On Wednesday, June 25, 2008, 5:37:30 AM, Ben Spencer wrote:
> Ok...the subject is a bit misleading. Let me clarify a little bit...
> What does it take for a domain to end up on the multi.surbl.org list?
> Realizing that multi is made up of several different lists, it might not
> be
> clear cut as each might have their own rules and in some cases it is
> more
> complicated then just end user reports.
> Background: someone complained that they couldn't email us and it turns
> out
> they were blocked because of the multi.surbl.org list. In a response we
> received from them, they stated: One person has a software program that
> erroneously flagged <the domain> as spam.
> What I am trying to confirm is that none of the multi.surbl.org lists
> actually will block on a single incident report. Reading over the
> surbl.org
> site (haven't dig into the rules for each list just yet), the lists seem
> to
> sway towards safer (no listing) then sorry end of things.
None of the lists will blacklist based solely on a user report.
Each list is pretty different.
Please report false positives to whitelist at our domain.
Jeff C.
Ok...the subject is a bit misleading. Let me clarify a little bit...
What does it take for a domain to end up on the multi.surbl.org list?
Realizing that multi is made up of several different lists, it might not
be
clear cut as each might have their own rules and in some cases it is
more
complicated then just end user reports.
Background: someone complained that they couldn't email us and it turns
out
they were blocked because of the multi.surbl.org list. In a response we
received from them, they stated: One person has a software program that
erroneously flagged <the domain> as spam.
What I am trying to confirm is that none of the multi.surbl.org lists
actually will block on a single incident report. Reading over the
surbl.org
site (haven't dig into the rules for each list just yet), the lists seem
to
sway towards safer (no listing) then sorry end of things.
Thanks
Benji Spencer
System Administrator
Moody Bible Institute
Phone: 312-329-2288
Fax: 312-329-8961
FYI - I seen a couple false positives today on mail from hotmail that
include this domain in the auto generated signature.
SignInAndWIN . ca
Example Signature:
Sign in to Windows Live Messenger, and enter for your chance to win
$1000 a day-today until May 12th. Visit SignInAndWIN . ca
<http://g.msn.ca/ca55/210>
Darrell
Hello
I have joined this discussion forum today to ask if there is anything wrong with the multi.surbl.org list? We had been using this list successfully for almost 3 years now. Beginning about 3/15/08, we are no longer getting the same number of hits as we had before. Before 3/15 we routinely saw 6000 - 8000 SuRBL hits per day. Between 3/15 and today we were seeing less then 500 hits per day.
This morning I switched our GWAVA to use black.uribl.com and am now seeing thousands of SuRBL hits. For test purposes I switched back to the multi.surbl.org but in 5 minutes didn't have any hits.
Does anyone else have this problem?
Thank you for any information.
Peter Garcia
SURBL was great when it was running. It made me wonder if I should
even run any other RBL's at all?
This is off topic already but what is generally thought to have less overhead?
It would seem to be that RBLs would but their effectiveness have
really dropped with the use of massive botnets.
Anyhow regarding my topic...
something has changed in the usage of the lists and so my false
positives has jumped.
This is doug swallows plugin for Icewarp MerakMail. (the author has
long since dropped support for this project)
http://clip.drlinky.com/149606
I have altered the scope to not include the header (from the surblg
list I was told to) and also to not scan the ip addresses but to no
avail.
I was getting false positives for test invites I was sending myself
from linked in.
I believe it is the way counting is performed that is messing things
up a bit. From the looks of it a count of 1 is rejected, but 1 is
added to everything anyway surbl_multi_count += 1
Appreciate any information
Thank you
KieranMullen
Are there any plans in the future to move the email based discussion
list to a forum based system with e-mail subscription per topics?
Thank you
KieranMullen
Judging by recent spamassassin-users mailing list messages, Verizon is
hijacking DNS responses that seem to be invalid and replacing them
with their own responses (in oder to drive traffic to their search
sites). Naturally this breaks SURBL lookups. If you are using
Verizon's nameservers and are getting false positives, you may want to
check into this.
Here's one reference:
http://www.freedom-to-tinker.com/?p=1227
Jeff C.
Does anyone have any comments on adding the malware domains at:
http://www.malwaredomains.com/
to the SURBL phising list, with significant filtering to exclude
possible false positives? The actual list would be the third field
of:
http://www.malwaredomains.com/files/domains.txt
The data includes malware and phishing sites.
Cheers,
Jeff C.
AUTOMATED REPLY
------------------------------
NCISP has taken over all support related to previous Aginet ISP services. Please contact them directly at support(a)ncisp.net if you are looking for support.
Scott Wolf
Question for admins
Is it ok if I run a list of 45k IP's I am researching, against SURBL list please ? I didn't want to do it without permission in case you suddenly thought I have become a MUCH larger company !!
Many thanks
Phil
_____________________________________________
Website Hosting from only £5.00 per month.
www.medwayhosting.com - +44 (0)1634 856965
_____________________________________________
Digital & Traditional Printing, and much more
www.medwayprint.com - +44 (0)1634 281199
_____________________________________________