> If you use mobile.de as a forwarder, it may make sense to add there IPs to > your trusted_networks configuration. If you do this, the DNSxL tests are > applied to the IP _before_ the mobile.de hop.
That is no problem special to us or our customers. The whitelist level for the four mobile.de IPs in the dnswl simply is wrong. Instead of HI a level of NONE would be right. It can't be the job of all SpamAssassin admins to write local rules because of such a wrong whitelist-scoring.