Hello Ryan, Friday, October 21, 2005, 1:22:38 PM, you wrote:
RM> This thread is ancient I know, but I am still using the rule posted below but RM> had to make an update to it (in case anyone else also uses this rule). RM> I changed __X_AUTH_WARN_3 to read: RM> header __X_AUTH_WARN_3 X-Authentication-Warning !~ /(?:using -f|owned RM> process doing -bs)/ RM> to accomodate for the following valid header: RM> X-Authentication-Warning: some.host.com: username owned process doing -bs SA 3.1.0 uses: 20_head_tests.cf:header X_AUTH_WARN_FAKED X-Authentication-Warning !~ /(?:set sender to \S{2,80} using -f|owned process doing -bs|claimed to be| didn.t use HELO protocol)/ [if-unset: host.example.com: foo owned process doing -bs] Bob Menschel