Hello, All,
I've been getting tons of spam where the domain name used in the sender,
e.g. [EMAIL PROTECTED], exactly matches the helo, e.g. justasailor.com.

Is there any way to set up a test to add points if these 2 are identical?  I
was thinking there might be a way to do it using the variables that Declude
creates but I don't know exactly what the syntax would be and I don't know
if Declude parses out the domain name into it's own variable.  But if there
were such a variable I'm thinking something along the lines of...

FROMDOMAIN  50  IS  %HELO%

Thanks In Advance,
Dan Geiser




-------------------------------------------------------------------
E-mail scanned for viruses by Nexus (http://www.ntgrp.com/mailscan)

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.JunkMail mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.JunkMail".  The archives can be found
at http://www.mail-archive.com.

Reply via email to