Re: [exim] Spam with IP like HELO

2009-03-06 Thread Todd Lyons
On Tue, Feb 24, 2009 at 7:30 PM, Gregg Lain wrote: > drop >   condition  = ${if and {{match {$sender_helo_name}{\N^\[(.+)\]$\N}}{isip4 > {$1}}}{true}{false}} >   message     = Access denied - IP based HELO not allowed. (violates RFC2821 > 4.1.3) Also note that if you're going to run this in produ

[exim] Spam with IP like HELO

2009-02-24 Thread Gregg Lain
Thanks for posting this - I read about in fact breaking the RFC and blocking anyone that uses an IP for a HELO at junkemailfilter.com and like it. I do outgoing email for a client and comcast blocked me because my reverse was not set-up - migrated servers.. (fixed now)... So with that big of

Re: [exim] Spam with IP like HELO

2007-05-03 Thread Kjetil Torgrim Homme
On Thu, 2007-05-03 at 23:32 +0200, Renaud Allard wrote: > As mentioned the spammers will have the right literal HELO because its > their interest. many spammers have no clue at all, viz. "HELO friend". > I think this is just like IP literals for receiving > mails, it is mainly used for abuse. we

Re: [exim] Spam with IP like HELO

2007-05-03 Thread Renaud Allard
Kjetil Torgrim Homme wrote: > On Thu, 2007-05-03 at 00:46 +0200, Renaud Allard wrote: >> I am receiving a bunch of stock spams (mostly in german). Their common >> property seems to be a helo like [ip.add.re.ss]. >> I am thinking about an ACL like this one: >> warn >> condition

Re: [exim] Spam with IP like HELO

2007-05-02 Thread Ted Cooper
Kjetil Torgrim Homme wrote: > On Thu, 2007-05-03 at 10:29 +1000, Ted Cooper wrote: >> Exim has a function to figure out if something is an IP address without >> all the regex >> >> # Deny RAW IP addresses - they MUST be quoted to comply with standards >> denymessage = ERRMSG_RAWIP1 >>

Re: [exim] Spam with IP like HELO

2007-05-02 Thread Kjetil Torgrim Homme
On Thu, 2007-05-03 at 10:29 +1000, Ted Cooper wrote: > Exim has a function to figure out if something is an IP address without > all the regex > > # Deny RAW IP addresses - they MUST be quoted to comply with standards > denymessage = ERRMSG_RAWIP1 > condition = > ${look

Re: [exim] Spam with IP like HELO

2007-05-02 Thread Bryan Rawlins
Kjetil Torgrim Homme wrote: > On Thu, 2007-05-03 at 00:46 +0200, Renaud Allard wrote: >> I am receiving a bunch of stock spams (mostly in german). Their common >> property seems to be a helo like [ip.add.re.ss]. >> I am thinking about an ACL like this one: >> warn >> condition

Re: [exim] Spam with IP like HELO

2007-05-02 Thread Bryan Rawlins
Renaud Allard wrote: > I am receiving a bunch of stock spams (mostly in german). Their common > property seems to be a helo like [ip.add.re.ss]. > I am thinking about an ACL like this one: > warn > condition = ${if > match{$sender_helo_name}{\N(25[0-5]|2[0-4][0-9]|[01]?[0-9][0

Re: [exim] Spam with IP like HELO

2007-05-02 Thread Ted Cooper
Renaud Allard wrote: > Hi, > > I am receiving a bunch of stock spams (mostly in german). Their common > property seems to be a helo like [ip.add.re.ss]. > I am thinking about an ACL like this one: > warn > condition = ${if > match{$sender_helo_name}{\N(25[0-5]|2[0-4][0-9]|[01

Re: [exim] Spam with IP like HELO

2007-05-02 Thread Kjetil Torgrim Homme
On Thu, 2007-05-03 at 00:46 +0200, Renaud Allard wrote: > I am receiving a bunch of stock spams (mostly in german). Their common > property seems to be a helo like [ip.add.re.ss]. > I am thinking about an ACL like this one: > warn > condition = ${if > match{$sender_helo_name}{

[exim] Spam with IP like HELO

2007-05-02 Thread Renaud Allard
Hi, I am receiving a bunch of stock spams (mostly in german). Their common property seems to be a helo like [ip.add.re.ss]. I am thinking about an ACL like this one: warn condition = ${if match{$sender_helo_name}{\N(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|