On 2/19/19 6:12 PM, Kevin A. McGrail wrote:
Hi All,
Thoughts on how to fix this issue where sendgrid is hitting this rule?
3.2 HELO_DYNAMIC_IPADDR Relay HELO'd using suspicious hostname (IP
addr 1)
Example helo: o168-245-122-130.outbound-mail.sendgrid.net
Specific to sendgrid.net, I have meta rules that subtract a few points
for reputable senders like sendgrid.net.
Generally, I wish there were generic plugins that would allow for a
method to subtract a specified number of points for trusted senders.
This would be something like the def_whitelist_auth and whitelist_auth
entries with the ability to look at Received headers or other unique
headers from the sender.
Let's say example.com sent email from sendgrid.net and DMARC passes
(SPF_PASS and alignment with the envelope-from domain or DKIM_PASS_AU).
I would like to subtract a few points in this case without having to
list every domain in advance in a meta rule or whitelist_auth entry.
Maybe something like this:
whitelist_auth_rcvd sendgrid.net -2.5
whitelist_auth_rcvd authsmtp.net -2.5
whitelist_auth_rcvd authsmtp.com -2.8
whitelist_auth_rcvd dotmailer.com -2.8
whitelist_auth_rcvd mailgun.info -1.8
Similarly, Office 365 is a major source of spam so I have done something
similar for them by meta rules to add a point or two for
.outbound.protection.outlook.com
Then subtract a couple of points for certain X-OriginatorOrg that are
known and trusted.
whitelist_auth_o365 ena.com -3.2 # known to use Duo 2FA
whitelist_auth_o365 ascentis.com -2.2
whitelist_auth_o365 equinix.com -2.5
whitelist_auth_o365 gartner.com -2.8
whitelist_auth_o365 nike.com -2.8
How would one go about writing a custom plugin like this? Does anyone
else think these would be useful?
Another helpful plugin would be something like greylisting for new
Office 365 senders but known X-OriginatorOrg's would be excluded from
greylisting.
Thanks,
Dave
But not hitting any RDNS dynamic rules for the received header
(o168-245-122-130.outbound-mail.sendgrid.net)
Regards,
KAM