On 10/10/2011 01:28 PM, [email protected] wrote: > Doing a not nice rule of (RCVD_IN_DNSWL_HI && SPF_FAIL) might be fun, > or putting !SPF_FAIL in the DNSWL rules. Ick... *every* hit for that > is in the dos corpora, so probably not good to add. (Daryl, what did > you do?)
khop-bl has a version of this. Basically, it downplays white-DNSBL hits that fail to match __NOT_SPOOFED (which is to say, it lacks all of: some sort of SPF pass, verified DKIM, last-external relay authentication, or else all relays are trusted). It boosts the negative score of white-DNSBL hits that also hit __NOT_SPOOFED (unless there are already lots of negative points from white-DNSBLs). This prevents overlap issues from combining e.g. DNSWL and HOSTKARMA-White.
signature.asc
Description: OpenPGP digital signature
