Mark Little wrote:
> Recently I have seen an influx of SPAM including a fake Received: from
> header (not something new), but what is strange is the IP included is the
> hosts actual IP address and not a fake one.
> (Examples below)
>
> So I have been trying to work out how to add an ACL to be able to scan for
> this - because as far as I am concerned I should never be receiving an
> email from an IP address that includes "Received: from [<same IP>]".
Don't! There are legitimate reasons for such headers.
--
B. Johannessen <bob@???> - GSM: +4797152009
Johannessen Design Bureau -
http://www.db.org/