Skip to content

New rule (Headers) Mailing list relay with multiple beenthere headers#3884

Closed
IndiaAce wants to merge 3 commits intomainfrom
india.fn.ESC-6767.create_multi_google_group_rule
Closed

New rule (Headers) Mailing list relay with multiple beenthere headers#3884
IndiaAce wants to merge 3 commits intomainfrom
india.fn.ESC-6767.create_multi_google_group_rule

Conversation

@IndiaAce
Copy link
Copy Markdown
Member

Description

This rule detects messages relayed through mailing lists or groups with multiple X-BeenThere headers, indicating potential mailing list abuse or routing manipulation.

Associated samples

Associated hunts

This rule detects messages relayed through mailing lists or groups with multiple X-BeenThere headers, indicating potential mailing list abuse or routing manipulation.
@IndiaAce IndiaAce requested a review from a team as a code owner January 28, 2026 13:08
@github-actions github-actions Bot added the in-test-rules PR is in our testing suite to collect telemetry label Jan 28, 2026
github-actions Bot added a commit that referenced this pull request Jan 28, 2026
Added condition to check if sender's root domain is not in sender domains.
github-actions Bot added a commit that referenced this pull request Jan 28, 2026
github-actions Bot added a commit that referenced this pull request Jan 28, 2026
@IndiaAce
Copy link
Copy Markdown
Member Author

Too many FPs and was just testing this out at a global level. Gonna close it out.

@IndiaAce IndiaAce closed this Jan 30, 2026
github-actions Bot added a commit that referenced this pull request Jan 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant