#spamd
@dalias
Maybe a tarpit like OpenBSD's spamd?

https://man.openbsd.org/spamd.8
spamd(8) - OpenBSD manual pages
man.openbsd.org
July 5, 2025 at 10:12 PM
So DANE/TLSA records are incompatible with a spamd tarpit unless it is made to support STARTSSL. That sucks. I've recently set up TLSA records for my mail servers, but I also run a spamd tarpit that doesn't support STARTSSL, so I can't receive mail from non-whitelisted mail servers that use DANE.
May 23, 2025 at 11:56 PM
The latest "Lazy reading" by Dragonfly Digest www.dragonflydigest.com has "Eighteen years of Greytrapping" nxdomain.no/~peter/eight... featured. (Later this year it wil be nineteen years :) and updates will come) #spamd #spam #openbsd #antispam #greytrapping #greylisting #cybercrime
DragonFly BSD Digest – A running description of activity related to DragonFly BSD.
www.dragonflydigest.com
January 18, 2026 at 2:21 PM
spamd child max
I have the following information: posfix + dovecot + spamassisan , So: Code: unix root@mail:~ # ps ax |grep spam 18914 - Ss 12:10.69 spamd (perl) 74489 - Ss 0:00.36 /usr/local/sbin/spamass-milter -f -p /var/run/spamass-milter.sock 80859 - I 0:01.79 spamd child (perl) 84587 - I 0:00.92 spamd child (perl) I have the following info in /var/log/maillog: Code: warning: milter inet:127.0.0.1:783: unreasonable packet length: 1397768525 > 1073741823 spamd[18914]: prefork: child states: MANY_TYPE_SUCH_AS_BBB_OR_BI_AND_SO_ON warning: milter inet:127.0.0.1:783: can't read SMFIC_OPTNEG reply packet header: Operation timed out An instance of my maillog: Code: Jun 6 14:19:18 mail spamd[18914]: prefork: child states: IBIBB Jun 6 14:19:18 mail postfix/smtpd[84968]: warning: milter inet:127.0.0.1:783: can't read SMFIC_OPTNEG reply packet header: Operation timed out Jun 6 14:19:18 mail postfix/smtpd[84968]: warning: milter inet:127.0.0.1:783: read error in initial handshake Jun 6 14:19:18 mail postfix/smtpd[84968]: lost connection after CONNECT from unknown[66.63.187.8] Jun 6 14:19:18 mail spamd[84972]: spamd: bad protocol: header error: \x{00}\x{00}\x{00}\rO\x{00}\x{00}\x{00}\x{06}\x{00}\x{00}\x{01}\x{FF}\x{00}\x{1F}\x{FF}\x{FF} Jun 6 14:19:18 mail postfix/smtpd[84968]: disconnect from unknown[66.63.187.8] commands=0/0 Jun 6 14:19:18 mail spamd[18914]: prefork: child states: IBIIB Jun 6 14:19:18 mail spamd[18914]: prefork: adjust: 3 idle children more than 2 maximum idle children. Decreasing spamd children: 84972 killed. Jun 6 14:19:18 mail spamd[18914]: prefork: child states: IBIKB Jun 6 14:19:18 mail spamd[18914]: spamd: handled cleanup of child pid [84972] due to SIGCHLD: interrupted, signal 2 (0002) Jun 6 14:19:27 mail spamd[84973]: spamd: timeout: (30 second socket timeout reading input from client) Jun 6 14:19:27 mail postfix/smtpd[84969]: warning: milter inet:127.0.0.1:783: unreasonable packet length: 1397768525 > 1073741823 Jun 6 14:19:27 mail postfix/smtpd[84969]: warning: milter inet:127.0.0.1:783: read error in initial handshake Jun 6 14:19:27 mail postfix/smtpd[84969]: lost connection after CONNECT from unknown[212.120.163.110] Jun 6 14:19:27 mail postfix/smtpd[84969]: disconnect from unknown[212.120.163.110] commands=0/0 Jun 6 14:19:27 mail spamd[18914]: prefork: child states: IBII Jun 6 14:19:27 mail spamd[18914]: prefork: adjust: 3 idle children more than 2 maximum idle children. Decreasing spamd children: 84973 killed. Jun 6 14:19:27 mail spamd[18914]: prefork: child states: IBIK Jun 6 14:19:27 mail spamd[18914]: spamd: handled cleanup of child pid [84973] due to SIGCHLD: interrupted, signal 2 (0002) Jun 6 14:19:37 mail postfix/smtpd[84971]: connect from unknown[182.204.177.94] Jun 6 14:19:37 mail spamd[80859]: spamd: connection from localhost [127.0.0.1]:32591 to port 783, fd 6 Jun 6 14:19:41 mail spamd[84587]: spamd: timeout: (30 second socket timeout reading input from client) Jun 6 14:19:41 mail postfix/smtpd[84970]: warning: milter inet:127.0.0.1:783: unreasonable packet length: 1397768525 > 1073741823 Jun 6 14:19:41 mail postfix/smtpd[84970]: warning: milter inet:127.0.0.1:783: read error in initial handshake Jun 6 14:19:41 mail postfix/smtpd[84970]: lost connection after CONNECT from unknown[182.204.177.94] Jun 6 14:19:41 mail postfix/smtpd[84970]: disconnect from unknown[182.204.177.94] commands=0/0 Jun 6 14:19:41 mail spamd[18914]: prefork: child states: BII Jun 6 14:20:03 mail postfix/smtpd[84965]: connect from unknown[182.204.177.94] My postconf: Code: root@mail:~ # postconf -m btree cidr environ fail hash inline internal ldap memcache mysql pcre pipemap proxy randmap regexp socketmap static tcp texthash unionmap unix My master.cf is: Code: root@mail:~ # grep -v ^# /usr/local/etc/postfix/master.cf |grep -v ^$ smtp inet n - n - - smtpd smtps inet n - n - - smtpd -o syslog_name=postfix/smtps -o smtpd_tls_wrappermode=yes -o smtpd_sasl_auth_enable=yes -o smtpd_sasl_type=dovecot -o smtpd_sasl_path=private/auth -o smtpd_client_restrictions=permit_sasl_authenticated,reject -o milter_macro_daemon_name=ORIGINATING -o content_filter=spamassassin submission inet n - n - - smtpd -o syslog_name=postfix/submission -o smtpd_tls_security_level=encrypt -o smtpd_sasl_auth_enable=yes -o smtpd_sasl_type=dovecot -o smtpd_sasl_path=private/auth -o smtpd_reject_unlisted_recipient=no -o smtpd_client_restrictions=permit_sasl_authenticated,reject -o milter_macro_daemon_name=ORIGINATING dovecot unix - n n - - pipe flags=DRhu user=vmail:vmail argv=/usr/local/libexec/dovecot/deliver -f ${sender} -d ${user}@${nexthop} pickup unix n - n 60 1 pickup cleanup unix n - n - 0 cleanup qmgr unix n - n 300 1 qmgr tlsmgr unix - - n 1000? 1 tlsmgr rewrite unix - - n - - trivial-rewrite bounce unix - - n - 0 bounce defer unix - - n - 0 bounce trace unix - - n - 0 bounce verify unix - - n - 1 verify flush unix n - n 1000? 0 flush proxymap unix - - n - - proxymap proxywrite unix - - n - 1 proxymap smtp unix - - n - - smtp -o content_filter=spamassassin relay unix - - n - - smtp -o syslog_name=postfix/$service_name showq unix n - n - - showq error unix - - n - - error retry unix - - n - - error discard unix - - n - - discard local unix - n n - - local virtual unix - n n - - virtual lmtp unix - - n - - lmtp anvil unix - - n - 1 anvil scache unix - - n - 1 scache maildrop unix - n n - - pipe flags=DRhu user=vmail argv=/usr/local/bin/maildrop -d ${recipient} postlog unix-dgram n - n - 1 postlogd spf-policy unix - n n - 0 spawn user=nobody argv=/usr/local/libexec/postfix-policyd-spf-perl spamassassin unix - n n - - pipe user=nobody argv=/usr/local/bin/spamc -u ${recipient} -f -e /usr/sbin/sendmail -oi -f ${sender} ${recipient} How can I run SA right?
forums.FreeBSD.org
June 7, 2025 at 4:22 AM
meu deus imagina se todos esses spamd que eu recebo são na verdade vagas de emprego e eu nunca atendo 😭😭😭😭 fiquei preocupado agora
August 6, 2024 at 7:24 PM
nxdomain.no
February 24, 2026 at 9:12 AM
The update you have been waiting for:

"Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off?" nxdomain.no/~peter/eight... (tracked bsdly.blogspot.com/2025/08/eigh...)

now has the complete 2025 data. #openbsd #spamd #greytrapping #spam #antispam #cybercrime #spamtraps #blocklists
Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off?
nxdomain.no
January 1, 2026 at 4:57 PM
Hm. Publishing "Eighteen years of greytrapping ..." retrospective nxdomain.no/~peter/eight... (bsdly.blogspot.com/2025/08/eigh...) has led to an uptick in digital archaeology. People are fetching the archived lists! #greytrapping #spamd #openbsd #pf #packetfiltering #antispam #cybercrime #security
Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off?
nxdomain.no
August 21, 2025 at 7:23 AM
had to wrangle some stragglers who managed to get through spamd on our backup MX! fired. out of the cannon. into the sun.
January 27, 2026 at 12:03 AM
OpenBSD spamd with greylisting, spamassassin + client-side, strict DKIM/SPF policies, and various other blacklists.
September 8, 2024 at 6:39 PM
Eighteen Years of Greytrapping Retrospective Published
www.undeadly.org
August 12, 2025 at 6:45 AM
Whew. I think I finally got spamass-milter talking to spamd. At least, there's no errors in the logs and my test emails arrive in a reasonable time frame.

