Wizcrafts Computer Services
SPECIALIZING INComputer, Website
and Email Security Solutions.
Spam, Scam & Exploit Blocking
Email Security and Spam Blocking using MailWasher Pro
Wizcrafts' MailWasher Pro Custom Anti-Spam Blacklist
With many reports showing that spam email now accounts for between 80% and 90% of all of the email received, globally, and because of the security and malware threats contained in many of those unwanted messages, a lot of people who use a stand-alone POP3 email "client" (e.g.: Microsoft Outlook, Outlook Express, Windows Live Mail, Thunderbird, Eudora, The Bat, etc) are turning to desktop anti-spam solutions - like MailWasher Pro - to screen and filter out time-wasting spam and socially engineered infected attachments before they are downloaded to their email client.
The MailWasher Pro E-mail Senders Blacklist
Another very useful feature of MailWasher Pro is the senders BlackList, which is based on the "From" address. By adding repeat spammers to the BlackList you can have any messages from them automatically deleted, before any custom spam filters are processed. A few years ago I used to blacklist most spam senders, because the spammers used domains under their control. All of that has changed since late 2006, when various Botnets began sending spam, as ordered by the Botmasters. The computers in the Botnets are personal Windows PC's of residential, business and Internet Cafe customers. The sender's email addresses are now 100% forged or fictitious accounts. While there may be the occasional duplication of a forged address, it is rare. If one was to add every one of the spam senders to the BlackList, MailWasher would crumble trying to process this data.
Since the MailWasher BlackList is processed before the custom spam filters, it makes sense to keep it as small as possible, while optimizing it's usefulness. You can do this by only adding wildcard entries or entire unwanted domains to the BlackList. The BlackList used in MailWasher Pro allows you to specify a limited number of wildcard descriptors, comprised of the following:
- ? means any one unspecified character
- * means zero or more unspecified characters
- + means one or more unspecified characters
You can combine those limited wildcard modifiers in a creative fashion to match and block a large assortment of forged sender addresses. For example, a spam run in early 2008 was using underscores or hyphens at the beginning of the forged sender account, like this example: _fdjghf@udhf.com, or like this one: -gjdf@kjfd.com. Other forged senders match a specific repetitive pattern, where the first 2 or 3 letters and the final ones before the @ sign are always the same, with the domain name on both sides of the @ sign. Examples of those are: LINexampleMET@example.de and DWexampleM@example.com. The following "wildcard" BlackList rules will block all of these forged senders.
If you are going to use wildcard BlackList rules, be sure you have gone over your list of approved senders and added them to your WhilteList. False Positives could possibly occur from those fairly broad wildcard expression matches. I have a spam filter rule that does a better job of matching the actual use of the domain name on both sides of @, than these two BlackList rules. That rule is in the three filters.txt lists, that can be loaded into the iframe below and is named "XdomainY@domain."
Blacklist last updated on Wednesday, 02-May-2012 09:18:06 MDT
- _+@+.+
- -+@+.+
- lin+met@+.de (Unbelievably, this almost 1 year old forged sender prefix is still being used)
- dw+m@+.+
- +@bestdebtrepair.net
- +@freenet.de
- noreply@newsletter.+ (Canadian Pharmacy scams)
- +@usa.com (Fake USA Government scam emails)
- *@emaillove.net (Russian dating scam website and email provider)
- kef+diz@+
- tequil*a+@+.com
- +@yahoo.com.hk (Used by Nigerian 419 scammers)
- harryb@aol.com (Nigerian 419 scammer)
- info@law.com (Nigerian 419 scammer)
- The following filters are very effective right now! (added in 2010)
- +@*hinet.net
- +@+.br
- +@+.cn
- +@+.de
- +@+.es
- +@+.gr
- +@+.hk
- +@+.in
- +@+.jp
- +@+.kr
- +@+.ru
- +@+.tw
- +@+.ua
- +@+.vn
- martynov@+
- +@mail.com
- +@+.net.co
- info@atm.com
- +@*ukrtel.net
- +@chinamobile.com
- +@webmail.register.com
- noreply@singlesnet.com
- noreply@message.myspace.com
- networks@facebook.com
- notification@facebookmail.com
- med?@googlemail.com
- notification*@googlemail.com
- +@adamjeeinsurance.com
- Job@DunHill.com
- *@loan.co.uk
- *@contact.co.uk
- beststore@yahoo.com
- *discount*@yahoo.com
- *love@yahoo.com
- lovepil*@yahoo.com
- medical*@yahoo.com
- nice@yahoo.com
- nissoe@yahoo.com
- pharm+@yahoo.com
- watches+@yahoo.com
- delivers@amazon.com
- oem?software*@+
- softwareoem*@+
- +@+.roma6ka.com
- +@rediffmail.com
- dr.max+@+
- drmax+@+
- goodstuff@+
- nope@+
- n?pes@+
- +@breathemail.net
- *viagr+@+
- customers*@eftps.gov (EFTPS Phishing Scam)
- penis+@+
- +enlarger*@yahoo.com
- enlargepen+@+
- ci?lis+@+
- ci?liz+@+
- wathes+@yahoo.com
- *easy-e-card*@+
- +@izonyou.com
- *e-card-delivery@+
- +@hotmail.co.za
- goodstufmop*@yahoo.com
- oodstufmop*@yahoo.com
- levitra+@+
- viagra+@+
- +@yahoo.co.uk
- +@yahoo.it
- +@vip.163.com
- +@hotels.octopustravel.com
- +@afterwork.com
- +@163.com
- +@mindspring.com (Careful!)
- +@otcpundit.com
- +@best*offers.com
- *@yourfanbox.com
- *@fdic.gov
- +@myautorepair.info
- security@quickbooks.com
- *.sdfdsf@+
- info.center@eftps.gov
- info.manager@+.gov
- @usps.net
- +@*nacha.+
- test.test@aol.com
- +@bbb.org
- +@ymail.com (tentative rule)
- +@potter.m.lawfirm.+
- +@habbo.com
- +@chinesegamer.net
Blacklist last updated on May 2, 2012:
+@chinesegamer.net
| Monitor this page for changes | Please Donate to Wizcrafts | |


