https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6919

            Bug ID: 6919
           Summary: RDNS_DYNAMIC / HELO_DYNAMIC_IPADDR overshoot with
                    generic dedicated server hosting RDNS
           Product: Spamassassin
           Version: 3.3.1
          Hardware: PC
                OS: Linux
            Status: NEW
          Severity: normal
          Priority: P2
         Component: Rules
          Assignee: [email protected]
          Reporter: [email protected]
    Classification: Unclassified

The rules 
 0.4 RDNS_DYNAMIC           Delivered to internal network by host with
                            dynamic-looking rDNS
 3.2 HELO_DYNAMIC_IPADDR    Relay HELO'd using suspicious hostname (IP addr
                            1)
match on the generic RDNS that is issued by many hosting and colocation
providers, in this case the german company HostEurope:

Received: from ds80-237-211-109.dedicated.hosteurope.de
(ds80-237-211-109.dedicated.hosteurope.de [80.237.211.109])

The machine in question is a dedicated server with a fixed IP address and very
unlikely to have a DynIP. 

This overshoot combined with the relatively high score is responsible for some
false positives on our setup.

-- 
You are receiving this mail because:
You are the assignee for the bug.

Reply via email to