Hi everyone!
We have 4 PMG nodes running in cluster, and i have added the following regex entries, but without success, on the logs i see the e-mail messages getting blocked by DNSBL and not by regex rules at the blacklist on Who Objects:

Our rules is configured this way:

Is my regex syntax wrong or may be the mail filter rules?
The point is that we received a bunch of thousands SPAM e-mail s coming from this .sbs domain for instance, and is being processed and getting blocked by DNSBL's in our PMG's, the server loads are going insane with many process of pmg-smtp-filter as screenshot below:

I need to get the blacklist by regex working to block some .tlds we need to block, this way, we can stop the spammers from this Tlds at the connection time, drop the transaction before, saving resources of hardware.
Any tip is very welcome!
Thank you all in advance!
We have 4 PMG nodes running in cluster, and i have added the following regex entries, but without success, on the logs i see the e-mail messages getting blocked by DNSBL and not by regex rules at the blacklist on Who Objects:

Our rules is configured this way:

Is my regex syntax wrong or may be the mail filter rules?
The point is that we received a bunch of thousands SPAM e-mail s coming from this .sbs domain for instance, and is being processed and getting blocked by DNSBL's in our PMG's, the server loads are going insane with many process of pmg-smtp-filter as screenshot below:

I need to get the blacklist by regex working to block some .tlds we need to block, this way, we can stop the spammers from this Tlds at the connection time, drop the transaction before, saving resources of hardware.
Any tip is very welcome!
Thank you all in advance!