Evaluate UTF-8 From / Subject

2024-07-18 Thread Nikolaos Milas
Hello, Is there a way we can search for strings in UTF-8 encoded From and/or Subject headers? For example, here is part of a phishing mail header: ... From: =?utf-8?B?Is6VzpjOnc6ZzprOlyDOpM6hzpHOoM6VzpbOkSI=?=   To: exam...@example.com Message-id: <9d6ceda2599640f6....@amtelecom.net> Date

Re: Understanding FORGED_GMAIL_RCVD and other rules

2022-06-28 Thread Nikolaos Milas
On 22/6/2022 1:53 μ.μ., Greg Troxel wrote: ... I suspect your real problem is that there is config to increase the score for FORGED_GMAIL_RCVD. Your example shows 4.0 which I think everyone would say is too high. ... Hi Greg and Marc, who were both prompt to help! Sorry for my delayed feedba

Understanding FORGED_GMAIL_RCVD and other rules

2022-06-22 Thread Nikolaos Milas
Hello, There is one mailchimp user (an org sending mail news by leveraging mailchimp services), whose mails are flagged by our mail gateway servers (postfix with amavis and spamassassin) with "FORGED_GMAIL_RCVD". I am trying to understand what is wrong with these mails and they trigger the "