current random information

  • smtp handler is postfix
  • email authentication includes milters for spf, dkim, dmarc, postsrsd
  • content filtering includes spamassassin, clamav
  • mailing lists handled by mailman 2 and public-inbox

configuration hotspots

  • mailman2 per-list mboxes: /var/lib/mailman/archives/private/FOO.mbox/FOO.mbox

brief recipes

  • designate spam email that leaked into mailing lists:
    # cd /var/lib/mailman/archives/private/LIST.mbox
    # mutt -f LIST.mbox
    (select message, then:) "| sa-learn --spam"
    (to check:) "| spamassassin -dtD 2>&1 | less"
  • nuke mailman archive spam - blunt
    # cd /var/lib/mailman/archives/private/LIST/PERIOD
    # chmod 640 FILE.html  # not 000, leads to /var/log/mailman/error

  • To remove an inbox.sourceware.org message from the html,nntp,imap archives as inbox admin do:
    $ curl https://inbox.sourceware.org/..../raw | public-inbox-learn spam
    

pre-2019 historical information

Random information about sourceware's email setup

  • smtp handler is in /service/qpsmtpd
  • low-level spam handling is spamassassin
  • most mail infrastructure is qmail
  • mailing lists are handled by ezmlm-idx
  • higher-level mailing list handling is accomplished by home-grown /sourceware/infra/mlcheckd

Common Tasks

  • Confirm a user was added to list YYY within lists-XXX mailing lists?
    ezmlm-list /var/qmail/lists-XXX/YYY | grep 'USER'
  • sitewide blacklist ezmlm-list /qmail/lists/global/deny
  • sitewide whitelist ezmlm-list /qmail/lists/global/allow

useful tools

  • /home/cgf/bin/qpdump --search='email address regex'
    Dumps information (including spamassassin logs when possible) about any incoming smtp traffice associated with the email address
  • /home/cgf/bin/satest rule < email
    Shows which patterns matched rule in supplied email
  • /home/cgf/bin/mldump mldump /var/log/qmail/send/*
    Dumps qmail send logs in a more human readable format.
  • spamc -R -u GLOBAL -U /var/run/spamd < mail
    Check mail against running spamd, output scores.
  • Really whitelist an email address:
    mysql A -u -p root
    mysql> update awl set count= 1000000, totscore= -1E7 where email = 'email@address';
  • Procedure after updating /etc/mail/spamassassin/local.cf:
    spamassassin --lint && service spamassassin restart