Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Enhancement] Query HELOs, PTRs, and Reply-To's against SURBL and URIBL as well #4141

Merged
merged 1 commit into from
Apr 11, 2022

Conversation

twesterhever
Copy link
Contributor

@twesterhever twesterhever commented Apr 9, 2022

In several environments, querying HELOs, PTRs, and Reply-To's against SURBL and URIBL as well was found to increase the spam detection rates notably, particularly if spam or phishing messages were directly sent from compromised webservers (SURBL seems to have a good coverage of these). No false positives were detected related to this over the period of several weeks.

Also, this will increase the number of DNS queries made per message by 6 at the most (contrary to checks like URL and DKIM, which might pile up to tenths of lookups), so I guess it is not an inappropriate suggestion for rspamds default configuration.

(See also: #4052)

@vstakhov vstakhov merged commit 1405bed into rspamd:master Apr 11, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants