I've been field a number of complaints that spam has been getting worse on our servers using mailscanner. I am running the latest MailScanner etc but looking at the headers I see
0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked.
I think this is causing the SA scores to be low thus letting spam thru. I was using Googles open DNS servers so instead I changed my /etc/resolv.conf to use two local caching DNS servers that should be very low volume and not be blocked. I verified this by testing per the URIBL FAQ:
host -tTXT 2.0.0.127.multi.uribl.com
2.0.0.127.multi.uribl.com descriptive text "permanent testpoint"
This test supposedly confirms that my DNS queries are not blocked but I am still seeing the URIBL_BLOCKED with a value of 0 in the headers even after using my own DNS servers. That being said does SPAMASSASSIN or MS have other DNS servers hard coded somewhere that my be overriding my systems resolv.conf?