On 20/02/11 11:31 -0500, dar...@chaosreigns.com wrote: > I'm a DNSWL admin. I would like to see full examples (well, headers).
I sent you and Matthias some headers to look at. > What IP addresses are being looked up in DNSWL? > > It's possible you don't have trusted_networks and internal_networks > configured correctly, resulting in looking up an IP address belonging to > your ISP or another mail server which you have configured to relay mail to > you. They are not set at all so this really could be a problem in my configuration, particularly because a lot of my mails come thru iki.fi's mail services. > Also, I see your threshold (6.31) is set higher than the default (5), and > at the default the two examples you provided would have been classified > correctly. Although I understand you may not wish to lower your threshold. > Interesting problem though. I think it's actually the Ubuntu default. I really don't have a problem lowering the threshold and, in fact, I will probably do that soon. Like I said, I just redid our mail setup entirely when we moved to new hardware, so I figured I'll monitor the spam patterns we see for a while and then fine tune the rules. - Pasi