SpamAssassin gets these from the headers and they're easily forged.

My feature would be whitelist only if received from a server which reverse
looks up as being that domain.

Two different mechanisms.

hmm why not:

whitelist_from_rcvd *@ibm.com ibm.com

The second part of the command does not have to be a complete server name.
Just a substring of it. So if any of the mailservers are reported as
(something).ibm.com in the received headers, this will have the same effect
as your "lookup" feature.

>Don't think I'd be able to find what servers they send out all their mail
>Possible feature:
>Whitelisting based on reverse name lookups.
>If the email was sent from a server that reverse looks up as domain then
>From: *@ibm.com lookup
>lookup as an additional parameter to yes no.
