On Mon, 20 Apr 2015 20:50:08 +0200 Axb wrote: > On 04/20/2015 08:04 PM, Dianne Skoll wrote:
> > Is anyone else seeing a sudden uptick in RCVD_ILLEGAL_IP FPs? > > There is an ongoing discussion about this with MS, thru backchannels. > > They're intentionally using the 0/8 to mask internal IPs. > A very VERY bad choice and they have been advised that not only SA > thinks it's a bad idea. Yahoo did the same thing a couple of months. Perhaps it would be useful to split RCVD_ILLEGAL_IP into a local and a non-local version according to whether the IP addresses can be routed outside of the local network. The RCVD_ILLEGAL_IP hits I'm seeing on spam are mostly multicast addresses.