>>The way that it should work is it should take the HELO/EHLO domain from the
>>SMTP envelope (you can find it in the top Received: header), and check to
>>make sure that it has an MX or A record. That's all.
So if the MX and/or A records exist for that domain, and it still gets marked as X-IMAIL-SPAM-VALHELO that would perhaps indicate some problem with the DNS lookup which I mail is performing...?
Correct (unless Ipswitch's version of the test is doing something unusual).
Of two examples which I see this AM... One from a AOL user, and one from a user on one of our domains faberinc.com which both have MX and A records.
Ah, but it doesn't necessarily look up aol.com for an E-mail from [EMAIL PROTECTED], and it won't necessarily look up faberinc.com for an E-mail from [EMAIL PROTECTED] The *only* domain that matters is the one in the top Received: header (the one that IMail adds).
For AOL, you would likely see something like "Received: from mx22.mailer.aol.com" -- in this case, the domain used for the HELO/EHLO lookup would be mx22.mailer.aol.com. That's the one that is required to be a valid domain (but the RFCs technically require that you *not* block E-mail just because the HELO/EHLO doesn't resolve...).
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers.
Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask about our free 30-day evaluation.
--- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
