antispam:reputation

Manage spam filter reputation.

warden --task=antispam:reputation --oper=<reputation_add|reputation_del>
Option
Value Description
--oper <string> The operation that you want to perform. Operations: reputation_add, reputation_del
--pattern <string> An email address, domain name, IP address, or HELO name.
--signed_by <string> The DKIM signing domain or the tag 'spf' (no quotes) to use the SPF record. When a message contains both a DKIM signature and an SPF pass, the DKIM signature takes the priority, so the record bound to the 'spf' tag won't be checked. Only email addresses and domains can be bound to DKIM or SPF. Records of IP addresses and HELO names are always without DKIM/SPF.
--operation <blacklist|whitelist> Blacklist or whitelist the pattern. This adds a score of 100 for blacklisting or -100 for whitelisting. When a standalone email address is blacklisted/whitelisted, all records of the email address bound to an IP address, DKIM signature, or SPF pass will be removed from the database, and only the standalone record is kept. It is necessary to understand that blacklisting/whitelisting through reputation is not the same as blacklisting/whitelisting using an Amavis policy. TxRep blacklisting/whitelisting adjusts the reputation of the pattern by a high score. This blacklisted or whitelisted reputation score can wear out over time, as scores of new messages from the sender are added to the total reputation score.

Examples

// blacklist a standalone email address
warden --task=antispam:reputation --oper=reputation_add --pattern=spam@example.com --operation=blacklist

// whitelist an email address bound to its DKIM signing domain
warden --task=antispam:reputation --oper=reputation_add --pattern=user@example.com --signed_by=example.com --operation=whitelist

// blacklist an IP address (records of IP addresses are always without DKIM/SPF)
warden --task=antispam:reputation --oper=reputation_add --pattern=192.0.2.44 --operation=blacklist

// whitelist a HELO name
warden --task=antispam:reputation --oper=reputation_add --pattern=host.example.net --operation=whitelist

// remove the reputation record of an email address bound to its SPF pass
warden --task=antispam:reputation --oper=reputation_del --pattern=user@example.com --signed_by=spf

// blacklist a phishing domain that is masquerading as the payroll system
warden --task=antispam:reputation --oper=reputation_add --pattern=payroll-updates.example.net --operation=blacklist

Related Pages