# ====================================================================== # MASTER SPAMASSASSIN CONFIGURATION - VOXOS | MWD ENTERPRISE SHIELD # Version 5.1: ULTIMATE HARDENING (Logistics, NaTIS, cPanel, & Trust-Tax) # ====================================================================== # === 1. SYSTEM SCAN LIMIT === # Increased to 5MB to prevent bypass by large attachments max_full_scan_size 5000 # === 2. GENERAL SCORING SETTINGS === required_score 4.0 rewrite_header Subject *****SPAM***** _SCORE_/_REQD_ report_safe 0 # === 3. NEUTRALIZE SPAMMER "ARMOR" === # We neutralize the "Trust Bonus" (-60) in Section 6 using a Tax. score SPF_PASS 0 score DKIM_PASS 0 score RDNS_DYNAMIC 0.8 score RDNS_NONE 1.8 # === 4. INTERNAL BRAND & ADMIN PROTECTION (MWD / VOXOS / CPANEL) === header __LOCAL_FROM_BRAND From =~ /\b(MagicWebDesigns|Voxos|cPanel|Webhost|System Admin|Microsoft|Office 365|Outlook)\b/i header __LOCAL_FROM_INTERNAL From =~ /@(voxos\.co\.za|magicwebdesigns\.co\.za|officesolution\.co\.za|kwikwap\.co\.za|microsoft\.com)\b/i meta LOCAL_BRAND_SPOOF (__LOCAL_FROM_BRAND && !__LOCAL_FROM_INTERNAL) describe LOCAL_BRAND_SPOOF Uses company/admin name but sent from external domain score LOCAL_BRAND_SPOOF 4.5 header LOCAL_ADMIN_LURE Subject =~ /\b(Alarm System|Threshold|Storage Full|Suspended|Security Alert|Mailbox Quota|Exceeded|Action Required|Password Expiring)\b/i describe LOCAL_ADMIN_LURE System admin/cPanel/Microsoft impersonation alert score LOCAL_ADMIN_LURE 3.5 # === 5. SA LOGISTICS & UTILITY SHIELD (RAM, CourierIT, Buffalo, PayCity, NaTIS, SABC) === # Names and Base64 signatures for common SA Brands header __LOG_NAME_PLAIN From =~ /\b(CourierIT|RAM Hand-to-Hand|RAM Couriers|Buffalo International|Buffalo Logistics|The Courier Guy|DHL|Aramex|PayCity|NaTIS|SABC|TV Licen|FNB|Standard Bank|Absa)\b/i header __LOG_NAME_B64 From =~ /(Q291cmllcklU|UkFNIEhhbmQtdG8tSGFuZA|QnVmZmFsbw|UGF5Q2l0eQ|U0FCQw)/i meta __LOGISTICS_NAME (__LOG_NAME_PLAIN || __LOG_NAME_B64) # Legitimate domains for these brands header __LOGISTICS_DOM From =~ /@(ram\.co\.za|courierit\.co\.za|buffaloex\.com|thecourierguy\.co\.za|paycity\.co\.za|natis\.gov\.za|sabc\.co\.za|fnb\.co\.za|standardbank\.co\.za|absa\.co\.za|dhl\.com|aramex\.com)\b/i meta LOCAL_COURIER_SPOOF (__LOGISTICS_NAME && !__LOGISTICS_DOM) describe LOCAL_COURIER_SPOOF SA Brand used with unauthorized domain score LOCAL_COURIER_SPOOF 4.5 # High-pressure subject lures header LOCAL_DELIVERY_LURE Subject =~ /\b(at your door|driver was|package ready|parcel status|delivery update|parcel is waiting|confirm now|tried to deliver|Buffalo package|Shipment Update|Enforcement Order|Services Blocked|Traffic Fine|License Renewal|Final Demand|TV Licence|Beneficiary Added|POP_|Proof of Payment)\b/i describe LOCAL_DELIVERY_LURE High-pressure brand lure (Phishing) score LOCAL_DELIVERY_LURE 3.5 # === 6. THE