Re: Better whitelisting with DNSWL

2008-07-03 Thread Marc Perkel
Henrik K wrote: On Thu, Jul 03, 2008 at 10:48:07AM +0200, Matus UHLAR - fantomas wrote: On 03.07.08 11:35, Henrik K wrote: I'd like to encourage people to take more advantage of DNSWL. I'm currently converting DNSWL entries into trusted_networks and using shortcircuited ALL_TR

Re: Better whitelisting with DNSWL

2008-07-03 Thread Matthias Leisi
> [snip code + explanation] Very nice :) > It would be nice to see something like this built into SA in the future, > possibly even distributing all the entries daily with sa-update. We can produce almost any export format of dnswl.org data, also in a way that it would fit for some sa-update cha

Re: Better whitelisting with DNSWL

2008-07-03 Thread ram
On Thu, 2008-07-03 at 10:48 +0200, Matus UHLAR - fantomas wrote: > On 03.07.08 11:35, Henrik K wrote: > > I'd like to encourage people to take more advantage of DNSWL. > > while DNSWL('s) may be good, I encountered many cases whan spam and bounces > won't get catched by SA because the sender is i

Re: Better whitelisting with DNSWL

2008-07-03 Thread Henrik K
On Thu, Jul 03, 2008 at 10:48:07AM +0200, Matus UHLAR - fantomas wrote: > On 03.07.08 11:35, Henrik K wrote: > > I'd like to encourage people to take more advantage of DNSWL. > > while DNSWL('s) may be good, I encountered many cases whan spam and bounces > won't get catched by SA because the sende

Re: Better whitelisting with DNSWL

2008-07-03 Thread Matus UHLAR - fantomas
On 03.07.08 11:35, Henrik K wrote: > I'd like to encourage people to take more advantage of DNSWL. while DNSWL('s) may be good, I encountered many cases whan spam and bounces won't get catched by SA because the sender is in DNSQL. > I'm currently converting DNSWL entries into trusted_networks and

Better whitelisting with DNSWL

2008-07-03 Thread Henrik K
Hi, I'd like to encourage people to take more advantage of DNSWL. I'm currently converting DNSWL entries into trusted_networks and using shortcircuited ALL_TRUSTED to reduce unnecessary processing. Also DNS checks are reduced. With only 'med' and 'high' entries, 15% of my traffic hits ALL_TRUST