Thank you
Yes we use some of the Declude filters, but not all.
I've set it up to update all the Declude filters daily.
We also use Sniffer and the whole system works pretty well.
We get these from what the log analyzer says are remote senders and sniffer seems to pick them up later. I wanted to stop them as they all are spam and I realize they are getting stopped later in the day, but the additional weight will cause them to be forwarded to the Sniffer pop account sooner.

I'm looking forward to the 32 bit release of Gauntlet in the hope we will be able to reduce these and other early leakers. when we used commtouch with declude, it seemed to pick up some of this sooner. I hope Gauntlet will help.

John



On 12/7/2014 7:18 AM, David Barker wrote:
Are you using any of the Declude filters ? You can find them all here: http://mailsbestfriend.com/downloads/

Here is a PCRE for what you are trying to do.

MAILFROM    10    PCRE    (?i:\.(eu|me|link)$)

David

On 12/6/2014 11:20 AM, John wrote:
I'm getting quite a bit of spam from a sender who's email address ends with a number followed by .link
for example   2.link
there are various numbers and characters prior to the number.
is there a simple way to catch these. I'm guessing PCRE?

thanks
John Doyle



#############################################################
This message is sent to you because you are subscribed to
 the mailing list <[email protected]>.
To unsubscribe, E-mail to: <[email protected]>
To switch to the DIGEST mode, E-mail to <[email protected]> To switch to the INDEX mode, E-mail to <[email protected]>
Send administrative queries to <[email protected]>





#############################################################
This message is sent to you because you are subscribed to
 the mailing list <[email protected]>.
To unsubscribe, E-mail to: <[email protected]>
To switch to the DIGEST mode, E-mail to <[email protected]>
To switch to the INDEX mode, E-mail to <[email protected]>
Send administrative queries to  <[email protected]>

Reply via email to