On 4/22/11 11:07 AM, Niamh Holding wrote:
Hello

I have a custom rule-

header   NH_TDIALIN X-Spam-Relays-Untrusted =~ /^[^\]]+ 
rdns=.*dip\.t-dialin\.net/i
score    NH_TDIALIN 1.61
describe NH_TDIALIN Received directly from dynamic t-dialin.net address

postfix? #1, just reject at mta.!
if not, then have postfix check server, and insert a header.
then let SA score that custom header.

(friday is NOT a good day to match wits with regex)


--
Michael Scheidell, CTO
o: 561-999-5000
d: 561-948-2259
ISN: 1259*1300
>*| *SECNAP Network Security Corporation

   * Best Intrusion Prevention Product, Networks Product Guide
   * Certified SNORT Integrator
   * Hot Company Award, World Executive Alliance
   * Best in Email Security, 2010 Network Products Guide
   * King of Spam Filters, SC Magazine

______________________________________________________________________
This email has been scanned and certified safe by SpammerTrap(r). For Information please see http://www.secnap.com/products/spammertrap/ ______________________________________________________________________

Reply via email to