I got an unexpected hit on a test that shouldn't have passed the first line of the filter which has a REVDNS NOTENDSWITH statement. I have confirmed the condition in other E-mails that I have have been processed since I modified this filter. This statement is tripping unexpectedly whenever a (timeout) condition is met for the REVDNS lookup. A sample filter that will always hit regardless of host with this bug in a timeout condition is as follows.

REVDNS        END    NOTENDSWITH    .mailpure.com
REMOTEIP    1    CONTAINS    .

Good catch.

This will be fixed in the next release. Specifically, this will happen if the string you are comparing against ("(timeout)" in this case) is shorter than the search string (".mailpure.com"). So given the details of the issue, a broader workaround might be an extra line "REVDNS END NOTENDSWITH .com" as the first line.

-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000.
Declude Virus: Ultra reliable virus detection and the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask for a free 30-day evaluation.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.JunkMail mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.JunkMail".  The archives can be found
at http://www.mail-archive.com.

Reply via email to