Saw this today, Jul 6 09:04:14 mx1 policyd-spf[19732]: : prepend Received-SPF: Pass (sender SPF authorized) identity=helo; client-ip=40.107.243.78; helo=nam12-dm6-obe.outbound.protection.outlook.com; envelope-from=mela...@example.com; receiver=example.net
But, $ dig +short nam12-dm6-obe.outbound.protection.outlook.com 157.56.209.183 and, $ dig +short -x 40.107.243.78 mail-dm6nam12on2078.outbound.protection.outlook.com. When the sending domain does not have its own SPF record, that mismatch triggers spamassassin's FORGED_SPF_HELO rule. It's only adding one point, but since you send a bajillion messages, it'd be nice to avoid. _______________________________________________ mailop mailing list mailop@mailop.org https://list.mailop.org/listinfo/mailop