> /root/whitelist.txt:
> 216.239.32.0/19      #gmail servers

I just allowed all the announcements I saw from their AS for now.

64.233.160/19
66.102/20
66.249.64/19
72.14.192/19
72.14.224/20
216.239.32/19

Unless you run a site with enough users that they stay whitelisted
anyway, the larger shared-spool mail systems can be something of a problem,
so it's worth keeping an eye on 'spamdb|grep GREY'.

> It's a bit of an extreme allowance really... www.dnsstuff.com is good for
> looking up allocated IP ranges by the way.

Find the relevant AS, use a looking-glass or route-views if you don't have
your own router to pull it from. In cizcoeee that's "sh ip bgp reg _15169$".

> If you make a change to the whitelist file, update the table with:
> pfctl -t spamd-mywhite -T add -f /root/white.txt

-Tr (rather than -Ta) covers deletions too.
Add -v to get feedback.

Reply via email to