On 10 Feb 2021, at 14:41, Eugene Podshivalov wrote:

Hello,

I've just received a spam email from a client who presented itself as
emx.mail.ru but its ip 117.30.137.22 resolves to
22.137.30.117.broad.xm.fj.dynamic.163data.com.cn

 Are reverse client hostname and the ehlo one not supposed to match?

In principle, yes. In reality, they very often do not, even with entirely legitimate email.


--
Bill Cole
b...@scconsult.com or billc...@apache.org
(AKA @grumpybozo and many *@billmail.scconsult.com addresses)
Not Currently Available For Hire

Reply via email to