This is what I was seeing a couple of weeks ago when I posted the question about blocking messages that had spoofed email addresses in our domains. I still haven't figured out a good way to handle this in the case where we have dozens of virtual domains connecting from variable sources.

Can you share your code for filter relay based on HELO?

How much legit mail will that end up rejecting? I see a lot of systems where they may say HELO xyz.com and it really be from xyz.com, but the hostname would be some ISP reverse DNS hostname, such as z.y.x.w.qrst.com and the IP be w.x.y.z -- how would your filter handle this?


