Hello All, A client in my domain let's say domain.com is receiving lots of bounce mails "backscatter" or "joe job" can I block all bounced mail to that specific user u...@domain.com? I have the following check_headers but does not work for me because it will block genuine email and mail server relays mail for three other domains.
/^Subject: .*Unzustellbar: Twit 99-435/ DISCARD /^Subject: .*Your Discount Code on Amazon/ DISCARD /^Subject: .*Returned mail: Service unavailable/ DISCARD /^Subject: .*SPAM? Notifica sullo stato del recapito (Errore)/ DISCARD /^Subject: .*\*\*\*SPAM\*\*\*/ DISCARD /^Subject: .*Returned Mail: *Twit 99-435/ DISCARD /^Subject: .* Delivery Notification: Delivery has failed/ DISCARD /^Subject: .Considered UNSOLICITED BULK EMAIL/ DISCARD /^Subject: .Undeliverable: Twitter 957-358/ DISCARD /^Subject: .Mail delivery failed: returning message/ DISCARD /^Subject: .Returned mail: see transcript for deatils/ DISCARD /^Subject: .Spam: Delivery Status Notification (Failure)/ DISCARD /^Subject: .Undeliverable Mail/ DISCARD /^Subject: .failure notice/ DISCARD /^Subject: .Mailzustellung fehlgeschlagen / Mail delivery failed/ DISCARD /^Subject: .*Store Apple/ DISCARD /^Subject: .*Mail Delivery Failure/ DISCARD /^From: .*Viagra/ DISCARD /^From: Mail Delivery Subsystem/ DISCARD /^From: .*MDaemon/ DISCARD /^From: .*Systemadministrator/ DISCARD /^Subject: Virus Detected by Network Associates, Inc\. Webshield/ DISCARD /^Subject:.* ---- Virus Detected ----$/ DISCARD All bounced mail came from different domains. Reporting-MTA: dns;hesa06uker.he.local Received-From-MTA: dns;c2beaimr05.btconnect.com Arrival-Date: Fri, 14 May 2010 07:19:48 +0100 Final-Recipient: rfc822;private...@4wealthifa.com Action: failed Status: 5.1.1 Reporting-MTA: dns;habexchange.THC.local Received-From-MTA: dns;spamserver.habitat.com Arrival-Date: Fri, 14 May 2010 00:52:45 -0500 Final-Recipient: rfc822;rick_whi...@habitat.com Action: failed Status: 5.1.1 Thanks, Motty