I ask because I get a lot of these type headers that are being flagged by the VALFROM. I only have the mailfrom option checked.
Chris


X-Persona: <xAbuse>
Received: from broadcast.cybergolf.com [216.162.206.160] by peake.com with ESMTP
(SMTPD32-8.03) id A8331A60106; Wed, 24 Sep 2003 13:45:23 -0400
Received: from localhost.localdomain (broadcast.cybergolf.com [127.0.0.1])
by broadcast.cybergolf.com (8.11.6/8.11.6) with SMTP id h8OHVQs19042
for <[EMAIL PROTECTED]>; Wed, 24 Sep 2003 10:31:26 -0700
Received: from root
by localhost.localdomain with local (phpmailer);
Wed, 24 Sep 2003 10:31:26 -0700
Date: Wed, 24 Sep 2003 10:31:26 -0700
To: "[EMAIL PROTECTED]" <[EMAIL PROTECTED]>
From: Renditions <[EMAIL PROTECTED]>
Reply-to: Renditions <[EMAIL PROTECTED]>
Subject: Golf Specials
Message-ID: <[EMAIL PROTECTED]>
X-Priority: 3
X-Mailer: phpmailer [version 1.65]
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/html; charset="iso-8859-1"
X-IMAIL-SPAM-VALFROM: (27656454)
X-RCPT-TO: <[EMAIL PROTECTED]>
Status: U
X-IMail-Rule: H~X-IMAIL-SPAM:[EMAIL PROTECTED] Data- X-IMAIL-SPAM-VALFROM: (2765645



At 12:04 PM 09/24/2003 -0400, you wrote:


Which of these AS features have the least false positives?

Verify Mail From

A MAILFROM test will never have false positives, except when a mail client is set up incorrectly (in a way that the sender will never receive bounce messages, and probably never even receive replies).


Perform DNS Lookup for connecting server

For a reverse DNS test, we've seen rates ranging from about 10% to 25% of legitimate mailservers having no reverse DNS entry.


Verify HELO/EHLO Domain

In theory, this should never have any false positives. However, most mail clients will send bogus HELO/EHLO information (such as "hostname" or "localhost"). So this must be used carefully.


We recommend that our customers not block on any of these, but use them in a weighting system (with MAILFROM weighted very high, and REVDNS/HELOBOGUS weighted fairly low).

-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask about our free 30-day evaluation.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]



To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ --- [This E-mail scanned for viruses by Declude/F-Prot AV]


--- [This E-mail scanned for viruses by Declude/F-Prot AV]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to