Standard description: Helo is almost an IP addr.


An untrusted relay used a hostname (FQDN) as a HELO argument during a SMTP transaction that contains a series of numbers that might represent an IPv4 address.

One likely reason for this is that the hostname is taken from the reverse DNS entry used to indicate a dynamically allocated address (see also Rules/HELO_DYNAMIC_DHCP).

