Thursday, April 26, 2007

 

ADSL authentication

We are currently experiencing some issues with authenticating our ADSL users. The mechanism that proxies the RADIUS authentication off of the BT network is not functioning. While we are seeing the requests from authentication and granting them where correct, this data is not getting back to you.

This issue is currently seeing as being within the Thus/Demon/YourComms network and a solution from them is being persued. The issue was first discovered at 10am today. This should in theory only effect users that are either connecting afresh, or sessions are dropping and need refreshing - since routing and transit mechanisms are fine, it is initial authentication that is failing.

Thursday, April 19, 2007

 

Greylisting - A new antispam feature

GREYLISTING
Our most recent addition to our spam scanning servers is to add greylisting to our spam scanning servers.

Greylisting allows us to delay the acceptance of email by 5 minutes for hosts and domains which are not known to us. Once the 5 minute delay has expired email from the host/domain is accepted immediately and will continue through the usual scanning processes.

A normal mail server sending mail will have no problems in retrying the mail delivery after 5 minutes has expired. Where the inbound mail is being sent from a compromised server or PC, the spam software does not normally run a queue for delayed mail and so the mail is never resent. The statistics of the last 48 hours suggest as many as 50% of the servers attempting to deliver mail which pass the RBL tests are not genuine mail servers as they never attempt to deliver the mail a second time.

Customers should be aware that mail will only be delayed by 5 minutes where that sender has never sent mail to our network previously. Our servers have already whitelisted many popular servers and mail addresses including hotmail, msn, yahoo and ebay.

For customers still seeing occasional spam mails it is worth ensuring that you do not have a catchall on your mail address. Where a catchall is unavoidable, identifying specific aliases that are targeted by spammers is a useful option. These aliases can then be set via our support site with a target of :fail: (include the colons) which will cause all future mail to those aliases to be rejected to the sending server.

Finally it is worth noting that the vast majority of the spam that we see can be traced back to mailto: links on websites that have been harvested by spammers. Remember, if you need to include an email address on a web page, avoid using a mailto: hyperlink

 

Anti Spam Scanning

Our new anti spam features have been running for several days now resulting in a marked decrease in spam.

Previously 89% to 90% of all inbound mail was rejected by our scanners.
As of today that figure is now closer to 93% to 94%

Tests in order and the percentage of mail rejected is as follows.
85% Spamhaus RBL
6% Other RBL's including dynamic range and our own RBL
2% Greylisting
1% Spamassassin including our custom rule set
1% Image spam

Notes :-
Our image scanner rejected over 5000 images in the last 7 days.
50% of the servers attempting to deliver mail which pass the RBL tests did not return after the 5 minute greylisting timeout.

 

LVS director reboot

Our primary LVS director crashed a short time ago (11:23:07) which required a reboot to fix.

The failure caused loss of service to POP, IMAP and web clusters 150, 212 and 156.

The total outage was less than 6 minutes, service was restored at 11:29am.

Monday, April 16, 2007

 

Reducing Image Spam

We are pleased to announce that our spam scanning service has been upgraded to include intelligent scanning of images within emails using a number of techniques including OCR (Optical Character Recognition). The system has been developed entirely in house using a third party OCR package.

A recent snapshot of statistics show.

Messages blocked by :

49,458 DNS blacklists
835 SpamAssasin
792 NEW Image scanning

4,661 Messages accepted as clean

The new scanner represents a 15% fall in the number of messages accepted for delivery.

This page is powered by Blogger. Isn't yours?