[Rspamd] Fix spoofing detection
This commit is contained in:
		@@ -17,6 +17,6 @@ SOGO_CONTACT_SPOOFED {
 | 
				
			|||||||
  expression = "(R_SPF_PERMFAIL | R_SPF_SOFTFAIL | R_SPF_FAIL) & ~SOGO_CONTACT";
 | 
					  expression = "(R_SPF_PERMFAIL | R_SPF_SOFTFAIL | R_SPF_FAIL) & ~SOGO_CONTACT";
 | 
				
			||||||
}
 | 
					}
 | 
				
			||||||
SPOOFED_UNAUTH {
 | 
					SPOOFED_UNAUTH {
 | 
				
			||||||
  expression = "!MAILCOW_AUTH & !MAILCOW_WHITE & !R_SPF_ALLOW & !DMARC_POLICY_ALLOW & !ARC_ALLOW & !SIEVE_HOST";
 | 
					  expression = "!MAILCOW_AUTH & !MAILCOW_WHITE & !R_SPF_ALLOW & !DMARC_POLICY_ALLOW & !ARC_ALLOW & !SIEVE_HOST & MAILCOW_DOMAIN_HEADER_FROM";
 | 
				
			||||||
  score = 5.0;
 | 
					  score = 5.0;
 | 
				
			||||||
}
 | 
					}
 | 
				
			||||||
 
 | 
				
			|||||||
@@ -89,3 +89,10 @@ SIEVE_HOST {
 | 
				
			|||||||
  map = "$LOCAL_CONFDIR/custom/dovecot_trusted.map";
 | 
					  map = "$LOCAL_CONFDIR/custom/dovecot_trusted.map";
 | 
				
			||||||
  symbols_set = ["SIEVE_HOST"];
 | 
					  symbols_set = ["SIEVE_HOST"];
 | 
				
			||||||
}
 | 
					}
 | 
				
			||||||
 | 
					
 | 
				
			||||||
 | 
					MAILCOW_DOMAIN_HEADER_FROM { 
 | 
				
			||||||
 | 
					  type = "header";  
 | 
				
			||||||
 | 
					  header = "from";  
 | 
				
			||||||
 | 
					  filter = "email:domain";  
 | 
				
			||||||
 | 
					  map = "redis://DOMAIN_MAP"; 
 | 
				
			||||||
 | 
					}
 | 
				
			||||||
 
 | 
				
			|||||||
		Reference in New Issue
	
	Block a user