Hi;
Just wanted to
share the idea of a filter that we have tested with good
results.
We use our
blacklist in 3 different filters.
- Blacklist- where
we delete at IMail level. This we noticed is real efficient. [Action=
"">
- Blacklist in
Header- where the blacklist entries appear in the header but not as the
sender. At times spammers use the blacklist domain for Rely To but not the
from address. [Action = "">
- Blacklist in
body- the blacklist email addresses appear in the body of email.
[Action = HOLD]
We recently
added another filter and it is:
REVDNS 0 ENDSWITH
Blacklist entry
Of course our
output is based on blacklist entries that just have
.domain.com
This has worked
well and has caught a number of emails.
Just thought to
share this...
Regards,
Kami
