[Exim] Blocking 'forwarded' spam, a smarter callout?

Top Page
Delete this message
Reply to this message
Author: Bob Tanner
Date:  
To: exim-users
Subject: [Exim] Blocking 'forwarded' spam, a smarter callout?
Recently went sub-domains. In order to keep backward compatibility, we've
setup forwards for the "important" address.

Example, /etc/aliases:

support@???: support@???

Part of the sub-domain move was so I could control the MX hosts for
subdomain.tld.com and not have to depend on the main mail hub for spam
protection.

The problem is now spammers send mail to support@???, they get forwarded
to MX host for subdomain.tld.com, a callout happens, and from what I can see
in the logs, the callout goes to tld.com, which passes.

How can I make subdomain.tld.com do a callout on the sender for the
originating sender, not the forward of tld.com?

--
Bob Tanner <tanner@???>         | Phone : (952)943-8700
http://www.mn-linux.org, Minnesota, Linux | Fax   : (952)943-8500
Key fingerprint = AB15 0BDF BCDE 4369 5B42  1973 7CF1 A709 2CC1 B288