ietf
[Top] [All Lists]

Re: Corporate email attachment filters and IETF emails

2009-12-30 08:11:06
Well we finally tracked down the problem!!!!

Part of the delay was, I was not going to submit a fake ID to run this down, but was just working toward the -01 version which I submitted yesterday.....

Dave CROCKER wrote:


Robert Moskowitz wrote:
But the short of it is that only a small selection of email attachments are let through and otherwise the email is dropped silently. Thus the email for validating an ID submission never got to my corporate email account.


I doubt that I-D transaction messages conform to any common abuse template. As Russ notes, there's no attachment, but I do not, offhand, know any any interesting vocabulary or text pattern in these messages that ought to be problematic. Even the included URL ought not to be all that interesting to filtering code.

Consequently, it could be interesting to track down why your corporate filters are flagging these.

Ho boy, this was interesting:

==============================================================

Bob,

I think I found the problem.  For this particular message, something in
the message is triggering the adult spam rule and the message is being
discarded. See "action-discard" in the filter log query below.

I will safe list this address
and I have added a rule to classify anything with the string "I-D
Submitter Authentication for draft" to NOT be classified as spam.
Unfortunately, I don't have a copy of the entire message, only the
header information.  Please submit your request (again, and I'm sorry)
and I'll follow it though again.

filter.log.20091229133738:[2009-12-29 13:49:41.105443 +0000] trce
s=jy7be8shq mod=mltr cmd=rcptto
addr=<robert(_dot_)moskowitz(_at_)verizonbusiness(_dot_)com>
filter.log.20091229133738:[2009-12-29 13:49:41.108045 +0000] trce
s=jy7be8shq m=1 x=nBTDne4N011260 mod=session cmd=rcptto
data=<robert(_dot_)moskowitz(_at_)verizonbusiness(_dot_)com>
filter.log.20091229133738:[2009-12-29 13:49:41.110406 +0000] rprt
s=jy7be8shq m=1 x=nBTDne4N011260 mod=mail cmd=env_rcpt r=1
value=robert(_dot_)moskowitz(_at_)verizonbusiness(_dot_)com verified= routes=
filter.log.20091229133738:[2009-12-29 13:49:41.110651 +0000] debg
s=jy7be8shq m=1 x=nBTDne4N011260 mod=session cmd=rcptto
data=<robert(_dot_)moskowitz(_at_)verizonbusiness(_dot_)com>  duration=0.003
filter.log.20091229133738:[2009-12-29 13:49:41.690626 +0000] rprt
s=jy7be8shq m=1 x=nBTDne4N011260 mod=mail cmd=msg module=spam
rule=notspam_adultspam action=discard attachments=0 rcpts=1 routes=
size=1897 guid=fcf05cb1989e39177f93e4b510f07261
hdr_mid=<20091229134958(_dot_)C53313A68AE(_at_)-------------(_dot_)com> 
qid=nBTDne4N011260
subject="I-D Submitter Authentication for
draft-moskowitz-hip-rfc4423-bis" duration=0.504 elapsed=0.590

=======================================================================================

Once we cleared this up, the system sent me another auth email this morning 
that got properly caught in the spamblocker that I was able to release and 
safelist.

My hunch it is all that NASTY stuff in the auth key that set the filters off!  
:)




_______________________________________________
Ietf mailing list
Ietf(_at_)ietf(_dot_)org
https://www.ietf.org/mailman/listinfo/ietf