The header shows the IP address of REVDNS in the form of:

X-Note: Sent from Reverse DNS: mail.maskofnoreturn.com([65.214.161.171]).

Can the IP address be detected in the HEADER filter?

I want to setup a filter if certain IP addresses are listed in the Header. Ideally I like to filter on the IP address of the REVDNS entry but since we can't it seems like the next best thing is to filter the header.

Since we started keeping track of the REVDNS IP addresses we are finding quite a lot of spammers with the same IP address in their REVDNS but different domain names. I like to experiment with such a filter and evaluate the results.

Although you can detect the IP address with the HEADER filter, you could instead use REMOTEIP:


REMOTEIP 0 IS 65.214.161.171

or

REMOTEIP 0 CONTAINS 65.214.161.


-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you have been missing: Ask for a free 30-day evaluation.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.JunkMail mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.JunkMail".  The archives can be found
at http://www.mail-archive.com.

Reply via email to