Print Page | Close Window

Next Release or something

Printed From: LogSat Software
Category: Spam Filter ISP
Forum Name: Spam Filter ISP Support
Forum Description: General support for Spam Filter ISP
URL: https://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=5164
Printed Date: 15 July 2025 at 4:40am


Topic: Next Release or something
Posted By: Terry
Subject: Next Release or something
Date Posted: 15 May 2005 at 1:58pm

Can we add an option where if the incoming connection gets a dns error it can be quarantined.  I am seeing a lot of "China" connections that get a dns error but the spamfilter lets them through.....wish it wouldn't do that...have I missed a setting somewhere?




Replies:
Posted By: Desperado
Date Posted: 15 May 2005 at 2:30pm

Terry,

What you are asking for, in principal, is good in many cases but, DNS Servers do fail or go down or become slow ans blocking messages due to DNS failures would cause potential false positives.  I end up parsing my logs and run scripts to add ip's that fail dns more than 3 times in a 60 minute eriod and still I run the risk of falsly bocking.

regards,



-------------
The Desperado
Dan Seligmann.
Work: http://www.mags.net
Personal: http://www.desperado.com



Posted By: LogSat
Date Posted: 15 May 2005 at 7:34pm
DNS timeouts are unfortunately too common to quarantine emails if one occurs - it would generate too many false positives. We're not inclined to add this feature in...

-------------
Roberto Franceschetti

http://www.logsat.com" rel="nofollow - LogSat Software

http://www.logsat.com/sfi-spam-filter.asp" rel="nofollow - Spam Filter ISP


Posted By: lead
Date Posted: 16 May 2005 at 12:00pm
I find too many DNS failures as well. The only (and complex way) I can see around this is to semi-quarantine email and attempt DNS resolves on them at a later time. After so many attempts the quarantine becomes solid. However I don't think spamfilter should do this, as it sounds like something too easy to break.




Posted By: Desperado
Date Posted: 16 May 2005 at 2:08pm

Hmmm ... You may be on to something.  How about if a message that doesn't resolve (rdns) gets queued and will only deliver once it *does* resolve?  Then the "ExpireRetryQueueHours=" setting will remove it after the retry time expires.  Roberto, is this possible?

Regards,



-------------
The Desperado
Dan Seligmann.
Work: http://www.mags.net
Personal: http://www.desperado.com



Posted By: LogSat
Date Posted: 16 May 2005 at 11:32pm
Not now, in theory it could be added, but it *really* would be confusing both in coding and in operating it... I'd rather archive this for a while...

-------------
Roberto Franceschetti

http://www.logsat.com" rel="nofollow - LogSat Software

http://www.logsat.com/sfi-spam-filter.asp" rel="nofollow - Spam Filter ISP



Print Page | Close Window