Antispam MxGuard Business Product information New

Connection-level defences: DNSBLs, postscreen and rate limiting

Transcom 31 Aug 2025, 17:23

A large share of junk is stopped before MxGuard even reads the message, at the connection and envelope stages. This is the cheapest and most effective place to block obvious abuse.

Postscreen and DNSBLs. At connection time, six DNS blocklists (including Spamhaus, SORBS and Mailspike) are queried in parallel. Reaching a threshold of three hits blocks the connection outright. Conversely, the DNSWL trusted-sender list (list.dnswl.org) lets known-good senders bypass heavier checks.

Rate limiting. Each sending source is held to 30 connections per minute, 60 messages per minute and 100 recipients per message. This throttles bulk abuse and snowshoe campaigns without affecting normal correspondents.

SPF at the envelope. SPF is validated via policyd-spf before the body is accepted, so forged envelope senders are caught early.

Because these checks run first, the expensive AI scoring layers only ever see mail that has already survived the coarse filters — which keeps the whole system fast.

0 comments

Sign in with your TDesk account to comment.

← Back to all posts