>Can someone help me with this please? 205.214.199.131 is a sendmail machine
>I have rigged to help out Imail with deliveries so it has a secondary MX.
>People send mail to xxx from xxx which is obviously forged and the only
>proof is the X-auth warning from my secondary MX. Can anyone see any way of
>stopping this? I thought of using a filter but the filters afaik does not do
>HEADERS.

>X-Declude-Sender: [EMAIL PROTECTED] [205.214.199.131]

Here's the problem -- Declude JunkMail sees the E-mail as coming directly 
from your sendmail machine.  If you add a line "IPBYPASS 205.214.199.131" 
to the \IMail\Declude\global.cfg file, Declude JunkMail will see the IP 
that the spam was really sent from.

The new filtering that is in beta doesn't have a way to filter the headers 
yet, but it will.

                                                    -Scott
---
Declude: Anti-virus, Anti-spam and Anti-hijacking solutions for 
IMail.  http://www.declude.com

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---

This E-mail came from the Declude.JunkMail mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.JunkMail".  You can E-mail
[EMAIL PROTECTED] for assistance.  You can visit our web
site at http://www.declude.com .

Reply via email to