This page collects the software and resources I use against spam, malware and viruses on my own and on customer mail systems. The whole stack is Open Source.
Filtering stages
Mail passes four stages, in this order:
- postscreen – turns away the most obvious junk before a full SMTP session is granted
- postgrey – greylisting, applied selectively rather than to every sender
- rspamd – scoring as a milter, with Bayes classification and a fuzzy hash storage on a Redis backend
- Dovecot with Sieve – IMAPSieve feeds messages that users move into or out of the junk folder back into the Bayes and fuzzy databases the earlier stages depend on
Software I use against Spam and Malware
- Postfix – mail server, including postscreen
- rspamd – spam filtering, Bayes and fuzzy hashes
- postgrey – greylisting
- Dovecot – IMAP/POP3, Sieve and IMAPSieve
- Redis – backend for Bayes tokens and fuzzy hashes
- rbldnsd – locally mirrored DNS blocklists
SpamAssassin and Amavisd-new served this purpose for many years and have been replaced by rspamd. Postfwd is still installed, but no longer in use – rspamd covers policy decisions by score.
DNS Block Lists I use against Spam
rspamd queries the following zones. The scores add up – no single list is enough to reject a message on its own, and lists that cover whole netblocks or entire ASNs are weighted well below the action threshold.
Against the sending host:
zen.spamhaus.orgdnsbl-1.uceprotect.net– single spam sourcesdnsbl-2.uceprotect.net– whole netblocksdnsbl-3.uceprotect.net– whole ASNsrep.mailspike.netbl.spameatingmonkey.netandbl.ipv6.spameatingmonkey.netbl.blocklist.debip.virusfree.cz
Against the domains and URLs inside a message:
dbl.spamhaus.orgmulti.uribl.commulti.surbl.organdhashbl.surbl.orguribl.spameatingmonkey.netandfresh15.spameatingmonkey.neturibl.rspamd.comandemail.rspamd.comebl.msbl.org
Two whitelists pull in the other direction and lower the score of known-good senders: list.dnswl.org and dwl.dnswl.org.
The high-volume zones – the three UCEPROTECT levels, Spamhaus and a whitelist zone – are answered from local mirrors instead of the public resolvers. That avoids rate limits and any dependency on their availability.
Not in use: the two SenderScore zones are switched off, and ips.backscatterer.org is deliberately left out – it is meant for callout verification, and used as an inbound signal it hits legitimate bounce and autoresponder senders.