Backscatter agent - false positive RSS


Testing out the backscatter agent, I've configured it to forward emails to myself rather than rejecting outright. It seems that we've got some false positives happening - as best as I can tell, the recieved bounce does have the correct Message-ID and otherwise looks like a legit bounce. (Other legit bounces are being let through).

Is there anywhere I can send this for futher review?

by Shannon McCracken 8 years ago

Never mind - after looking at them, I realised following the example, I was using a regex of using ".*@internal.local$", but the internal server name was actually in the outgoing emails meaning the real pattern I should be using is ".*@server.internal.local". I just cheated and set it to ".*internal.local$" (removing the @ sign) - which I believe will be reliable enough (real backscatter seems completely alien and this avoids issues if we have a different internal mail server).

by Shannon McCracken 8 years ago

@Shannon McCracken: I'd recommend using


(please note that the dot characters should be "escaped" using backslash, otherwise the dot is interpreted as "any character", so it will match "minternalslocal" as well).

by Krisztian Fekete 8 years ago
(in reply to this post)

New comment

Fill in the form below to add a new comment. All fields are required. If you are a registered user on our site, please sign in first.

Email address (will not be published):
Your comment:

ORF Technical Support

Configuring, installing and troubleshooting ORF.

News & Announcements

Your dose of ORF-related news and announcements.

Everything but ORF

Discuss Exchange and system administration with fellow admins.

Feature Test Program

Feature Test Program discussion. Membership is required to visit this forum.

ORF Beta

Join the great bug hunt of the latest test release.

Customer Service

Stay Informed