Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #210681 > unrolled thread

Re: [OT] send all email from certain From: addresses into a spam

Started byGreg Wooledge <wooledg@eeg.ccf.org>
First post2019-07-03 17:40 +0200
Last post2019-07-05 02:40 +0200
Articles 16 — 11 participants

Back to article view | Back to linux.debian.user

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: [OT] send all email from certain From: addresses into a spam Greg Wooledge <wooledg@eeg.ccf.org> - 2019-07-03 17:40 +0200
    Re: [OT] send all email from certain From: addresses into a spam Reco <recoverym4n@enotuniq.net> - 2019-07-03 17:50 +0200
      Re: [OT] send all email from certain From: addresses into a spam Michael Stone <mstone@debian.org> - 2019-07-03 18:00 +0200
        Re: [OT] send all email from certain From: addresses into a spam andreimpopescu@gmail.com - 2019-07-03 18:30 +0200
      Re: [OT] send all email from certain From: addresses into a spam Mark Fletcher <mark27q1@gmail.com> - 2019-07-04 16:30 +0200
        Re: [OT] send all email from certain From: addresses into a spam Reco <recoverym4n@enotuniq.net> - 2019-07-04 17:20 +0200
          Re: [OT] send all email from certain From: addresses into a spam Celejar <celejar@gmail.com> - 2019-07-05 00:40 +0200
            Re: [OT] send all email from certain From: addresses into a spam Reco <recoverym4n@enotuniq.net> - 2019-07-05 08:40 +0200
              Re: [OT] send all email from certain From: addresses into a spam Celejar <celejar@gmail.com> - 2019-07-07 05:10 +0200
                Re: [OT] send all email from certain From: addresses into a spam Reco <recoverym4n@enotuniq.net> - 2019-07-07 08:10 +0200
                  Re: [OT] send all email from certain From: addresses into a spam Celejar <celejar@gmail.com> - 2019-07-08 14:20 +0200
              Re: [OT] send all email from certain From: addresses into a spam rhkramer@gmail.com - 2019-07-07 13:50 +0200
                Re: [OT] send all email from certain From: addresses into a spam <tomas@tuxteam.de> - 2019-07-07 16:40 +0200
                Re: [OT] send all email from certain From: addresses into a spam David Wright <deblis@lionunicorn.co.uk> - 2019-07-07 16:40 +0200
                  Re: [OT] send all email from certain From: addresses into a spam John Hasler <jhasler@newsguy.com> - 2019-07-07 21:00 +0200
    Re: [OT] send all email from certain From: addresses into a spam Joel Roth <joelz@pobox.com> - 2019-07-05 02:40 +0200

#210681 — Re: [OT] send all email from certain From: addresses into a spam

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2019-07-03 17:40 +0200
SubjectRe: [OT] send all email from certain From: addresses into a spam
Message-ID<yfPwu-7sw-9@gated-at.bofh.it>
On Wed, Jul 03, 2019 at 06:30:32PM +0300, Reco wrote:
> I'm merely curious why you have to write a new program for this.
> I mean, there are maildrop and procmail for client-side and sieve for
> the server-side already.

procmail might have worked, but it's more of a pain to learn procmail
than it is to write my own filter.  I also get more flexibility this way.

The write-up of my approach is at
<https://lists.debian.org/debian-user/2017/02/msg00100.html>.

[toc] | [next] | [standalone]


#210684

FromReco <recoverym4n@enotuniq.net>
Date2019-07-03 17:50 +0200
Message-ID<yfPG9-7vP-3@gated-at.bofh.it>
In reply to#210681
	Hi.

On Wed, Jul 03, 2019 at 11:39:22AM -0400, Greg Wooledge wrote:
> On Wed, Jul 03, 2019 at 06:30:32PM +0300, Reco wrote:
> > I'm merely curious why you have to write a new program for this.
> > I mean, there are maildrop and procmail for client-side and sieve for
> > the server-side already.
> 
> procmail might have worked, but it's more of a pain to learn procmail
> than it is to write my own filter.  I also get more flexibility this way.
> 
> The write-up of my approach is at
> <https://lists.debian.org/debian-user/2017/02/msg00100.html>.

Maildrop does exactly this. For instance, 

^From:.*User Name/

Transforms to this snippet of .mailfilter:

if ( /^From:.*User Name/:h )
	to /dev/null

Works with exim, postfix and probably qmail OOB.

