Victor Duchovni: > With explicit DNSWL lookups, indeed "defer_if_reject" is acceptable, since > the DWL is operated locally or by a competent provider and persistent temp > failure of lookups is less likely. So it seems to me that this has cleaner > semantics than "check_client_access" with name-based "OK" results, provided > the DWL lookup-key is an address, not a domain name!
A client hostname is bad because it may not be available, but what is the problem with helo/sender/recipient domains? Wietse