From: Karsten Bräckelmann <guenther_at_nospam>
Date: Tue Oct 12 2010 - 22:40:42 GMT

On Wed, 2010-10-13 at 11:16 +1300, Peter Lowish wrote:
> How are RCVD_IN_* rules implemented Karsten?

They are generally DNS BL checks, some of which do (and are safe for)
deep header parsing. Most of them are checked against the handing-over
relay's IP only, though.

They are enabled (by default) by the skip_rbl_checks option, set to 0.
If they have not been disabled deliberately or erroneously, missing of
such rule hits indicates a DNS problem. (If you are using your ISPs DNS
directly or as a forwarder, a local caching non-forwarding DNS usually
solves it.)

Of course, your trusted and internal networks must be correct. SA is
good at guessing them in most cases, but a more complicate setup might
need tweaking.

I mentioned it specifically, because you stated the reported IPs to send
a lot of spam. Thus, they are most likely to be listed with some of the

Can't say more, because you didn't include any information regarding
your environment.

> I have similar spam being sent from such addresses as
> and I don’t see that rule in the
> matching rules

The sender frequently is forged, or registered for abusive purposes with
a freemail provider. The left-hand part after the dot looks suspiciously
like a forgery.

Anyway, the sender address is irrelevant in the context of relay IP
checks. Like the submitting host's IP, as you mentioned.

What I am missing is an answer to my question, if you are seeing *ANY*
of such rule hits -- and if so, which, and how frequently.

> Running mailwatch for mailscanner with spamassassin

