I solved this same problem last week by setting up my own DNS server
that does not do forwarding - it hits the root servers. It was a bugger
to figure out, finally reached out to Validity and they sent me the
below note about query limit.
> check: dns_block_rule RCVD_IN_VALIDITY_SAFE_BLOCKED hit, creating
/root/.spamassassin/dnsblock_sa-accredit.habeas.com (This means DNSBL
blocked you due to too many queries. Set all affected rules score to 0,
or use "dns_query_restriction deny sa-accredit.habeas.com" to disable
queries)
> To be clear, Validity has no association with Spamassassin. And this
too many queries message is not saying you on our blocklist nor are we
blocking your emails. This message is saying that the party querying our
block list has reached their query limit.
I have that.
Then I don't understand why I still have the issue with
RCVD_IN_VALIDITY_CERTIFIED_BLOCKED
RCVD_IN_VALIDITY_RPBL_BLOCKED
RCVD_IN_VALIDITY_SAFE_BLOCKED
(in the spamd logs and in the message headers).