Now just to wait for more spam.

#postfix #spamassassin
July 22, 2025 at 12:38 AM
The Rest Is Trash
nxdomain.no
February 1, 2026 at 11:43 AM
"The Rest Is Trash"
We are now halfway through the nineteenth year of greytrapping, still tracking and collecting from the wealth of imbecility out there
nxdomain.no/~peter/the_r... bsdly.blogspot.com/2026/02/the-... #spamd #greytrapping #greylisting #openbsd #freebsd #spam #antispam #cybercrime
The Rest Is Trash
nxdomain.no
February 7, 2026 at 11:57 AM
The Rest Is Trash
nxdomain.no
February 4, 2026 at 6:42 PM
Eighteen years of greytrapping (nxdomain.no/~peter/eight... or tracked bsdly.blogspot.com/2025/08/eigh... has numbers and graphs refreshed as of end of July (now actually 19 years).

#spam #antispam #spamd #openbsd #greylisting #greytrapping #security #cybercrime #cybersecurity #smtp #email
Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off?
nxdomain.no
August 2, 2026 at 11:11 AM
Possibly not blogworthy, but: One puzzling side effect of running greytrapping (as in nxdomain.no/~peter/eight...) is seeing password guessers using obviously generated gibberish local parts (see nxdomain.no/~peter/shoul...). #greytrapping #passwordguessing #passwordgroping #spamd #ssh #pop3gropers
Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off?
nxdomain.no
December 24, 2025 at 1:05 PM
Heh. Looks like Why 451 is Good for You - Greylisting Perspectives From the Early Noughties nxdomain.no/~peter/why_4... (tracked bsdly.blogspot.com/2025/12/why-...) hit hackernews: news.ycombinator.com/item?id=4641...

#greylisting #greytrapping #spam #spamtrapping #antispam #spamd #openbsd #smtp
Why 451 is Good for You - Greylisting Perspectives From the Early Noughties
nxdomain.no
January 3, 2026 at 12:42 PM
An update on #green #cybercrime #prevention: "Harvesting the Noise While it's Fresh, Revisited" nxdomain.no/~peter/harve... (or bsdly.blogspot.com/2022/12/that...) updated: harvesting even more useful data from #openbsd #spamd log noise.
#antispam #greytrapping #greencomputing #spam #email #smtp
That grumpy BSD guy: Harvesting the Noise While it's Fresh, Revisited
nxdomain.no
January 12, 2025 at 1:34 PM
"Oh yes, you signed up for this. You did. Honest." https://nxdomain.no/~peter/oh_yes_you_signed_up_for_this_2009.html A linkedin post (linked within) reminded me of this post, added here, almost pristine
#greytrapping #spam #countermeasures #email #scams #spamd "well poisoning #cybercrime
Oh yes, you signed up for this. You did. Honest.
nxdomain.no
July 25, 2025 at 6:30 AM
"Oh yes, you signed up for this. You did. Honest." nxdomain.no/~peter/oh_ye... A linkedin post by @paulvixie.bsky.social (linked within) reminded me of this post, so added here, almost pristine
#greytrapping #spam #countermeasures #email #scams #spamd #wellpoisoning #cybercrime
Oh yes, you signed up for this. You did. Honest.
nxdomain.no
July 25, 2025 at 6:32 AM
Is SPF Simply Too Hard For Application Developers?
Sender Policy Framework (SPF) is unloved by some, because it conflicts with established SMTP email use cases. But is it also just too hard? nxdomain.no/~peter/is_sp...
(2016 but still holds) #smtp #spf #mail #spam #antispam #security #openbsd #spamd
Is SPF Simply Too Hard For Application Developers?
nxdomain.no
January 22, 2025 at 10:04 PM
"Maintaining A Publicly Available Blacklist - Mechanisms And Principles" (also bsdly.blogspot.com/2013/04/main...). TL;DR: blocklisting is a kind of public shaming, be sure your process is verifiable+transparent.

#blocklists #spamtraps #antispam #smtp #spamd #openbsd #freebsd #security #cybercrime
Maintaining A Publicly Available Blacklist - Mechanisms And Principles
When you publicly assert that somebody sent spam, you need to ensure that your data is accurate . Your process needs to be simple and veri...
bsdly.blogspot.com
August 2, 2025 at 11:28 AM
python-aiospamc
Asyncio-based client for SpamAssassin's SPAMD service
aur.archlinux.org
September 12, 2026 at 10:21 PM