*screenshots*? During the day I use a text-only mail client, so I can't
look at them for you until tonight unless you post the text version of the
full message headers. I can't say whether anyone else will bother to look.

> What is the alternate solution to using whitelist_from ?

There are several variants, whitelist_from_rcvd and whitelist_from_spf
being the most useful.

> I been also trying to setup AWL via MySQL.....no luck on
> that.

"AWL" is a misleading name; it is a score averager, not really a whitelist
- it's only a whitelist if someone with a history of sending ham happens
to send a spammy message.

> I use Exim for mail then , it relays to Lotus Domino.....if that helps.

At this point it's not relevant.

> Content analysis details: (5.7 points, 10.0 required)

Ah, good, this may be enough to give useful advice...

> pts rule name description
> ---- ----------------- --------------------------------------------------
> -4.0 RCVD_IN_DNSWL_MED RBL: Sender listed at http://www.dnswl.org/, medium
> trust [ listed in list.dnswl.org]
> 1.0 EXTRA_MPART_TYPE Header has extraneous Content-type:...type= entry
> -0.0 SPF_HELO_PASS SPF: HELO matches SPF record
> 1.8 SUBJ_ALL_CAPS Subject is all capitals
> -0.0 SPF_PASS SPF: sender matches SPF record
> 0.0 HTML_MESSAGE BODY: HTML included in message
> 1.4 SARE_GIF_ATTACH FULL: Email has a inline gif
> 1.5 MY_CID_AND_ARIAL2 SARE CID and Arial2
> 4.0 SARE_FORGED_CITI Message appears to be forged, (citibank.com)

Okay, given that it seems to be a Citibank mail, and SPF passes, you'd
want to use whitelist_from_SPF. See the documentation for the details.

