Re: Fake paypal email triggers -7.5 USER_IN_DEF_DKIM_WL From: address is in the default DKIM
"Tom Williams via users" <[email protected]>
| Newsgroups | gmane.mail.spam.spamassassin.general |
|---|---|
| Message-ID | <[email protected]> |
Hi! Casual observer here, but I have a question about the headers. On 1/29/25 12:23 AM, Niamh Holding wrote: (snip) > Authentication-Results: spf=softfail (sender IP is 2a01:111:f403:48::209) > smtp.mailfrom=euroland.fr; dkim=pass (signature was verified) > header.d=paypal.com;dmarc=pass action=none header.from=paypal.com; > Received-SPF: SoftFail (protection.outlook.com: domain of transitioning > euroland.fr discourages use of 2a01:111:f403:48::209 as permitted sender) (snip) Why wouldn't the SPF softfail messages not trigger some kind of rule? Especially the "discourages use of" message. Also, I noticed Spamassassin 3.4.6 is being used. Would Spamassassin 4.0 have done a better job at processing these headers? Thanks! Tom