Reco

[toc] | [prev] | [next] | [standalone]


#210685

FromMichael Stone <mstone@debian.org>
Date2019-07-03 18:00 +0200
Message-ID<yfPPP-7z5-3@gated-at.bofh.it>
In reply to#210684
On Wed, Jul 03, 2019 at 06:44:42PM +0300, Reco wrote:
>	Hi.
>
>On Wed, Jul 03, 2019 at 11:39:22AM -0400, Greg Wooledge wrote:
>> On Wed, Jul 03, 2019 at 06:30:32PM +0300, Reco wrote:
>> > I'm merely curious why you have to write a new program for this.
>> > I mean, there are maildrop and procmail for client-side and sieve for
>> > the server-side already.
>>
>> procmail might have worked, but it's more of a pain to learn procmail
>> than it is to write my own filter.  I also get more flexibility this way.
>>
>> The write-up of my approach is at
>> <https://lists.debian.org/debian-user/2017/02/msg00100.html>.
>
>Maildrop does exactly this. For instance,
>
>^From:.*User Name/
>
>Transforms to this snippet of .mailfilter:
>
>if ( /^From:.*User Name/:h )
>	to /dev/null
>
>Works with exim, postfix and probably qmail OOB.

maildrop is definitely recommended these days (especially for anyone 
still running procmail). 

[toc] | [prev] | [next] | [standalone]


#210686

Fromandreimpopescu@gmail.com
Date2019-07-03 18:30 +0200
Message-ID<yfQiS-7Y0-5@gated-at.bofh.it>
In reply to#210685

[Multipart message — attachments visible in raw view] — view raw

On Mi, 03 iul 19, 11:53:11, Michael Stone wrote:
> 
> maildrop is definitely recommended these days (especially for anyone still
> running procmail).

imapfilter works fine if you use IMAP and your server has poor or no 
filtering (exposed to users).

Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [next] | [standalone]


#210714

FromMark Fletcher <mark27q1@gmail.com>
Date2019-07-04 16:30 +0200
Message-ID<ygaUh-3v4-1@gated-at.bofh.it>
In reply to#210684
On Wed, Jul 03, 2019 at 06:44:42PM +0300, Reco wrote:
> 	Hi.
> 
> On Wed, Jul 03, 2019 at 11:39:22AM -0400, Greg Wooledge wrote:
> > 
> > procmail might have worked, but it's more of a pain to learn procmail
> > than it is to write my own filter.  I also get more flexibility this way.
> > 
> > The write-up of my approach is at
> > <https://lists.debian.org/debian-user/2017/02/msg00100.html>.
> 
> Maildrop does exactly this. For instance, 
> 
> ^From:.*User Name/
> 
> Transforms to this snippet of .mailfilter:
> 
> if ( /^From:.*User Name/:h )
> 	to /dev/null
> 
> Works with exim, postfix and probably qmail OOB.
> 

Could this also be expanded to delete not only mail from a particular 
user, but also any mail *replying to* that mail as well? In other words, 
get rid of not only the mail that starts a thread, but the entire 
thread?

Or would that be a task better done in mutt?

Mark

[toc] | [prev] | [next] | [standalone]


#210718

FromReco <recoverym4n@enotuniq.net>
Date2019-07-04 17:20 +0200
Message-ID<ygbGF-40e-7@gated-at.bofh.it>
In reply to#210714
	Hi.

On Thu, Jul 04, 2019 at 11:29:20PM +0900, Mark Fletcher wrote:
> On Wed, Jul 03, 2019 at 06:44:42PM +0300, Reco wrote:
> > On Wed, Jul 03, 2019 at 11:39:22AM -0400, Greg Wooledge wrote:
> > > 
> > > procmail might have worked, but it's more of a pain to learn procmail
> > > than it is to write my own filter.  I also get more flexibility this way.
> > > 
> > > The write-up of my approach is at
> > > <https://lists.debian.org/debian-user/2017/02/msg00100.html>.
> > 
> > Maildrop does exactly this. For instance, 
> > 
> > ^From:.*User Name/
> > 
> > Transforms to this snippet of .mailfilter:
> > 
> > if ( /^From:.*User Name/:h )
> > 	to /dev/null
> > 
> > Works with exim, postfix and probably qmail OOB.
> > 
> 
> Could this also be expanded to delete not only mail from a particular 
> user, but also any mail *replying to* that mail as well? In other words, 
> get rid of not only the mail that starts a thread, but the entire 
> thread?

