I sporadically get multipart/alternative email where the first (text)
part consists only of a one- or two-sentence warning that the content
"can only be viewed in HTML."  I have never seen a non-spam message that 
matches this description.

body VIEWED_ONLY_IN_HTML        /This \w+ can only be \w+ in HTML/i
describe VIEWED_ONLY_IN_HTML    Text part says you must view the HTML part
score VIEWED_ONLY_IN_HTML       1.5

The most recent example also included in the HTML part a "click here" link
which for some reason did not trigger the CLICK_HERE_LINK rule.  Could
this be because the HTML part had "Content-Transfer-Encoding: binary"?
In general, how does one check why a rule did NOT match?

Spamassassin-talk mailing list

Reply via email to