On 10/10/2011 01:28 PM, [email protected] wrote:
> Doing a not nice rule of (RCVD_IN_DNSWL_HI && SPF_FAIL) might be fun,
> or putting !SPF_FAIL in the DNSWL rules.  Ick... *every* hit for that
> is in the dos corpora, so probably not good to add.  (Daryl, what did
> you do?)

khop-bl has a version of this.  Basically, it downplays white-DNSBL hits
that fail to match __NOT_SPOOFED (which is to say, it lacks all of: some
sort of SPF pass, verified DKIM, last-external relay authentication, or
else all relays are trusted).  It boosts the negative score of
white-DNSBL hits that also hit __NOT_SPOOFED (unless there are already
lots of negative points from white-DNSBLs).  This prevents overlap
issues from combining e.g. DNSWL and HOSTKARMA-White.

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to