I don't see a universal way of doing this, but I'd try a match against a
References header.
For instance, your e-mail has this References header:

References: <E1hihDN-00068j-56@enotuniq.net>
        <20190703153922.GZ2450@eeg.ccf.org>
        <E1hihR4-0006A9-VE@enotuniq.net>

So, assuming that you wish to block threads that are started by me,
participated by me, etc, you'll need (:h should correctly process a
multiline header):

if ( /^From:.*recoverym4n@enotuniq.net/:h )
	to /dev/null
if ( /^References:.*enotuniq.net/:h )
	to /dev/null

But that assumes that everybody in the thread are using a sane e-mail
client. And relies on Message-ID that can include literally anything
(but it does include a domain most of the time).


> Or would that be a task better done in mutt?

That's an option too. The obvious disadvantage is that you see e-mails
and (sub)threads that you want to delete.

Reco

[toc] | [prev] | [next] | [standalone]


#210737

FromCelejar <celejar@gmail.com>
Date2019-07-05 00:40 +0200
Message-ID<ygiyt-80n-7@gated-at.bofh.it>
In reply to#210718
On Thu, 4 Jul 2019 18:17:36 +0300
Reco <recoverym4n@enotuniq.net> wrote:

...

> For instance, your e-mail has this References header:
> 
> References: <E1hihDN-00068j-56@enotuniq.net>
>         <20190703153922.GZ2450@eeg.ccf.org>
>         <E1hihR4-0006A9-VE@enotuniq.net>
> 
> So, assuming that you wish to block threads that are started by me,
> participated by me, etc, you'll need (:h should correctly process a
> multiline header):
> 
> if ( /^From:.*recoverym4n@enotuniq.net/:h )
> 	to /dev/null
> if ( /^References:.*enotuniq.net/:h )
> 	to /dev/null
> 
> But that assumes that everybody in the thread are using a sane e-mail
> client. And relies on Message-ID that can include literally anything
> (but it does include a domain most of the time).

Wait, but wouldn't that block any threads referring to any mail sent
from any address at the specified domain? This might work fine for a
small domain, but it's going to be bad for mail coming from Gmail
accounts ...

Celejar

[toc] | [prev] | [next] | [standalone]


#210744

FromReco <recoverym4n@enotuniq.net>
Date2019-07-05 08:40 +0200
Message-ID<ygq2Z-5bd-1@gated-at.bofh.it>
In reply to#210737
	Hi.

On Thu, Jul 04, 2019 at 06:30:12PM -0400, Celejar wrote:
> On Thu, 4 Jul 2019 18:17:36 +0300
> Reco <recoverym4n@enotuniq.net> wrote:
> 
> ...
> 
> > For instance, your e-mail has this References header:
> > 
> > References: <E1hihDN-00068j-56@enotuniq.net>
> >         <20190703153922.GZ2450@eeg.ccf.org>
> >         <E1hihR4-0006A9-VE@enotuniq.net>
> > 
> > So, assuming that you wish to block threads that are started by me,
> > participated by me, etc, you'll need (:h should correctly process a
> > multiline header):
> > 
> > if ( /^From:.*recoverym4n@enotuniq.net/:h )
> > 	to /dev/null
> > if ( /^References:.*enotuniq.net/:h )
> > 	to /dev/null
> > 
> > But that assumes that everybody in the thread are using a sane e-mail
> > client. And relies on Message-ID that can include literally anything
> > (but it does include a domain most of the time).
> 
> Wait, but wouldn't that block any threads referring to any mail sent
> from any address at the specified domain? This might work fine for a
> small domain, but it's going to be bad for mail coming from Gmail
> accounts ...

That's another disadvantage, I agree. But it's a feature at the same
time. For instance, outlook.com sents nothing but spam to this maillist,
so any e-mails from that domain can be safely 'blocked' this way.

Reco

[toc] | [prev] | [next] | [standalone]


#210874

FromCelejar <celejar@gmail.com>
Date2019-07-07 05:10 +0200
Message-ID<yh5IS-4DB-3@gated-at.bofh.it>
In reply to#210744
On Fri, 5 Jul 2019 09:35:46 +0300
Reco <recoverym4n@enotuniq.net> wrote:

...

> time. For instance, outlook.com sents nothing but spam to this maillist,
> so any e-mails from that domain can be safely 'blocked' this way.

