Advertisment

Sunday, 30 March 2014

Email Spam Filtering

Email Spam Filtering

By default, Kloxo’s spam filtering capabilities are not configured to reduce spam messages. You will need to make some changes to make it work for you and your clients.

When you configure your first email addresses you will notice that a lot of the email you get will be marked as spam, by spamdyke adding ******SPAM****** to the email subject. By sending all email to your inbox, marked or not, it gives you an opportunity to see which good messages are false positives and how much spam is getting through.

The first step is to redirect email marked as spam to the spam folder. Do that by going to the Kloxo panel, select the Mail Accounts tab, then go to the email account Kloxo panel by clicking on the email account name. Click the Filter Config icon. Change “What To Do With Spam” to spambox, then click update.

Now return to the email account Kloxo panel and click the Spam Training icon. You will see the messages judged as spam listed in that page. If you see any good messages in that list you should click the box next to the message then click the “train as ham” button (spam=bad, ham=good). If you train a message as ham, any future messages from the same sender should not be marked as spam. You will want to monitor the messages marked as spam for a few days to make sure good messages aren’t being tossed.

Hint: If you are logged-in as admin you will also see buttons for Train As System Spam & Ham. If you use those buttons it will whitelist & blacklist messages for the entire system, rather than for individual email accounts.

Another Hint: Login to RoundCube to view good messages that landed in the spam folder. You may need to “subscribe” to the Junk folder in RoundCube settings to view the spam folder.

One More Hint: You will notice a tab in the Spam Training icon called Clear Spam Db. That’s not really a tab, it’s a command that wipes-out all of your spam/ham training entries. If you click on that tab it will delete all training entries for that email account without so much as a confirmation. Don’t click on that tab unless you have a compelling reason to do so.

You can adjust the level of spam filtering by going to the domain’s Kloxo panel and clicking the Spam Status icon. The default is 5. Setting it to a lower number will mark more email as spam, and setting it higher will mark less email as spam. I usually set it higher, to maybe 6 or 7, since I don’t want to miss any messages. We will be blocking most of the spam with DNS blacklists anyway.
DNS blacklists will turn away a lot of spam before it reaches filtering. These are lists of sending servers that have been blacklisted for spamming. Once you subscribe to DNS blacklists, any email received from rogue sending servers will be deleted. Depending on your spam situation, 80% or more of all unsolicited email can be removed by simply subscribing to some major blacklists. To do that, go to the Kloxo admin panel and click the Server Mail Settings icon. Click the Spamdyke tab. In the box at the bottom marked “Space separated DNS RBL servers” enter bl.spamcop.net and zen.spamhaus.org separated by a single space. Click the update button. Those blacklists are free, and are the most well-respected spam authorities.

It’s a good idea to also select Reject Servers Without RDNS Names. There really aren’t any legitimate email servers that don’t have rDNS properly set.
Your spam should be pretty well under control now.

Securing the System

Securing the System

Spend a few days becoming accustomed to your new server, browsing the various features of webmin. But when you are done looking around you should recognize that there are certain security risks in having SSH and webmin running. Therefore, within a few days you should consider locking down the server by restricting access to both.

To disable webmin, go to the System icon at the top of webmin, then click on the “Bootup and Shutdown” icon. Click the webmin service. Next to “Start at boot time?” select the “No” radio button, then click the Save button. Now go back into the webmin service again and click the “Stop Now” button. Webmin should no longer be accessible.

Kloxo recommends changing the SSH communications port from 22 to something else for security (perhaps 522). While I have no objection to doing that, and you might just go ahead and do it to get Kloxo to stop bugging you about it, I suggest that terminal access isn’t necessary most of the time for maintaining a Kloxo hosting server. For that reason I simply disable SSH when I’m not actively using it, and you might consider doing the same. But recognize that disabling SSH is controversial, since you are locked out of the system and have no way to make command line repairs if you lose your Kloxo control panel. Consider the disabling of SSH carefully. As an alternative, you might consider SSH Authorized Key access instead, which can be configured through Kloxo.

Remember! If you change any ports to non-standard ports they will need to be added to the SPF firewall configuration, and APF will need to be restarted to apply changes, as follows.

/usr/local/sbin/apf –r

To disable SSH terminal access, login to Kloxo as administrator. In the security box, click the SSH Config icon. Put a check mark in the box next to “Completely Disable Password Based Access”.

Click the Update button.

Your system is now locked out. You can still administrate Kloxo and you still have basic VPS services access, but otherwise your system is inaccessible.

You should reboot the system from time to time (perhaps every month or so), to make sure that any kernel updates are applied and to flush memory. You can do that from either the VPS control panel or Kloxo administration (look in the Machine box in the admin panel).

Regaining System Access

Regaining System Access

You can regain SSH terminal access by going back to the Kloxo administration page. In the security box, click the SSH Config icon. Remove the check mark from the box next to “Completely Disable Password Based Access”. Click the Update button.

To regain webmin access, open PuTTY and login as root. Issue the following command.

# service webmin start

You can now login to webmin. If you will be doing system maintenance & configuration for a while you should go back into the System icon and into Bootup and Shutdown to set webmin to start on boot. Otherwise you will need to issue the above command with PuTTY each time the system is rebooted.