[Enhancement] Query HELOs, PTRs, and Reply-To's against SURBL and URIBL as well #4141
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
In several environments, querying HELOs, PTRs, and Reply-To's against SURBL and URIBL as well was found to increase the spam detection rates notably, particularly if spam or phishing messages were directly sent from compromised webservers (SURBL seems to have a good coverage of these). No false positives were detected related to this over the period of several weeks.
Also, this will increase the number of DNS queries made per message by 6 at the most (contrary to checks like URL and DKIM, which might pile up to tenths of lookups), so I guess it is not an inappropriate suggestion for
rspamd
s default configuration.(See also: #4052)