NEUTRALIZER (TAXING THE -60 POINT SERVER TRUST BONUS) === # This rule kills "High Trust" spam. If it's a Spoof + a Lure, we add 65 points # to override the server's SPF/DKIM trust bonuses. header LOCAL_HIGH_PRIO X-Priority =~ /^[12]/ meta LOCAL_TRUST_NEUTRALIZER ( (LOCAL_BRAND_SPOOF || LOCAL_COURIER_SPOOF) && (LOCAL_ADMIN_LURE || LOCAL_DELIVERY_LURE || LOCAL_HIGH_PRIO) ) describe LOCAL_TRUST_NEUTRALIZER Neutralizing SPF/DKIM trust bonus for impersonation scams score LOCAL_TRUST_NEUTRALIZER 65.0 # === 7. THE "QUISHING" & MALWARE SHIELD === body LOCAL_QR_LURE /\b(scan the QR|QR code below|scan with your phone|mobile scan required)\b/i describe LOCAL_QR_LURE Lures user to scan a QR code score LOCAL_QR_LURE 4.5 header LOCAL_INV_SUBJ Subject =~ /\b(Invoice|Statement|Remittance|PO_|Payment Advice)\b/i body __HAS_HTML_ATT /Content-Type: text\/html; name=.*\.html/i body __HAS_ZIP_ATT /Content-Type: application\/zip; name=.*\.zip/i meta LOCAL_MALWARE_LURE (LOCAL_INV_SUBJ && (__HAS_HTML_ATT || __HAS_ZIP_ATT)) describe LOCAL_MALWARE_LURE Invoice lure with suspicious attachment score LOCAL_MALWARE_LURE 4.1 # === 8. SA GOVT / TENDER HARDENING === header __FROM_GOV_KW From =~ /\b(SARS|eFiling|SAPS|Police|AARTO|Sanral|PRASA|TRANSNET|ESKOM|CIPC)\b/i header __NOT_GOV_DOMAIN From !~ /\.(gov\.za|saps\.gov\.za|sars\.gov\.za|transnet\.net|prasa\.com|eskom\.co\.za|cipc\.co\.za)\b/i meta LOCAL_GOV_PHISH (__FROM_GOV_KW && __NOT_GOV_DOMAIN) describe LOCAL_GOV_PHISH Impersonation of SA Govt or Utility score LOCAL_GOV_PHISH 5.0 header LOCAL_SA_RFQ_SCAM Subject =~ /\b(Request for Quotation|RFQ|Tender Board|Bidding Document|Invitation to Bid)\b/i describe LOCAL_SA_RFQ_SCAM Potential SA Tender/RFQ Phishing score LOCAL_SA_RFQ_SCAM 4.1 # === 9. DOMAIN BLACKLIST (V5.1 CONSOLIDATED) === blacklist_from *.icu blacklist_from *.monster blacklist_from *@*.online blacklist_from *@*.site blacklist_from *@*.ro blacklist_from *@andjemztech.com blacklist_from *@honormairne.com blacklist_from *@seo-factory.ro blacklist_from *@hostburly.com blacklist_from *@pflanzenfruechte.com blacklist_from *@asado.org blacklist_from *@paycity-invoicing.com blacklist_from *@swift-services.net blacklist_from *@firebaseapp.com # === 10. INFRASTRUCTURE WHITELIST (VOXOS & CLIENTS) === whitelist_from *@voxos.co.za whitelist_from *@magicwebdesigns.co.za whitelist_from *@officesolution.co.za whitelist_from *@kwikwap.co.za welcomelist_from_rcvd *@voxos.co.za welcomelist_from_rcvd *@magicwebdesigns.co.za # Client Specific Whitelist (Restored from your April File) whitelist_from admin@totalkroon.co.za whitelist_from incontact@fnb.co.za whitelist_from noreply@cipc.co.za whitelist_from toshibascan@fstoshiba.co.za whitelist_from *@engo.co.za whitelist_from *@ruantel.co.za # === 11. BAYESIAN AUTO-LEARNING === bayes_auto_learn_threshold_spam 4.5 bayes_auto_learn_threshold_ham 0.1