Here are a couple of rules I am using to catch spam from em5000.net, a so-called "legitimate" email service that nonetheless sends me nothing but spam. They've been VERY active lately - these rules would have caught literally 2/3 of my spam that SpamAssassin has missed in the last two weeks.
I'm not sure if this belongs in the distribution since a single spam source never seems to last too long... header BIGOFFERS From =~ /(?:bigoffers|hotoffers)/i describe BIGOFFERS RealBigOffers - frequent spammer score BIGOFFERS 5.0 uri EM5000 /em5000\.net/i describe EM5000 em5000.net:Frequent SPAM content score EM5000 4.0 -- michael moncur mgm at starlingtech.com http://www.starlingtech.com/ "My theory of evolution is that Darwin was adopted." -- Steven Wright _______________________________________________ Spamassassin-talk mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/spamassassin-talk