[Rspamd] Fix spoofing detection
This commit is contained in:
parent
1f365f5cff
commit
ba14f0f113
@ -17,6 +17,6 @@ SOGO_CONTACT_SPOOFED {
|
|||||||
expression = "(R_SPF_PERMFAIL | R_SPF_SOFTFAIL | R_SPF_FAIL) & ~SOGO_CONTACT";
|
expression = "(R_SPF_PERMFAIL | R_SPF_SOFTFAIL | R_SPF_FAIL) & ~SOGO_CONTACT";
|
||||||
}
|
}
|
||||||
SPOOFED_UNAUTH {
|
SPOOFED_UNAUTH {
|
||||||
expression = "!MAILCOW_AUTH & !MAILCOW_WHITE & !R_SPF_ALLOW & !DMARC_POLICY_ALLOW & !ARC_ALLOW & !SIEVE_HOST";
|
expression = "!MAILCOW_AUTH & !MAILCOW_WHITE & !R_SPF_ALLOW & !DMARC_POLICY_ALLOW & !ARC_ALLOW & !SIEVE_HOST & MAILCOW_DOMAIN_HEADER_FROM";
|
||||||
score = 5.0;
|
score = 5.0;
|
||||||
}
|
}
|
||||||
|
@ -89,3 +89,10 @@ SIEVE_HOST {
|
|||||||
map = "$LOCAL_CONFDIR/custom/dovecot_trusted.map";
|
map = "$LOCAL_CONFDIR/custom/dovecot_trusted.map";
|
||||||
symbols_set = ["SIEVE_HOST"];
|
symbols_set = ["SIEVE_HOST"];
|
||||||
}
|
}
|
||||||
|
|
||||||
|
MAILCOW_DOMAIN_HEADER_FROM {
|
||||||
|
type = "header";
|
||||||
|
header = "from";
|
||||||
|
filter = "email:domain";
|
||||||
|
map = "redis://DOMAIN_MAP";
|
||||||
|
}
|
||||||
|
Loading…
Reference in New Issue
Block a user