to purchase a second license for a server that is online there in case something goes wrong ?<DIV>&nbsp;</DIV><DIV>I only have 1 server running now but have the same problem that fallback servers are a problem fighting spam</DIV>]]>
   </description>
   <pubDate>Thu, 06 Nov 2008 10:40:45 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6575&amp;PID=12474&amp;title=spam-passing-filters#12474</guid>
  </item> 
  <item>
   <title><![CDATA[spam passing filters : Roberto,  I understand your...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6575&amp;PID=12473&amp;title=spam-passing-filters#12473</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=261">StevenJohns</a><br /><strong>Subject:</strong> 6575<br /><strong>Posted:</strong> 06 November 2008 at 9:02am<br /><br />Roberto,<DIV>&nbsp;</DIV><DIV>I understand your issues as you have explained them and I can understand the reasons for checking the IP filters at TCP connection time. However, only a fool and his dog would only have one email server, so it stands to reason that everyone should have a backup Mx server, and some people might want that to be hosted be their ISP. This in turn means that we MUST have a way of filtering the emails which come through the backup MX.</DIV><DIV>As I said, we send our emails through SpamAssassin after SF specifically because SF does not scan the headers (we turn off all other Spam Assassin filters).</DIV><DIV>&nbsp;</DIV><DIV>Still a good product, but I feel you may be hitting brick walls soon due to design desicions made years ago.</DIV><DIV>&nbsp;</DIV><DIV>Cheers.</DIV>]]>
   </description>
   <pubDate>Thu, 06 Nov 2008 09:02:30 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6575&amp;PID=12473&amp;title=spam-passing-filters#12473</guid>
  </item> 
  <item>
   <title><![CDATA[spam passing filters : StevenJohns,  There&amp;#039;s two...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6575&amp;PID=12471&amp;title=spam-passing-filters#12471</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 6575<br /><strong>Posted:</strong> 05 November 2008 at 4:16pm<br /><br />StevenJohns,<br /><br />There's two main issues. The first is ours, and is caused by how SpamFilter applies its filters. All the IP-based filters are checked before the email is actually received, and are thus applied super-fast. If we were to check the IP in the headers as well, we'd have to receive the email as well and then go back and re-apply the IP filters. That will involve quite a bit of work... but as I said that's an internal matter  <img src="https://www.logsat.com/spamfilter/forums/smileys/smiley1.gif" border="0" align="middle" /><br />The second issue is that we've always made it a point since SpamFilter v1.0 six years ago of *not* checking the headers, as they can always be faked. For example, if SpamFilter were to check the IP in the last header, a spammer could add a fake header listing gmail's IP at the top of the email, and send it thru a host not yet IP-blacklisted. If the email is determined to be spam by the other filters, we risk blocking gmail's IP as well. There would have to be a lot of confusing if/then logic to determine what IPs are then reported as spammers and which not. An option would be to only check the last received header if the email has been received by a specific IP (the secondary MX server)...<br />We're going to do some brainstorming to see what can be done, as this subject is appearing more and more often recently.]]>
   </description>
   <pubDate>Wed, 05 Nov 2008 16:16:18 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6575&amp;PID=12471&amp;title=spam-passing-filters#12471</guid>
  </item> 
  <item>
   <title><![CDATA[spam passing filters : Roberto,  As 2CNL have added...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6575&amp;PID=12469&amp;title=spam-passing-filters#12469</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=261">StevenJohns</a><br /><strong>Subject:</strong> 6575<br /><strong>Posted:</strong> 05 November 2008 at 7:51am<br /><br />Roberto,<DIV>&nbsp;</DIV><DIV>As 2CNL have added the IP of their ISP's mail server to the greylistallowed, and they are using it as a backup MX, then I would have thought that SF could recieve the email, then check in the headers for the IP address which sent the email to the backup MX server....these IP's are inserted as the email passes every mail server, and I wouldn't have thought that their ISP would forge the headers.....</DIV><DIV>&nbsp;</DIV><DIV>2CNL...</DIV><DIV>We have seen an increase in email slipping through SF (with no real answer as to why), but we pass our email through another two filter levels which normally pick up all of these emails. As a cheap method, you could pass emails from SF through SpamAssassin to see if it picks up the 6%, I bet it would as it checks the IP's in all the recieved headers which SF does not do (for some strange reason??).</DIV><DIV>&nbsp;</DIV><DIV>&nbsp;</DIV>]]>
   </description>
   <pubDate>Wed, 05 Nov 2008 07:51:09 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6575&amp;PID=12469&amp;title=spam-passing-filters#12469</guid>
  </item> 
  <item>
   <title><![CDATA[spam passing filters : 2CNL,  If you were to have Outlook&amp;#039;s...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6575&amp;PID=12466&amp;title=spam-passing-filters#12466</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 6575<br /><strong>Posted:</strong> 04 November 2008 at 3:18pm<br /><br />2CNL,<br /><br />If you were to have Outlook's junk filter receive <em>all</em> of your emails rather than SpamFilter, you would see that much more than 6% of spam would slip thru. As SpamFilter will never be 100% accurate, some spam will go undetected. It is almost a certainty that another application can further stop some of this remaining spam.<br /><br />The main issue here is that you have another SMTP server which is receiving and processing your incoming emails in addition to SpamFilter. SpamFilter *must* see the original IP of the sender to stop spam effectively. All of our most efficient filters require to see that IP in order to do their job and stop the spam. If your secondary server processes emails first, and then passes them on to SpamFilter, the only filters that can then check emails for spam are the Bayesian filter, the SURBL filter and your keyword (if you specified any). These filters will only stop a very small percentage of emails, and thus will not be able to noticeably stop spam being forwarded by your secondary SMTP server.<br /><br /> In regards to the numbers above, please do note that many connection attempts are just "probes" that don't result in emails to be sent. Furthermore, SpamFilter caches for a few minutes IPs that sent large amounts of spam in a certain timeframe, and further connection attempts from them are rejected without any emails being transferred. All these factors mean that the statistics are to be taken with a grain of salt, as the numbers will never add up, and in some cases there will be noticeable discrepancies.]]>
   </description>
   <pubDate>Tue, 04 Nov 2008 15:18:36 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6575&amp;PID=12466&amp;title=spam-passing-filters#12466</guid>
  </item> 
  <item>
   <title><![CDATA[spam passing filters : Still approx 6% of the spam is...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6575&amp;PID=12465&amp;title=spam-passing-filters#12465</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=101">2CNL</a><br /><strong>Subject:</strong> 6575<br /><strong>Posted:</strong> 04 November 2008 at 7:43am<br /><br />Still approx 6% of the spam is passing through the logsat filters.<br>Some of this spam is very obvious and the real pain is, even the outlook unwanted mail list is collecting them, but logsat is not. It seems all these mails are coming from the backup smtp server ( of our isp) i put on the greyrlistallowed .<br>Any thougths what can be the cause of this passed spam.<br><br>Remarkable, but not very creal what is the cause are the following figures.<br>total inbound connections server: 540.000<br>emails forwarded 26000<br>emails blocked 82000<br>email attempts 15000<br><br>is this normal behaviour?<br><br>]]>
   </description>
   <pubDate>Tue, 04 Nov 2008 07:43:33 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6575&amp;PID=12465&amp;title=spam-passing-filters#12465</guid>
  </item> 
 </channel>
</rss>