Best way to slow down all the spam to my lists?

I'm the system admin (though I'm not great at it). I have a problem with spam. Hundreds of spam messages are posted to my lists each week. They're non-subscribers so they don't go to the lists, but they *do* go to me, the list owner which floods my inbox.
I'm looking at the page on how to use SpamAssassin: https://wiki.list.org/DOC/4.23%20How%20do%20I%20use%20SpamAssassin%20with%20...
Is that the best way to do what I need? If so, what's the best method to use in my case? My system: Mailman 2.1.20 Apache2 / 2.4.18 Postfix 3.1.0 Ubuntu 16.04.1 LTS

On 12/12/2019 9:46 AM, Chromatest J. Pantsmaker wrote:
I'm the system admin (though I'm not great at it). I have a problem with spam. Hundreds of spam messages are posted to my lists each week.
(What's a acceptable level? I wouldn't spend many hours just to eliminate 3 spams a day.)
Is that the best way to do what I need?
I'd go for #1, filtering at the MTA level, so that mailman generally has less to do, for some ideas-
https://www.howtoforge.com/spam-control-for-postfix https://www.linuxbabe.com/mail-server/block-email-spam-postfix
By implementing some of these, you may decide that spam-assassin isn't necessary.
Later,
z!

Thanks for the responses Carl and Bruce,
I've been getting about 20 per day. Some days more. The noise is way higher than the signal level here. It's a low-used email list.
I'll try out filtering at the MTA level and see how it goes.
On Fri, Dec 13, 2019 at 10:34 AM Carl Zwanzig <cpz@tuunq.com> wrote:

On 12/12/19 12:46 PM, Chromatest J. Pantsmaker wrote:
If you can't get earlier filtering to get the rate low enough, you may need to just change the option
Action to take for postings from non-members for which no explicit action is defined. (Details for generic_nonmember_action) To discard so you don't get the messages (don't set it to reject or you will be backscattering). It does say that you won't see messages that should go to the list but the send used the wrong account.
-- Richard Damon

Yeah, I wanted to avoid that because non-subscribers often email the list trying to contact the list admins or organization representatives instead. I've tried the first link above up through step 4. Step 5 is adding an additional filter to Spam Assassin and doesn't appear to be directly connected to the first four steps.
On Fri, Dec 13, 2019 at 11:18 AM Richard Damon <Richard@damon-family.org> wrote:

On Fri, Dec 13, 2019 at 11:16 AM Chromatest J. Pantsmaker < chromatest@chromatest.net> wrote:
I use RBL’s and the Spamassassin milter in Postfix with great success
David
-- IBM i on Power Systems: For when you can't afford to be out of business!
I'm riding in the American Diabetes Association's Tour de Cure to raise money for diabetes research, education, advocacy, and awareness. You can make a tax-deductible donation to my ride by visiting https://mideml.diabetessucks.net.
You can see where my donations come from by visiting my interactive donation map ... https://mideml.diabetessucks.net/map (it's a geeky thing).
I may have diabetes, but diabetes doesn't have me!

Good day all:
----- Original Message -----
just a fwiw:
years back, I ran a pretty fun mailman instance that handled a lot of internal tasks, and was integrated into a doc management system, was glued to a few ticket management systems, archived all of our accounting stuff, did hylafax, all kinds of fun tricky things
Of course, these internal lists got spammed all the time.
as an email sysadmin, I had notifications turned off, and it was part of the weekly checklist to log into the admin section of these lists and clear out all of the moderation stuff.
These seldom went over a few hundred per list per week, so it didn't actually take all that long. kind of a fri or mon morning-over-coffee task that I always suspected could be automated, but in-the-end, was a thing that really was best handled by someone who cared about 'delivering the mail' ! (aka, the postmaster's job).
fwiw. --chipper

On 12/12/2019 9:46 AM, Chromatest J. Pantsmaker wrote:
I'm the system admin (though I'm not great at it). I have a problem with spam. Hundreds of spam messages are posted to my lists each week.
(What's a acceptable level? I wouldn't spend many hours just to eliminate 3 spams a day.)
Is that the best way to do what I need?
I'd go for #1, filtering at the MTA level, so that mailman generally has less to do, for some ideas-
https://www.howtoforge.com/spam-control-for-postfix https://www.linuxbabe.com/mail-server/block-email-spam-postfix
By implementing some of these, you may decide that spam-assassin isn't necessary.
Later,
z!

Thanks for the responses Carl and Bruce,
I've been getting about 20 per day. Some days more. The noise is way higher than the signal level here. It's a low-used email list.
I'll try out filtering at the MTA level and see how it goes.
On Fri, Dec 13, 2019 at 10:34 AM Carl Zwanzig <cpz@tuunq.com> wrote:

On 12/12/19 12:46 PM, Chromatest J. Pantsmaker wrote:
If you can't get earlier filtering to get the rate low enough, you may need to just change the option
Action to take for postings from non-members for which no explicit action is defined. (Details for generic_nonmember_action) To discard so you don't get the messages (don't set it to reject or you will be backscattering). It does say that you won't see messages that should go to the list but the send used the wrong account.
-- Richard Damon

Yeah, I wanted to avoid that because non-subscribers often email the list trying to contact the list admins or organization representatives instead. I've tried the first link above up through step 4. Step 5 is adding an additional filter to Spam Assassin and doesn't appear to be directly connected to the first four steps.
On Fri, Dec 13, 2019 at 11:18 AM Richard Damon <Richard@damon-family.org> wrote:

On Fri, Dec 13, 2019 at 11:16 AM Chromatest J. Pantsmaker < chromatest@chromatest.net> wrote:
I use RBL’s and the Spamassassin milter in Postfix with great success
David
-- IBM i on Power Systems: For when you can't afford to be out of business!
I'm riding in the American Diabetes Association's Tour de Cure to raise money for diabetes research, education, advocacy, and awareness. You can make a tax-deductible donation to my ride by visiting https://mideml.diabetessucks.net.
You can see where my donations come from by visiting my interactive donation map ... https://mideml.diabetessucks.net/map (it's a geeky thing).
I may have diabetes, but diabetes doesn't have me!

Good day all:
----- Original Message -----
just a fwiw:
years back, I ran a pretty fun mailman instance that handled a lot of internal tasks, and was integrated into a doc management system, was glued to a few ticket management systems, archived all of our accounting stuff, did hylafax, all kinds of fun tricky things
Of course, these internal lists got spammed all the time.
as an email sysadmin, I had notifications turned off, and it was part of the weekly checklist to log into the admin section of these lists and clear out all of the moderation stuff.
These seldom went over a few hundred per list per week, so it didn't actually take all that long. kind of a fri or mon morning-over-coffee task that I always suspected could be automated, but in-the-end, was a thing that really was best handled by someone who cared about 'delivering the mail' ! (aka, the postmaster's job).
fwiw. --chipper
participants (5)
-
Carl Zwanzig
-
Chip Mefford
-
Chromatest J. Pantsmaker
-
David Gibbs
-
Richard Damon