Got a few of these 411 google form spams recently and was wondering why they weren’t getting caught by SA. Looks like the Return-Path: is triggering a whitelist rule on google.com so the rest of the tests aren’t enough to get it tagged. Anything I can do to keep the whitelist rule from firing when the free mail rules have been tripped?
thanks,
-Darrell
Return-Path: <3yVCtXxAJBSQMORGANWAGNERbjjdGMAIL.COM <http://3yvctxxajbsqmorganwagnerbjjdgmail.com/>[me]@trix.bounces.google.com>
Received: from mail.onholyground.com ([unix socket])
by mail.onholyground.com (Cyrus v2.4.20) with LMTPA;
Thu, 12 Nov 2020 09:12:13 -0600
X-Sieve: CMU Sieve 2.4
Received: from mail-vk1-f197.google.com (mail-vk1-f197.google.com [209.85.221.197])
by mail.onholyground.com (8.14.9/8.14.4) with ESMTP id 0ACFCBTW017981
(version=TLSv1/SSLv3 cipher=AES128-GCM-SHA256 bits=128 verify=OK)
for <[me]>; Thu, 12 Nov 2020 09:12:12 -0600
Received: by mail-vk1-f197.google.com with SMTP id y16so1640638vke.0
for <[me]>; Thu, 12 Nov 2020 07:12:12 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20161025;
h=mime-version:reply-to:message-id:date:subject:from:to;
bh=Xj+YfJdy6SvVqmqwKgKqW8OWjMVW3nj8jUVW78yd1PU=;
b=HzlI9oaQiGvUygeibKwDegYKhlGveOjA9H6ruvw9XG6oL/xw8sp+pg8o4kd012rlNu
zgjvPqRhAerGLgGphd0+Kt9vt3MNToHEUI3aDalZ1d7EQeE7ki9uzuvVX8Y/aiAWKI+D
p3J86hMTUEMqVKbAF9kmPTGWmxjon9NAgI7Zx/ZfRW2VbMnlbi5oYnW7n5cyPfu+b1Cr
GxFpzx9AHtrNWNXYR/bhUFLn/y8/6pKhVl+TGEOgBaNgzClWyPH6RbyHMcjDlZ3uTvrG
sDlAUj4uc26J+mrxvk8RpCpUBMAxaT5YkkbSVUzMo51FFmT0dUWeV3LOy6vXU4NBeLXG
Vhuw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20161025;
h=x-gm-message-state:mime-version:reply-to:message-id:date:subject
:from:to;
bh=Xj+YfJdy6SvVqmqwKgKqW8OWjMVW3nj8jUVW78yd1PU=;
b=gACy0+O415lR4xM+JUQo1MBT8RQE1rUBzW/qegRB1NPLJ2kryEPVDL3CQp90id7v2J
trtbPo2DC2Vts4jJx7eQpr6oMPMQIa1aZBJs0Z/6iejQxWgtVOA5YKVLMTrbgvXQ0eRY
/YmtWNfWd562OKhwJi9J28c8VsE6/doJ5aalENGhE9GlLMQ9EdE5zruNXcdLYtgmCtXG
LPgQLTkgY8FLNQNSWNB2ajma4LDWOu8XoawK8+0bTQ4gRfaXt3uja0/dG4B/kogIdoXP
68ogdGoYnlgxLnaqPqn7MFfCE1W9iVSI8eMzrescSR0aOIkgzG6wmvX7BTcPnAtqv4eA
a6eA==
X-Gm-Message-State: AOAM532jkOWP/B/k6Lk0O5/pJBQeNZlR462QiJlMTo6P2kHBNQwoDPM8
0UCdjsmi9g6pQdsPrtr4HaqRpGOB1gA+wgFtP8kk
MIME-Version: 1.0
X-Received: by 2002:a67:b44d:: with SMTP id c13mt20398769vsm.38.1605193929733;
Thu, 12 Nov 2020 07:12:09 -0800 (PST)
Reply-To: morganwagner1993@gmail.com
X-No-Auto-Attachment: 1
Message-ID: <000000000000fa8c4b05b3ea5506@google.com>
Date: Thu, 12 Nov 2020 15:12:11 +0000
Subject: Hello good day.
