yeah, RW pretty much hit this one on the head. You're going to need
to exempt it by IP, not by domain name.
On Thu, Nov 5, 2009 at 19:56, RW wrote:
> On Fri, 6 Nov 2009 03:28:40 +
> RW wrote:
>
>
>> The mail.nisdtx.org in the headers is
>> just a helo, so there'
On Fri, 6 Nov 2009 03:28:40 +
RW wrote:
> The mail.nisdtx.org in the headers is
> just a helo, so there's no real evidence for nisdtx.org anywhere in
> the headers. The plugin could do its own A-record lookup on
> mail.nisdtx.org and verify it against the IP addr
On Thu, 5 Nov 2009 19:39:10 -0600
Jonathan Nichols wrote:
> This might be very simple, but Botnet keeps triggering on a local
> school district. I THOUGHT that I added it to the pass_domains list
> correctly.
I'm not 100% sure, but I think the issue is that it hits BOTNET because
mail.nisdtx