[Rspamd-Users] How can I exclude resolved IPs from the resolved URL RBL queries?

Marcel Menzel mail at mcl.gg
Fri Sep 18 10:43:13 UTC 2026


Hi,

On 18/09/2026 09:59, Winkelmann, Bun-Jan via Users wrote:
> Hello,
> 
> Yesterday, Cloudflare was listed by Spamhaus XBL with the IPv6 address 
> block 2a06:98c1:3120::/64. This caused false positives in our Rspamd 
> junk detection. The address block isn't listed anymore.
> 
> Do you have any suggestions for excluding IP ranges in resolved URL RBL 
> queries?

My current approach for this is to create a type "ip" multimap 
containing IPs or Subnets you'd like to exempt:

   DISABLE_RBL_IP {
       type= "ip";
       map = "${CONFDIR}/custom/disable_rbl_ips.map";
   }

... and then create a new composite rule matching the created multimap 
and the RBL symbol you want to disable / remove the RBM symbol:

   DISABLE_IP_RBL {
     expression = "-DISABLE_RBL_IP & ^RBL_SPAMHAUS_XBL";
   }

It should be also possible to disable / remove a whole symbol group aswell:

   DISABLE_IP_RBL {
     expression = "-DISABLE_RBL_IP & ^g:rbl";
   }

You can read more about this here:
https://docs.rspamd.com/modules/multimap/
https://docs.rspamd.com/configuration/composites/

A note on this: This still causes the RBL to be queried but the result 
being ignored, still counting towards RBL quotas
> Kind regards
> Bun-Jan
> 

     - Marcel
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_0x49235D0D4F8ACED4.asc
Type: application/pgp-keys
Size: 6474 bytes
Desc: OpenPGP public key
URL: <https://lists.rspamd.com/pipermail/users/attachments/20260918/af053358/attachment.bin>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 840 bytes
Desc: OpenPGP digital signature
URL: <https://lists.rspamd.com/pipermail/users/attachments/20260918/af053358/attachment-0001.bin>


More information about the Users mailing list