From: morganwagner1993@gmail.com
To: [me]
Content-Type: multipart/alternative; boundary="00000000000019959e05b3ea56dc"
X-Greylist: Sender succeeded STARTTLS authentication, not delayed by milter-greylist-4.6.2 (mail.onholyground.com [204.130.133.20]); Thu, 12 Nov 2020 09:12:12 -0600 (CST)
X-Spam-Checked: This message probably not SPAM (-94.234)
X-Spam-Tests: BAYES_60,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM,FREEMAIL_REPLYTO,FREEMAIL_REPLYTO_END_DIGIT,HEADER_FROM_DIFFERENT_DOMAINS,HTML_MESSAGE,LOTS_OF_MONEY,MONEY_FRAUD_8,NOT_FROM_SENDER,NOT_SENDER_MSGID,SO_PUB_SNDR_DOMAIN_DKIM_50,SPF_HELO_NONE,SPF_PASS,TXREP,T_GB_FREEM_FROM_NOT_REPLY,USER_IN_SPF_WHITELIST
X-Scanned-By: MIMEDefang 2.84
thanks,
-Darrell
Return-Path: <3yVCtXxAJBSQMORGANWAGNERbjjdGMAIL.COM <http://3yvctxxajbsqmorganwagnerbjjdgmail.com/>[me]@trix.bounces.google.com>
Received: from mail.onholyground.com ([unix socket])
by mail.onholyground.com (Cyrus v2.4.20) with LMTPA;
Thu, 12 Nov 2020 09:12:13 -0600
X-Sieve: CMU Sieve 2.4
Received: from mail-vk1-f197.google.com (mail-vk1-f197.google.com [209.85.221.197])
by mail.onholyground.com (8.14.9/8.14.4) with ESMTP id 0ACFCBTW017981
(version=TLSv1/SSLv3 cipher=AES128-GCM-SHA256 bits=128 verify=OK)
for <[me]>; Thu, 12 Nov 2020 09:12:12 -0600
Received: by mail-vk1-f197.google.com with SMTP id y16so1640638vke.0
for <[me]>; Thu, 12 Nov 2020 07:12:12 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20161025;
h=mime-version:reply-to:message-id:date:subject:from:to;
bh=Xj+YfJdy6SvVqmqwKgKqW8OWjMVW3nj8jUVW78yd1PU=;
b=HzlI9oaQiGvUygeibKwDegYKhlGveOjA9H6ruvw9XG6oL/xw8sp+pg8o4kd012rlNu
zgjvPqRhAerGLgGphd0+Kt9vt3MNToHEUI3aDalZ1d7EQeE7ki9uzuvVX8Y/aiAWKI+D
p3J86hMTUEMqVKbAF9kmPTGWmxjon9NAgI7Zx/ZfRW2VbMnlbi5oYnW7n5cyPfu+b1Cr
GxFpzx9AHtrNWNXYR/bhUFLn/y8/6pKhVl+TGEOgBaNgzClWyPH6RbyHMcjDlZ3uTvrG
sDlAUj4uc26J+mrxvk8RpCpUBMAxaT5YkkbSVUzMo51FFmT0dUWeV3LOy6vXU4NBeLXG
Vhuw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20161025;
h=x-gm-message-state:mime-version:reply-to:message-id:date:subject
:from:to;
bh=Xj+YfJdy6SvVqmqwKgKqW8OWjMVW3nj8jUVW78yd1PU=;
b=gACy0+O415lR4xM+JUQo1MBT8RQE1rUBzW/qegRB1NPLJ2kryEPVDL3CQp90id7v2J
trtbPo2DC2Vts4jJx7eQpr6oMPMQIa1aZBJs0Z/6iejQxWgtVOA5YKVLMTrbgvXQ0eRY
/YmtWNfWd562OKhwJi9J28c8VsE6/doJ5aalENGhE9GlLMQ9EdE5zruNXcdLYtgmCtXG
LPgQLTkgY8FLNQNSWNB2ajma4LDWOu8XoawK8+0bTQ4gRfaXt3uja0/dG4B/kogIdoXP
68ogdGoYnlgxLnaqPqn7MFfCE1W9iVSI8eMzrescSR0aOIkgzG6wmvX7BTcPnAtqv4eA
a6eA==
X-Gm-Message-State: AOAM532jkOWP/B/k6Lk0O5/pJBQeNZlR462QiJlMTo6P2kHBNQwoDPM8
0UCdjsmi9g6pQdsPrtr4HaqRpGOB1gA+wgFtP8kk
MIME-Version: 1.0
X-Received: by 2002:a67:b44d:: with SMTP id c13mt20398769vsm.38.1605193929733;
Thu, 12 Nov 2020 07:12:09 -0800 (PST)
Reply-To: morganwagner1993@gmail.com
X-No-Auto-Attachment: 1
Message-ID: <000000000000fa8c4b05b3ea5506@google.com>
Date: Thu, 12 Nov 2020 15:12:11 +0000
Subject: Hello good day.
From: morganwagner1993@gmail.com
To: [me]
Content-Type: multipart/alternative; boundary="00000000000019959e05b3ea56dc"
X-Greylist: Sender succeeded STARTTLS authentication, not delayed by milter-greylist-4.6.2 (mail.onholyground.com [204.130.133.20]); Thu, 12 Nov 2020 09:12:12 -0600 (CST)
X-Spam-Checked: This message probably not SPAM (-94.234)
X-Spam-Tests: BAYES_60,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM,FREEMAIL_REPLYTO,FREEMAIL_REPLYTO_END_DIGIT,HEADER_FROM_DIFFERENT_DOMAINS,HTML_MESSAGE,LOTS_OF_MONEY,MONEY_FRAUD_8,NOT_FROM_SENDER,NOT_SENDER_MSGID,SO_PUB_SNDR_DOMAIN_DKIM_50,SPF_HELO_NONE,SPF_PASS,TXREP,T_GB_FREEM_FROM_NOT_REPLY,USER_IN_SPF_WHITELIST
X-Scanned-By: MIMEDefang 2.84