Strange RCVD_IN_DNSWL_MED problem
I'm seeing a significant increase in spam over the last week. In most cases the difference seems to be RCVDINDNSWL_MED which is a whitelist that applies -2.3 to the spam score. But when I go to http://www.dnswl.org/ and lookup the IP, it claims it's not in the list.
Has anyone else experienced problems with spam like this lately?
Could it be that these IPs are being removed almost immediately as they discover the host has been compermised?
Could it be that list.dnswl.org data is not working or serving stale data?
I cannot help but wonder if a lot of whitelisted servers are suddenly going bad because of heartbleed.
Any ideas?
ioplex