Cisco Cisco Email Security Appliance C170 Guía Del Usuario

Descargar
Página de 1094
 
9-35
Cisco AsyncOS 8.0.1 for Email User Guide
 
Chapter 9      Using Message Filters to Enforce Email Policies
  Message Filter Rules
You can also check the verification results against the HELO, MAIL FROM, and PRA identities using 
the following syntax:
The following example shows the 
spf-status
 filter in use:
if (spf-status("pra") == "Fail")
skip-spam-check-for-verified-senders:
     if (sendergroup == "TRUSTED" and spf-status == "Pass"){
         skip-spamcheck();
     }
quarantine-spf-failed-mail:
     if (spf-status("pra") == "Fail") {
         if (spf-status("mailfrom") == "Fail"){
             # completely malicious mail
             quarantine("Policy");
         } else {
           if(spf-status("mailfrom") == "SoftFail") {
             # malicious mail, but tempting
             quarantine("Policy");
           }
         }
     } else {
       if(spf-status("pra") == "SoftFail"){
         if (spf-status("mailfrom") == "Fail"
                 or spf-status("mailfrom") == "SoftFail"){
             # malicious mail, but tempting
             quarantine("Policy");
         }
       }
     }