This definitely sounds like the right track.  Thanks.

Basically, I'm checking the name of the box that relayed using the received header.

So if the user confirms/changes trusted_networks and internal_networks settings to reflect their network and then I change the rule to check X-Spam-Relays-Untrusted instead of Received, we would essentially bypass their internal/trusted network relays for the test.

Correct?

Regards,
KAM



I think you can do this with the X-Spam-Relays-* headers. would that work?

On Thu, Feb 5, 2009 at 20:15, Kevin A. McGrail <[email protected]> wrote:
I've been looking at some rules and discussing a FP with a user that would
benefit greatly from ignoring the most recent received header.  Is there
currently a way to do this or would a new ruletype be the best way to
achieve this?

Reply via email to