明明記錄有收到信,連到SERVER上看信,確沒這封信,真的是很怪,不知道那出問題。
Nov 1 18:14:01 mail postfix/cleanup[16788]: A05E27A0139: hold: header Received: from bsjamesnb (223-142-72-143.dynamic.hinet.net [223.142.72.143])??by (Postfix) with ESMTP id A05E27A0139??for <roger.lin@>; Thu, 1 Nov 2012 18: from 223-142-72-143.dynamic.hinet.net[223.142.72.143]; from=<james.yan@> to=<roger.lin@> proto=ESMTP helo=<bsjamesnb>
Nov 1 18:14:07 mail MailScanner[14462]: Requeue: A05E27A0139.A6774 to E00EC7A013B
Nov 1 18:14:07 mail postfix/qmgr[9832]: E00EC7A013B: from=<james.yan@>, size=81180, nrcpt=2 (queue active)
Nov 1 18:14:11 mail postfix/local[19803]: E00EC7A013B: to=<roger.lin@>, relay=local, delay=12, delays=8.2/0.01/0/4.2, dsn=2.0.0, status=sent (delivered to command: /usr/bin/procmail -a "$EXTENSION" DEFAULT=/var/spool/maildir/$USER/ MAILDIR=/var/spool/maildir/$USER/)
Nov 1 18:14:11 mail postfix/qmgr[9832]: E00EC7A013B: removed
有被 procmail 處理,看看是不是 procmail 的規則把信給砍了。
像我就擺了一大堆廣告信規則在 /etc/procmailrc 裡,雖然有些漏網之魚會被 postfix 放行寄進來,不過到了 procmail 還是會被砍掉。
唉呀~~ 一聽到大大的解說,就知道答案八九不離十阿,明天去公司看一下user手邊這信是不真的符合我設定的規則,廣告信真的是太惹人厭了!謝謝大大^^
今天測試了一下,一樣是用3G網卡寄同樣的信,都收的到,且主旨並沒有我阻擋的內容,好奇怪.......
如果你方便把規則貼上來,可以幫你看看是否寫錯。
上次有位邦友也在 procmail 上設了 RegExp 規則,不過寫錯一個字,進來的信就全部符合,全部刪了 ...
VERBOSE=off
LOGFILE=/var/log/procmail.log
:0fw
| /usr/bin/spamc
##FB Virus=====================
:0b
* ^Subject:.*Your friend wants to share photos and updates with you*
/dev/null
:0b
* ^Subject:.*Your friend added a new photo with you to the album*
/dev/null
##=============================
:0b
* ^Subject:.*Unsuccessful fax transmission*
/dev/null
:0b
* ^Subject:.*Hotel Reservation*
/dev/null
:0b
* ^Subject:.*Reservation Confirmation*
/dev/null
:0b
* ^X-Spam-Level:.*\*\*\*\*\*\*\*\*\*\*\*
/dev/null
#/var/spool/mail/del-mail
:0b
* ^Subject:.*DHL International*
/dev/null
:0b
* ^Subject:.*FedEx Shipment Notification*
/dev/null
:0b
* ^Subject:.*trk-id*
/dev/null
:0b
* ^Subject:.*Your UPS Invoice is Ready*
/dev/null
:0b
* ^Subject:.*DHL International Delivery Failure Alert*
/dev/null
:0b
* ^Subject:.*DHL Express Delivery Failure Alert*
/dev/null
:0b
* ^Subject:.*DHL Express Notification*
/dev/null
:0b
* ^Subject:.*UPS Delivery Notification*
/dev/null
:0b
* ^Subject:.*DHL Parcel Tracking Notification*
/dev/null
:0b
* ^Subject:.*DHL Tracking Notification*
/dev/null
:0b
* ^Subject:.*DHL Delivery Notification*
/dev/null
:0b
* ^Subject:.*USPS Failed Delivery Notification*
/dev/null
:0b
* ^Subject:.*DHL Express*
/dev/null
:0b
* ^Subject:.*Phishing incident report*
/dev/null
:0b
* ^Subject:.*bdc-vm : Power*
/dev/null
#vi /usr/loca/etc/procmailrc
###########################################################################
###Procmail 寄進來的郵件依下列規則逐一過濾,未符合底下規則的信件都放行 ###
###Subjcet 主旨 ###
###Content-Type: ###
###########################################################################
############ KLEZ.G Virus ############
:0b
* ^Subject:.*(Let's be friends)
/dev/null
:0b
* ^Subject:.*A funny game
/dev/null
:0b
* ^Subject:.*Hello\,.*\,how are you.*
/dev/null
:0 B
* ^Content-Type:.*audio/x-wav.*
* ^.*name=.*\.(scr|SCR)
/dev/null
:0 B
* ^Content-Type:.*audio/x-midi.*
* ^.*name=.*\.(scr|SCR)
/dev/null
:0 B
* ^Content-Type:.*application/octet-stream.*
* ^.*name=.*\.(scr|SCR)
/dev/null
:0 Bb
* ^This game is my first work.*
* ^You\'re the first player.*
* I.*you would .* it.*
/dev/null
:0 Bb
* .*This is a.*patch.*
* ^I .* you would.*it.*
/dev/null
:0 Bb
* .*iframe src=3Dcid.*height=3D0 width=3D0.*
/dev/null
:0 B
* ^Content-Type:.*multipart/mixed.*
* name="ANTI_CIH.EXE"
/dev/null
:0b
* ^Subject:.*W32.Klez.*removal tools.*
/dev/null
############## Nimda Virus ###############
:0 Bh
* ^Content-Type:.*audio/x-wav.*
* name="readme.exe"
/dev/null
:0 Bh
* ^Content-Type:.*audio/x-wav.*
* name="sample.exe"
/dev/null
:0 B
* ^Content-Type:.*multipart/mixed.*
* name="readme.exe"
/dev/null
:0 B
* ^Content-Type:.*multipart/mixed.*
* name="sample.exe"
/dev/null
:0 B
* ^Content-Type:.*application.*
* name="readme.exe"
/dev/null
:0 B
* ^Content-Type:.*application.*
* name="sample.exe"
/dev/null
############# SirCam Virus ############
:0 Bh
* I send you this file in order to have your advice
/dev/null
############# PE.BRID.A ############
:0 H
* ^X-Mailer: EBT Reporter.*$
/dev/null
:0 B
* ^.*[Nn][Aa][Mm][Ee]=README\.EXE.*$
/dev/null