Skip to main content

Block incoming emails with malicious links

Comments

12 comments

  • 24x7server
    Hi, Do you have clamav enabled on your server? Have you configured clam to scan the mails? Configure ClamAV Scanner - Documentation - cPanel Documentation
    0
  • RaPha_Real
    yes sir i have clamav enabled on all of my servers.. I set them to scan "Scan Entire Home Directory" " Scan Mail" "Scan Public FTP Space" "Scan Public Web Space" and do even have malware detect. That's why Am a bit worry because it seems this kind of spam can penetrate successfully.
    0
  • cPanelMichael
    Hello, You may want to enable some additional SPAM prevention options, like some of the ones referenced on the following thread: cPanel Spam Filtering The Greylisting feature can make a significant difference: Greylisting - Documentation - cPanel Documentation Thank you.
    0
  • RaPha_Real
    Thank you cPanelMichael! any way Im done cPanel Spam Filtering and Greylisting - Documentation - cPanel Documentation long time ago. Anti-spam DNSBL by BOates Ill try this one. Hope it can help.
    0
  • ruzbehraja
    One of my email user receive an email with malicious links on it. Spamassasin failed to block the email. Is there any way I can block incoming emails with malicious links on it? Need your solutions guys. Thank you.

    Were your SpamAssassin Rules setup properly? Did you check the headers to see what score SpamAssassin gave and why it bypassed filtering it?
    0
  • RaPha_Real
    Were your SpamAssassin Rules setup properly? Did you check the headers to see what score SpamAssassin gave and why it bypassed filtering it?

    Yes sir did set up my spamassassin properly and its CL RBL etch is working. I even have lots of JunkEmail rejected by spamhous & spamcop. When I view its spam score via email delivery it given -4 spam score with 4x deferal before it passes through.
    0
  • RaPha_Real
    Cpanel experts...I still experience this issue...any better suggestion?
    0
  • cPanelMichael
    Hello, Can you provide some more details about the specific type of content that is making it through your existing rules? Thank you.
    0
  • RaPha_Real
    Hello, Can you provide some more details about the specific type of content that is making it through your existing rules? Thank you.

    Most of the spam/phishing email is similar to this one
    Hi ! Kindly please send me the last invoice to proceed in your payment immediately. http://domain.ru/Invoice-Number-4393350/
    https://drive.google.com/file/d/1KQkM0_ApNrMrD2vxm-uZZgTNsaxktOXH/view?usp=drivesdk
    0
  • 24x7server
    Hi, Nothing came along with your last reply. Can you send the spam email headers again?
    0
  • RaPha_Real
    Hi, Nothing came along with your last reply. Can you send the spam email headers again?

    this is the header
    **Important Please Read** From Nicole Barish To user@mydomain.com Date Wed 8:14 pm
    0
  • cPanelMichael
    Hello, You could setup a global filter with a rule that blocks the message if the message body contains a specific term (e.g. "http" or ".co.za"): Also, if it's making it through SpamAssassin, your RBLs, and Greylisting, then you may want to report it as SPAM to one of the RBLs you are using. Thank you.
    0

Please sign in to leave a comment.