OK the rule to block an unknown or a mail server without a PTR works great:

 

header  LOCAL_INVALID_PTR2  Received =~ /from \S+ \(unknown /

score  LOCAL_INVALID_PTR2         2

describe LOCAL_INVALID_PTR2       Header contains no PTR2

 

 

Now how can I make a rule to score if the PTR is different than the reported mail server like the SPAMMER below?:

 

Received: from cirencester.co.uk (c204131.adsl.hansenet.de [213.39.204.131])

 

 

Thanks in advance,

 

 

 

 

Robert

 

 

 

 

 

 

Peace he would say instead of goodbye....peace my brother.

 

Reply via email to