Here's a quick rule I just made in response to Verisign's actions.
header __DNS_SITEFINDER eval:check_rbl_from_host('sitefinder', '.') tflags __DNS_SITEFINDER net header SITEFINDER_IP eval:check_rbl_sub('sitefinder', '64.94.110.11') describe SITEFINDER_IP From: resolves to a verisign hijacked domain. score SITEFINDER_IP 1.5 This requires 2.60 because the check_rbl_from_host was not available until this release. Hope it helps someone! Frederic Tarasevicius Internet Information Services, Inc. ------------------------------------------------------- This sf.net email is sponsored by:ThinkGeek Welcome to geek heaven. http://thinkgeek.com/sf _______________________________________________ Spamassassin-talk mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/spamassassin-talk