Richard G
Verified User
Oke I have a spammer with ip 103.198.26.117.
So I added the cidr to the /etc/virtualhost/bad_sender_hosts_ip as followed:
103.198.26.0/24
and reloaded Exim.
But it doesn't seem to get blocked, they use anoter domain on the same ip and this happens:
So it looks as if it send via outlook.com but the helo is clearly the ip mentioned.
Does the bad_sender_hosts_ip not block helo ip's?
Or what's wrong here?
So I added the cidr to the /etc/virtualhost/bad_sender_hosts_ip as followed:
103.198.26.0/24
and reloaded Exim.
But it doesn't seem to get blocked, they use anoter domain on the same ip and this happens:
Code:
2022-10-22 23:54:47 1omMS5-0005rU-0N <= <> H=(e-storefront.co.uk) [103.198.26.117] P=esmtp S=17697 id=CUfDwc2zU3sEZA0FCxnuGkJ8c5dM7t84FwboX7pBGcahlNNs
2QMzbrG7LPQulzH3I00ERdPgJviUpqkV69Od1adzTb52KN7SOSMrE7h7QWMNBMmhb1Slb9yKJpvDg etc. IDSFWEFE.EUR
P193.PROD.OUTLOOK.COM T="Het is de perfecte tijd om te beginnen met Bitcoins" from <> for [email protected]
So it looks as if it send via outlook.com but the helo is clearly the ip mentioned.
Does the bad_sender_hosts_ip not block helo ip's?
Or what's wrong here?