Perhaps almost entirely spam, but not quite 'nothing but spam':

https://lists.debian.org/debian-user/2018/03/msg00901.html
https://lists.debian.org/debian-user/2018/12/msg00732.html

Celejar

[toc] | [prev] | [next] | [standalone]


#210880

FromReco <recoverym4n@enotuniq.net>
Date2019-07-07 08:10 +0200
Message-ID<yh8x3-6lk-3@gated-at.bofh.it>
In reply to#210874
	Hi.

On Sat, Jul 06, 2019 at 11:09:36PM -0400, Celejar wrote:
> On Fri, 5 Jul 2019 09:35:46 +0300
> Reco <recoverym4n@enotuniq.net> wrote:
> 
> ...
> 
> > time. For instance, outlook.com sents nothing but spam to this maillist,
> > so any e-mails from that domain can be safely 'blocked' this way.
> 
> Perhaps almost entirely spam, but not quite 'nothing but spam':
> 
> https://lists.debian.org/debian-user/2018/03/msg00901.html
> https://lists.debian.org/debian-user/2018/12/msg00732.html

A whopping two non-spam e-mails in a year? That's called negligible in
my book.

Reco

[toc] | [prev] | [next] | [standalone]


#210990

FromCelejar <celejar@gmail.com>
Date2019-07-08 14:20 +0200
Message-ID<yhAMG-6vT-7@gated-at.bofh.it>
In reply to#210880
On Sun, 7 Jul 2019 09:00:05 +0300
Reco <recoverym4n@enotuniq.net> wrote:

> 	Hi.
> 
> On Sat, Jul 06, 2019 at 11:09:36PM -0400, Celejar wrote:
> > On Fri, 5 Jul 2019 09:35:46 +0300
> > Reco <recoverym4n@enotuniq.net> wrote:
> > 
> > ...
> > 
> > > time. For instance, outlook.com sents nothing but spam to this maillist,
> > > so any e-mails from that domain can be safely 'blocked' this way.
> > 
> > Perhaps almost entirely spam, but not quite 'nothing but spam':
> > 
> > https://lists.debian.org/debian-user/2018/03/msg00901.html
> > https://lists.debian.org/debian-user/2018/12/msg00732.html
> 
> A whopping two non-spam e-mails in a year? That's called negligible in
> my book.

Fair enough. Everyone has his own tolerance for false positives.

Celejar

[toc] | [prev] | [next] | [standalone]


#210903

Fromrhkramer@gmail.com
Date2019-07-07 13:50 +0200
Message-ID<yhdQ5-TR-11@gated-at.bofh.it>
In reply to#210744
On Friday, July 05, 2019 02:35:46 AM Reco wrote:
> > > So, assuming that you wish to block threads that are started by me,
> > > participated by me, etc, you'll need (:h should correctly process a
> > > multiline header):
> > > 
> > > if ( /^From:.*recoverym4n@enotuniq.net/:h )
> > > 
> > > 	to /dev/null
> > > 
> > > if ( /^References:.*enotuniq.net/:h )
> > > 
> > > 	to /dev/null
> > > 
> > > But that assumes that everybody in the thread are using a sane e-mail
> > > client. And relies on Message-ID that can include literally anything
> > > (but it does include a domain most of the time).
> > 
> > Wait, but wouldn't that block any threads referring to any mail sent
> > from any address at the specified domain? This might work fine for a
> > small domain, but it's going to be bad for mail coming from Gmail
> > accounts ...

I haven't been following this thread carefully, nor do I understand the syntax 
used above, but couldn't the * be replaced with a specific name to limit which 
emails get sent to /dev/null?
 
> That's another disadvantage, I agree. But it's a feature at the same
> time. For instance, outlook.com sents nothing but spam to this maillist,
> so any e-mails from that domain can be safely 'blocked' this way.

[toc] | [prev] | [next] | [standalone]


#210925

From<tomas@tuxteam.de>
Date2019-07-07 16:40 +0200
Message-ID<yhguB-2wY-1@gated-at.bofh.it>
In reply to#210903

[Multipart message — attachments visible in raw view] — view raw

On Sun, Jul 07, 2019 at 07:47:58AM -0400, rhkramer@gmail.com wrote:
> On Friday, July 05, 2019 02:35:46 AM Reco wrote:

[...]

> > > > if ( /^From:.*recoverym4n@enotuniq.net/:h )
> > > > 
> > > > 	to /dev/null
> > > > 
> > > > if ( /^References:.*enotuniq.net/:h )
> > > > 
> > > > 	to /dev/null

[...]

> I haven't been following this thread carefully, nor do I understand the syntax 
> used above, but couldn't the * be replaced with a specific name to limit which 
> emails get sent to /dev/null?

