On 01/09/12 2:39 PM, m.roth@5-cent.us wrote:
I've argued before that blocks should be by source - actual source, the oldest "Received-From", not from the last mailer.
Those are far too easily forged, and in fact a majority of spam has forged Recieved headers, you can only trust the one YOUR mail server puts on or a chain from the latest back as far as you see trusted servers. Also, by the time you've read the header, its too late to reject the connection.