> Headers show that the message come from DSL and cable pools, so IMO it's > from a botnet. X-Greylist header reports that the sender retried only one > time and after 5 minutes and a few seconds. My greylist delay is 5 mn, > so I wonder if this is a coincidence, or if the spam engine reads the > text message in the SMTP reply that says "please come back in 00:05:00". > You may also try removing the polite and helpful "...in 00:05:00" and just say "Greylisting in progress, please come back later...". Or perhaps even remove the word "Greylisting" as well. The more fun & crazy (experimental) way would be to fill the the time in the SMTP message with letters/non-numeric characters, to see how they react to that :-) Hopefully they will crash... (I haven't heard of MTAs that notice the SMTP message and greylisting time printed there...) /P
Message
RE: [milter-greylist] new spam engines
2006-04-04 by fredrik.pettai@vattenfall.com
Attachments
- No local attachments were found for this message.