it Possible create Rule Snort for Check BlackList email (RBL)

  • Is it possible to create a snort rule related to the check of black mailing lists? Something similar in postfix when we use check_rbl.

    Thank you.

  • You can create your own IP Blacklist file and apply it using the IP REP tab in Snort. Information on creating blacklist and whitelist IP files can be found in the Snort online documentation here. Snort will block when a packet contains an IP address listed in the blacklist file.