Re: FP on URIBL_JP_SURBL + URIBL_SBL

2006-03-01 Thread Jeff Chan
On Monday, February 27, 2006, 10:27:59 AM, Dave Pooser wrote: > So I noticed some messages from one of my mailing lists landed in the ol' > spambucket; there was a URI in there for 4dquiz-com (dot instead of dash) > and it hit on URIBL_JP_SURBL and URIBL_SBL which scored enough to override > BAYES_

Re: FP on URIBL_JP_SURBL + URIBL_SBL

2006-02-27 Thread Dave Pooser
> OVERALL% SPAM% HAM% S/ORANK SCORE NAME > 22.415 31.8425 0.43700.986 0.491.64 URIBL_SBL > > The S/O is 0.986, which means that 1.4% of messages matching the rule were not > spam. Yep. But in my environment, that's my first-ever case (out of roughly 300,000 message

Re: FP on URIBL_JP_SURBL + URIBL_SBL

2006-02-27 Thread Matt Kettler
Dave Pooser wrote: > True. I'd increased the SBL score because I misunderstood how URIBL_SBL > works; I thought it was flagging sites that were hosted on SBL-listed > addresses, and I trust the SBL far more than other blacklists so I was > willing to score it higher. Lesson to learn: Don't increa

Re: FP on URIBL_JP_SURBL + URIBL_SBL

2006-02-27 Thread List Mail User
"4dquiz-com (dot instead of dash)" is getting DNS service from orderbox-dns_com ('_' instead of '.') - This makes them immediately suspect; Some of the subdomains and servers in that domain are strictly black, others are grey - They have been widely discussed in some non-public forums rece

Re: FP on URIBL_JP_SURBL + URIBL_SBL

2006-02-27 Thread Dave Pooser
> SA doesn't look up the host's IP against SBL.. it looks up the IPs of the > nameservers. Ah. Okay, then, I have been laboring under a misapprehension. > Also, for what it's worth, in SA 3.1.0, URIBL_JP_SURBL + URIBL_SBL + > BAYES_00 is less than 5.0. > > score BAYES_00 0.0001 0.0001 -2.312 -2.

Re: FP on URIBL_JP_SURBL + URIBL_SBL

2006-02-27 Thread Matt Kettler
Dave Pooser wrote: > So I noticed some messages from one of my mailing lists landed in the ol' > spambucket; there was a URI in there for 4dquiz-com (dot instead of dash) > and it hit on URIBL_JP_SURBL and URIBL_SBL which scored enough to override > BAYES_00. Also, for what it's worth, in SA 3.1.0

Re: FP on URIBL_JP_SURBL + URIBL_SBL

2006-02-27 Thread Matt Kettler
Dave Pooser wrote: > So I noticed some messages from one of my mailing lists landed in the ol' > spambucket; there was a URI in there for 4dquiz-com (dot instead of dash) > and it hit on URIBL_JP_SURBL and URIBL_SBL which scored enough to override > BAYES_00. Problem is, as best I can tell it's not