>>>>> amavisd-new with spamassassin and anti virus scanner, clamav with
>>>>> sanesecurity rules
>>>>> use enforcing rules in mail server, like block hosts with no DNS/rDNS
>>>>> Enforce SPF, publish SPF with hardfail
>>>>> use DNSBL's in your mail server, spamhaus, spamcop, spam.sorbs, and
>>>>> more etc.
>>>>> milter regex to stop dynamic/suspect hosts
>>>>> There is no one solution, the solution, is a box of many tricks
>>>>> You might get the odd false blocking, but if system opers can not be
>>>>> bothered running a compliant network with standardised naming
>>>>> conventions for servers, then it is not my problem, and we have had
>>>>> very
>>>>> very very few complaints about this type of policy in over a
>>>>> decade. If
>>>>> someoine sooks to you, educate them, dont whitelist them.
>>>> We (72,000 mailboxes) are currently using amavisd-new with
>>>> spamassassin and CRM114 via a custom plugin instead of the default
>>>> bayesian filter. Also like Noel, we're using DNSBLs, SPF (although we
>>>> had to publish a permissive record since some of our users are using
>>>> their ISP smtp instead of our own).
>>> try slockd ,it is a policy server for postfix
done , nice tool

