DNS Blacklist Analysis

I would like to be able to analyze the amount of spam blocked vs mail delivered but see no way to the information without being on Administrator just before we restart (weekly) the server.Any ideas?

Subject: DNS Blacklist Analysis

See my post here:

http://www-10.lotus.com/ldd/nd6forum.nsf/55c38d716d632d9b8525689b005ba1c0/33097f4fd67dcb6385256d480033b8f3?OpenDocument

Subject: RE: DNS Blacklist Analysis

Thanks. Am checking out your Blog as time permits. I’m seeing the first two events but not the last one “SMTP Server: %s disconnected”. Not seeing anything similar in Log.nsf. Am on 6.0.2CF1. Would that matter?

Subject: RE: DNS Blacklist Analysis

You may need to increase the logging level.

Try LOG_MAILROUTING=40 in Notes.ini

Subject: RE: DNS Blacklist Analysis

I already had that.As I was getting this message: “09/28/2003 02:20:22 AM Router: notes.ini setting for Log_Mailrouting being used (note - this option may now be configured in a Server Configuration document)” I commented out that line in favor of config document specifying logging level = verbose.

Same thing. No SMTP disconnect message. It would be in Misc events wouldn’t it?

Subject: RE: DNS Blacklist Analysis

Try Mail Routing Events…

Subject: DNS Blacklist - no SMTP disconnect

I have read where DoS attacks will sometimes use multiple SMTP connects with malformed message header that never disconnects. Once you’ve got 30 to 100 of these waiting for timeout you’re hooped.

All of this refers to PostFix and other Linux/Unix servers, but I wonder if Domino is not exploitable to something similar.

I have recently (twice in past 3 weeks) had my server hang during evening hours. In morning I go to console, hit and all activity in past 12 hours scrolls by. Server is running fine. Of course I restart as soon as I’ve captured some logs, but . . .

http://lists.netsys.com/pipermail/full-disclosure/2003-August/007543.html

Anybody know whether this is an issue to watch for. We’re running Domino 6.01.

Subject: RE: DNS Blacklist - no SMTP disconnect

That’s nothing to do with sessions not disconnecting. You need to disable quickedit mode in the server console window.

HTH

Subject: DNS Blacklist Analysis

The easiest thing to do would be to schedule a program document to show stats and then go back to the log file to review them.

– Charles

Subject: RE: DNS Blacklist Analysis

Thanks. I’ve been working on this and don’t seem to hit upon the right set of parameters.Can you shed some light on what program would run it and what command line entry.

The other response was right on in that I can see chart exactly who was blacklisted. I like your idea of having the summary info too.

Subject: DNS Blacklist Analysis

You can downlaod a trial copy of MailFrontier’s Anti-Spam gateway and they have a pretty good reporting module.

www.mailfrontier.com

It can either block spam or just report on it for you.