On Thursday 20 May 2004 15:57, Chris Santerre might have typed: > The key to this virus is this line: > Received: from multicam.com (adsl-64-173-247-195.dsl.lsan03.pacbell.net > [64.173.247.195]) > > it is your domain, but NOT your IP. What you need to do is write a rule for > that.
Alternate to a rule, use an access list at the MTA level (I know postfix does this) that rejects a HELO of your domain unless the host is allowed to use that HELO. That way you don't even have to bother with scanning the mail.
