On Sat, 6 Dec 2008, Mike Cisar wrote:

- the "from" always matches the "to" (so it always looks like its coming
  from yourself)

Silly, basic question: have you whitelist_from'd yourself? Baaad idea.

SPF checks would catch that if you published SPF records for your domain. If you know that mail from your domain will ever only originate at your MTA, then you might do what I do: use milter-regex to reject at SMTP time any mail inbound from the internet that claims to come from your domain.

http://www.impsec.org/~jhardin/antispam/

--
 John Hardin KA7OHZ                    http://www.impsec.org/~jhardin/
 [EMAIL PROTECTED]    FALaholic #11174     pgpk -a [EMAIL PROTECTED]
 key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C  AF76 D822 E6E6 B873 2E79
-----------------------------------------------------------------------
  The yardstick you should use when considering whether to support a
  given piece of legislation is "what if my worst enemy is chosen to
  administer this law?"
-----------------------------------------------------------------------
 9 days until Bill of Rights day

Reply via email to