On Wed, 2007-09-05 at 10:50 +0200, mouss wrote: > ram wrote: > > I am using SA 3.2.3 and very few spam get thru > > But I can still see some spam with urls because the the urls are not yet > > listed in uribls > > > > I tried to do some analysis on my quarantine, I found atleast some > > spammer domains have the same NS records. > > > > Now in my spamassassin can I do a DNS check (on all domains in body-urls > > or mail-from, reply-to etc) to find their NS records and score them on > > bad NS servers. > > What is the risk of FP's because innocent DNS providers may see > > themselves getting list > > > > > better show an example so that we can see. > if the NS belongs to a spam organization, then it's ok. otherwise, just > because a spammer configures his dns to point to my domain doesn't mean > you can block me! >
But if his DNS points to your server and you dont host DNS for him, his domain will not get resolved. I could easily check for such domains then.