Your question
I have a couple of questions regarding message verification and rejection and their defaults. I’ve checked the docs but I am left with a few questions.
-
I received a piece of spam email purporting to be from my own address; the to and the from are the same. Since I have DMARC policy set to reject on my domain, shouldn’t Stalwart have terminated this message in the MTA DATA phase when the policy was verified? The header does confirm the policy was recognized as reject and both SPF and DKIM failed.
-
If I wanted to enforce a rejection based on DKIM validation, e.g. reject any message that does not have a valid DKIM header, regardless of the DMARC policy (or lack thereof) would I change the MTA → Sender Authentication from ‘relaxed’ to ‘strict’, or do I require a sieve script?
-
To flat out reject all email from a domain, is that what Spam Filter → Lists → Blocked Domains is for, and do wildcards or regex work here, or only exact matches?
-
When the spam classifier hits the required default of 100 ham and spam, what begins to change?
-
What do you need to alter in order to have high scoring messages rejected instead of landing in Junk, or is that tied to the minimum samples in question 4?
Thanks, and keep up the great work.
I understand that topics in this category are triaged by a bot first but a human reply will follow up. If I’d prefer a human-only reply, I’ll add the no-ai tag to my topic.
on