|
|||||||||||
|
A compound bounce/(spf/dk/dkim) rule I'd like to see.
From: Dan Mahoney, System Admin <danm(at)prime.gushi.org>
Date: Wed Oct 10 2007 - 15:06:25 EDT
IF (message is a recognizable bounce || message is from <>)... AND (we can guess the domain being sent to (can't trust the "to" header, but maybe the X-Envelope-To or some MTA token?) AND the domain being sent TO supports SPF and/or DKIM...(i.e. implying a misdirected bounce) Score a compound rule hit. My logic here is that I would eventually like to compile an rfc-ignorant list of the senders of such bounces, and aid them in not SENDING such bounce messages, or at the very least, set up a ruleset in the future to block bounces from them, based on a low signal/noise ratio. I am not trying at all to claim that this should be something SCORABLE, immediately: I don't think SA's detection of legitimate bounce messages versus illegitmate bounce messages is good enough (please feel free to tell me differently). -Dan Mahoney -- "GO HOME AND COOK!!!" Donielle Cocossa, Taco Bell, 2:30 AM --------Dan Mahoney-------- Received on Wed Oct 10 15:08:49 2007 This archive was generated by hypermail 2.1.8 : Fri Jul 04 2008 - 12:18:51 EDT |
||||||||||
|
|||||||||||