Page 1 of 1

Score by RDNS TLD

Posted: 10 Dec 2021 08:25
by BOOZy
I'd like to propose the option to add a spam score base on the Top Level Domain of de reverse-DNS of the sender.

Lately more and more spam (and phishing) seems to arriving from non-botnet spammers who go through the effort of setting up servers with functional but disposable reverse-DNS records, eluding higher spam scores.

For example: host01.leadorrin.club [103.136.40.58], radlionay.xyz [185.53.170.106], etc.
Especially the .xyz TLDs seems to be very popular lately.

I'd like to have the option to add say 5 points to the score if the RDNS TLD matches .xyz or other specified TLDs.

Re: Score by RDNS TLD

Posted: 14 Dec 2021 10:47
by DeRaptor

Re: Score by RDNS TLD

Posted: 16 Dec 2021 10:15
by BOOZy
Both posts describe adding filters based on the 'from' email address, not the TLD of the sender's reverse-DNS.

Writing your own rules is nice if you have the time, skill and documentation needed available to you.
I'd love to spend the next two weeks acquiring those but I gather my boss won't be too happy.

Re: Score by RDNS TLD

Posted: 17 Dec 2021 08:01
by DeRaptor
Aha, okay.

You will add a score, if the RDNS check points to a unwanted domain like .xyz ?

Re: Score by RDNS TLD

Posted: 17 Dec 2021 13:13
by BOOZy
That's the idea.

I'm not sure of spamassasin does anything with reverse-DNS other than to check if one exists.