{"id":898,"date":"2011-08-25T00:03:19","date_gmt":"2011-08-25T04:03:19","guid":{"rendered":"https:\/\/lowtek.ca\/roo\/?p=898"},"modified":"2011-08-25T00:03:19","modified_gmt":"2011-08-25T04:03:19","slug":"greylisting-with-postfix-and-ubuntu","status":"publish","type":"post","link":"https:\/\/lowtek.ca\/roo\/2011\/greylisting-with-postfix-and-ubuntu\/","title":{"rendered":"Greylisting with Postfix and Ubuntu"},"content":{"rendered":"<p><a href=\"https:\/\/lowtek.ca\/roo\/wp-content\/uploads\/2011\/08\/greyspam.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-899\" title=\"greyspam\" src=\"https:\/\/lowtek.ca\/roo\/wp-content\/uploads\/2011\/08\/greyspam.png\" alt=\"\" width=\"335\" height=\"335\" \/><\/a>Recently it seems email <a href=\"http:\/\/www.scmagazineuk.com\/security-labs-record-surge-in-malicious-spam-over-past-week-reasons-unknown\/article\/209725\/\">spam levels have been increasing<\/a>, reading through the news it seems there is <a href=\"http:\/\/www.infosecurity-magazine.com\/view\/19063\/symantec-says-spam-levels-down-but-kaspersky-says-levels-are-up\/\">some debate<\/a> if it is really up or not. Either way, I know that my local mailbox has been getting more spam (specifically more binary attachment spam) lately. As I host my own email server, addressing spam levels is something I can do something about at the server level vs. needing to rely on clever filtering by the client.<\/p>\n<p>Hosting your own email server is a little dumb. I like the challenge, and knowing my data is stored on my computer systems is comforting. Most people should just stick with<a href=\"http:\/\/en.wikipedia.org\/wiki\/Gmail\"> gmail<\/a> or similar. If you are stubborn like myself, Ubuntu makes it easy to <a href=\"https:\/\/help.ubuntu.com\/community\/MailServer\">setup your own mail server<\/a>. There is of course the other details on getting a ISP that allows you to host a server etc. (exercise left to the reader)<\/p>\n<p>One alternative is to run a local mail server that <a href=\"http:\/\/en.wikipedia.org\/wiki\/Smarthost\">smarthosts<\/a> through your ISP (<a href=\"http:\/\/braiden.org\/?p=15\">or even Google<\/a>). It can use <a href=\"http:\/\/en.wikipedia.org\/wiki\/Fetchmail\">fetchmail<\/a> or similar to suck down email from your various accounts too. This would result in your data on your machines and good spam filtering as you offload that problem to the other mail server (say gmail).<\/p>\n<p>Ok, so you&#8217;re dumb like me and while <a href=\"https:\/\/help.ubuntu.com\/community\/PostfixAmavisNew#Spamassassin\">spamassassin<\/a> is doing an ok job, it&#8217;d be nice to stop more spam from hitting your mail server. The solution is <a href=\"http:\/\/projects.puremagic.com\/greylisting\/\">greylisting<\/a>, the <a href=\"https:\/\/help.ubuntu.com\/community\/PostfixGreylisting\">Ubuntu community docs<\/a> make it very simple to setup if you&#8217;ve got a postfix based mail system setup already.<\/p>\n<p>The concept behind greylisting is very simple. Spammers are lazy and so is spam software. One of the error codes a mail server can answer back is &#8216;temporary failure&#8217;. Greylisting causes the first attempt to deliver a given email message with a temporary failure code, any properly configured mail server will retry after a short period of time (usually minutes). Spam software can&#8217;t be bothered to go back, it&#8217;s spraying email across a large number of servers and a large number of addresses &#8211; a few failures aren&#8217;t important. If you want to know more, I encourage you to <a href=\"http:\/\/projects.puremagic.com\/greylisting\/whitepaper.html\">read through the whitepaper<\/a>.<\/p>\n<p>The trade off with greylisting is that normal email can be delayed. <a href=\"http:\/\/postgrey.schweikert.ch\/\">Postgrey<\/a> uses an adaptive whitelist to allow frequent valid email to skip the temporary fail sequence. The place you&#8217;ll notice delays is when you reset a password, since the email is likely to come from a mail server you don&#8217;t often get email from &#8211; so it will be delayed by the temporary fail code.<\/p>\n<p>After a day &#8211; spam has dropped to zero, and email is still arriving in my inbox. I did have to &#8220;wait&#8221; for a password reset email that was delayed by 1041 seconds (a bit more than 17mins), the delay time is due to the sending server retry cadence.<\/p>\n<p>Looking at a year of mail traffic on my server, it doesn&#8217;t appear that volumes are up that much.<\/p>\n<p><a href=\"https:\/\/lowtek.ca\/roo\/wp-content\/uploads\/2011\/08\/one-year-mail.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-900\" title=\"one-year-mail\" src=\"https:\/\/lowtek.ca\/roo\/wp-content\/uploads\/2011\/08\/one-year-mail.png\" alt=\"\" width=\"637\" height=\"256\" \/><\/a>Looking at the weekly graph shows a spike in rejects (due to greylisting), but if you look closely you can see the drop off on viruses and spam (since greylisting prevents those messages from ever being received and processed).<\/p>\n<p><a href=\"https:\/\/lowtek.ca\/roo\/wp-content\/uploads\/2011\/08\/high-reject.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-901\" title=\"high-reject\" src=\"https:\/\/lowtek.ca\/roo\/wp-content\/uploads\/2011\/08\/high-reject.png\" alt=\"\" width=\"637\" height=\"220\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Recently it seems email spam levels have been increasing, reading through the news it seems there is some debate if it is really up or not. Either way, I know that my local mailbox has been getting more spam (specifically more binary attachment spam) lately. As I host my own email server, addressing spam levels &hellip; <a href=\"https:\/\/lowtek.ca\/roo\/2011\/greylisting-with-postfix-and-ubuntu\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Greylisting with Postfix and Ubuntu&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-898","post","type-post","status-publish","format-standard","hentry","category-computing"],"_links":{"self":[{"href":"https:\/\/lowtek.ca\/roo\/wp-json\/wp\/v2\/posts\/898","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lowtek.ca\/roo\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lowtek.ca\/roo\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lowtek.ca\/roo\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lowtek.ca\/roo\/wp-json\/wp\/v2\/comments?post=898"}],"version-history":[{"count":2,"href":"https:\/\/lowtek.ca\/roo\/wp-json\/wp\/v2\/posts\/898\/revisions"}],"predecessor-version":[{"id":903,"href":"https:\/\/lowtek.ca\/roo\/wp-json\/wp\/v2\/posts\/898\/revisions\/903"}],"wp:attachment":[{"href":"https:\/\/lowtek.ca\/roo\/wp-json\/wp\/v2\/media?parent=898"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lowtek.ca\/roo\/wp-json\/wp\/v2\/categories?post=898"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lowtek.ca\/roo\/wp-json\/wp\/v2\/tags?post=898"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}