Nor have I, but those look suspiciously like regular expressions. In that case
you want to substitute the ".*" (with the dot). Also you might want to take
into acount that there may be some whitespace after the header label. Thus
perhaps

  /^References:\s+foo@enotunia.net/

assuming Perl flavour regexps (as I said, I followed things only cursorily).

Cheers
-- t

[toc] | [prev] | [next] | [standalone]


#210926

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2019-07-07 16:40 +0200
Message-ID<yhguC-2wY-13@gated-at.bofh.it>
In reply to#210903
On Sun 07 Jul 2019 at 07:47:58 (-0400), rhkramer@gmail.com wrote:
> On Friday, July 05, 2019 02:35:46 AM Reco wrote:
> > > > So, assuming that you wish to block threads that are started by me,
> > > > participated by me, etc, you'll need (:h should correctly process a
> > > > multiline header):
> > > > 
> > > > if ( /^From:.*recoverym4n@enotuniq.net/:h )
> > > > 
> > > > 	to /dev/null
> > > > 
> > > > if ( /^References:.*enotuniq.net/:h )
> > > > 
> > > > 	to /dev/null
> > > > 
> > > > But that assumes that everybody in the thread are using a sane e-mail
> > > > client. And relies on Message-ID that can include literally anything
> > > > (but it does include a domain most of the time).
> > > 
> > > Wait, but wouldn't that block any threads referring to any mail sent
> > > from any address at the specified domain? This might work fine for a
> > > small domain, but it's going to be bad for mail coming from Gmail
> > > accounts ...
> 
> I haven't been following this thread carefully, nor do I understand the syntax 
> used above, but couldn't the * be replaced with a specific name to limit which 
> emails get sent to /dev/null?

The method is very hit-or-miss. Firstly, it assumes that clients are
maintaining a References field, but some only use In-Reply-To.
Secondly, any domain in the References might look unique (like mine)
but might not be. (Anyone could use wren.corp, and I could change mine
from day to day if I like.) Thirdly, the local part (before the @)
might contain a static name (like yours does), but might not.

For an rough indication, try running
$ grep '@gmail.com>' /tmp/deblis | cut -d '<' -f 2 | sort -u | less
on an email mbox if you have one stored locally. (Your own outbox
could suffice.) You'll see the local part sometimes contains
specific information, but many use unique, random strings like
 999cd080-9e74-c40d-0650-f4277d56358c@gmail.com.

> > That's another disadvantage, I agree. But it's a feature at the same
> > time. For instance, outlook.com sents nothing but spam to this maillist,
> > so any e-mails from that domain can be safely 'blocked' this way.

If you're going to try this, I'd send the emails to a "spam" mbox
rather than /dev/null as you can't recover from the latter when you
find that your rule is too draconian. For example, much of my private
correspondence originates from or passes through outlook.com.
Trashing them all could be a costly mistake.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#210948

FromJohn Hasler <jhasler@newsguy.com>
Date2019-07-07 21:00 +0200
Message-ID<yhkye-4SH-7@gated-at.bofh.it>
In reply to#210926
I use Mailagent.  It can sort on anything in the headers using lex-like
rules.  You can add rules using Perl regular expressions. 
-- 
John Hasler 
jhasler@newsguy.com
Elmwood, WI USA

[toc] | [prev] | [next] | [standalone]


#210739

FromJoel Roth <joelz@pobox.com>
Date2019-07-05 02:40 +0200
Message-ID<ygkqB-F0-1@gated-at.bofh.it>
In reply to#210681
On Wed, Jul 03, 2019, Greg Wooledge wrote:
> On Wed, Jul 03, 2019 at 06:30:32PM +0300, Reco wrote:
> > I'm merely curious why you have to write a new program for this.
> > I mean, there are maildrop and procmail for client-side and sieve for
> > the server-side already.
> 
> procmail might have worked, but it's more of a pain to learn procmail
> than it is to write my own filter.  I also get more flexibility this way.
> 
> The write-up of my approach is at
> <https://lists.debian.org/debian-user/2017/02/msg00100.html>.

Cool.

For those who are friendly with perl, Email::Filter or
Email::Filter::Rules provides a less cryptic alternative to
procmail. I use Email::Filter with Net::IMAP::Client so that
I run one filter process per mail check, rather than one
process per mail when triggering the filter from a .forward
file.

-- 

Joel Roth

"Welcome to the World Heat Bank, where we store your waste
energy and return it with interest"

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web