<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="http://syndication.webwiz.co.uk/rss_namespace/">
 <channel>
  <title>Spam Filter ISP Forums : GreyListing Release</title>
  <link>https://www.logsat.com/spamfilter/forums/</link>
  <description><![CDATA[This is an XML content feed of; Spam Filter ISP Forums : Spam Filter ISP Support : GreyListing Release]]></description>
  <pubDate>Tue, 14 Jul 2026 18:49:37 +0000</pubDate>
  <lastBuildDate>Sun, 20 Jan 2013 02:35:01 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 11.04</generator>
  <ttl>360</ttl>
  <WebWizForums:feedURL>https://www.logsat.com/spamfilter/forums/RSS_post_feed.asp?TID=7049</WebWizForums:feedURL>
  <image>
   <title><![CDATA[Spam Filter ISP Forums]]></title>
   <url>https://www.logsat.com/spamfilter/forums/forum_images/web_wiz_forums.png</url>
   <link>https://www.logsat.com/spamfilter/forums/</link>
  </image>
  <item>
   <title><![CDATA[GreyListing Release : If a server is no longer greylisted...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7049&amp;PID=14471&amp;title=greylisting-release#14471</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=104">yapadu</a><br /><strong>Subject:</strong> 7049<br /><strong>Posted:</strong> 20 January 2013 at 2:35am<br /><br />If a server is no longer greylisted the connection from the remote server is allowed.&nbsp; That does not mean the server is whitelisted, the rest of the filtering systems should still be working.<br><br><br>]]>
   </description>
   <pubDate>Sun, 20 Jan 2013 02:35:01 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7049&amp;PID=14471&amp;title=greylisting-release#14471</guid>
  </item> 
  <item>
   <title><![CDATA[GreyListing Release : Hi RobertoThanks for your reply....]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7049&amp;PID=14470&amp;title=greylisting-release#14470</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=1339">Bluefly</a><br /><strong>Subject:</strong> 7049<br /><strong>Posted:</strong> 15 January 2013 at 11:43pm<br /><br />Hi Roberto<br><br>Thanks for your reply. I may not have made my point very clear. I was not suggesting removing the IP from the list but from the cache. If a real mail server tries to send an email and finds it greylisted, it should retry within a few minutes, after which the IP will be whitelisted. It is the cache which seems to be holding IPs for hours. I can't see why this would be necessary. In my case, I believe that the compromised server is sending a DIFFERENT email some time later and, because the IP is already in greylist limbo, it is being flagged as okay and white listed. This then opens the door for more spam from that source. If this is the case, and I admit it may not be, then clearing the cache of a listed IP after 10 or 20 minutes would go some way to solve the problem. <br><br>Craig <br>]]>
   </description>
   <pubDate>Tue, 15 Jan 2013 23:43:44 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7049&amp;PID=14470&amp;title=greylisting-release#14470</guid>
  </item> 
  <item>
   <title><![CDATA[GreyListing Release : If an IP was to be removed from...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7049&amp;PID=14469&amp;title=greylisting-release#14469</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8">LogSat</a><br /><strong>Subject:</strong> 7049<br /><strong>Posted:</strong> 15 January 2013 at 10:59pm<br /><br />If an IP was to be removed from the list of IPs that have passed the greylist test after a few hours, or even after a few days, this could result in too many emails being delayed, especially if the sender's domain does not send out many emails to your domain. This is because if for example a domain sends you an email once a day, and the IP for their mail server was removed from the greylist approved senders, each day the sender's mail server would send an email, the initial email would fail, and they would have to wait until the next re-try to re-send it. This could delay that email 20-30 minutes each day, which cold cause several complains, especially since this scenario would repeat itself for any domain that doesn't send you multiple emails per day.<div><br></div><div>The greylist filter is designed to be a first barrier from spammer bots. If a spam bot (very inefficiently) retries to send spam to the same server, this will indeed cause them to pass the greylist filter from that point on. This is how greylist filters are designed to work. There should be hopefully other filters that will catch that spam, even though of course no antispam software is perfect and some will make it thru.</div>]]>
   </description>
   <pubDate>Tue, 15 Jan 2013 22:59:41 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7049&amp;PID=14469&amp;title=greylisting-release#14469</guid>
  </item> 
  <item>
   <title><![CDATA[GreyListing Release : I have a new issue with emails...]]></title>
   <link>https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7049&amp;PID=14468&amp;title=greylisting-release#14468</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="https://www.logsat.com/spamfilter/forums/member_profile.asp?PF=1339">Bluefly</a><br /><strong>Subject:</strong> 7049<br /><strong>Posted:</strong> 15 January 2013 at 9:36pm<br /><br />I have a new issue with emails being delivered from obviouly compromised home computers (based on their DNS names) which are making it through grey listing. From what I can gather, the initial connection from the computer is correctly sent to the grey list cache. However, if another spam email is later sent from the same IP, it is released from greylist limbo and the address white listed. This could be hours later. The email is forwarded and, generally, picked up by the Outlook junk mail filter. <br><br>This not the behaviour of a correctly RFC configured mail server but it seems to have the same effect from the point of the greylist filter in that the filter seems to "think" that a server is reconnecting (I think).&nbsp; <br><br>Is there some way to control this or at least clear the greylist cache after, say 20 minutes of listing an IP address? I've noticed entries in the cache that are more than 7 hours old. <br><br>An example follows:<br><br>01/15/13 23:17:22:446 -- (3900) Detected TCP Connection: 62.83.170.235<br>01/15/13 23:17:22:446 -- (3900) Connection from: 62.83.170.235&nbsp; -&nbsp; Originating country : Spain<br>01/15/13 23:17:22:446 -- (3900) GreyList limbo - Added 62.83.170.235<br>01/15/13 23:17:22:446 -- (3900) IP is in not in GreyList Allowed. Disconnecting: 62.83.170.235<br>01/15/13 23:17:22:462 -- (3900) No Data Received<br>01/15/13 23:17:22:462 -- (3900) Disconnect<br><br>01/16/13 03:48:20:977 -- (3840) Detected TCP Connection: 62.83.170.235<br>01/16/13 03:48:20:977 -- (3840) Connection from: 62.83.170.235&nbsp; -&nbsp; Originating country : Spain<br>01/16/13 03:48:20:977 -- (3840) GreyList cache - 62.83.170.235 removed from limbo, will add to allowed list<br>01/16/13 03:48:20:977 -- (3840) IP Greylist - Added 62.83.170.235 to list<br>01/16/13 03:48:21:727 -- (3840) Received MAIL FROM: &lt;ecizxvtrpoecb@cla.co.uk&gt;<br><br>]]>
   </description>
   <pubDate>Tue, 15 Jan 2013 21:36:16 +0000</pubDate>
   <guid isPermaLink="true">https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=7049&amp;PID=14468&amp;title=greylisting-release#14468</guid>
  </item> 
 </channel>
</rss>