Hi, i'm experiencing a strabge problem using Spamassassassin (2.60).. It recognizes a mail as spam, rewrite message (using the rule from safe_report 1) but adds its header with wrong X-Spam-Status..
Any idea?? Luca PS:look at message attached From [EMAIL PROTECTED] Thu Dec 4 18:17:14 2003 X-UIDL: 7Qk"!doR"!_9""!?Ia"! Received: from localhost [127.0.0.1] by mbox.unict.it with SpamAssassin (2.60 1.212-2003-09-23-exp); Thu, 04 Dec 2003 18:17:18 +0100 From: "Marguerite Dunham" <[EMAIL PROTECTED]> To: xxxxxxxxxxxxxxxxxxxx Subject: **SPAM** Refill your medication online!k Date: Thu, 04 Dec 2003 16:18:44 GMT Message-Id: <[EMAIL PROTECTED]> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----------=_3FCF6C1E.A1272C11" X-Spam-Checker-Version: SpamAssassin 2.60 (1.212-2003-09-23-exp) on mbox.unict.it X-Spam-Level: * X-Spam-Status: No, hits=1.5 required=5.0 tests=BAYES_50,BIZ_TLD,CASHCASHCASH, DNS_FROM_RFCI_DSN,HTML_FONTCOLOR_BLUE,HTML_FONT_BIG, HTML_FONT_INVISIBLE,HTML_MESSAGE autolearn=no version=2.60 Status: RO X-Status: X-Keywords: X-UID: 29 This is a multi-part message in MIME format. ------------=_3FCF6C1E.A1272C11 Content-Type: text/plain Content-Disposition: inline Content-Transfer-Encoding: 8bit Questo messaggio è probabilmente SPAM. Il messaggio originale è stato allegato a questo messaggio, così sarà possibile riconoscere o bloccare messaggi sgraditi in futuro. Per ulteriori informazioni visiti http:/www.unict.it/cea/istruzioni_spam.htm This mail is probably spam. The original message has been attached along with this report, so you can recognize or block similar unwanted mail in future. See http:/www.unict.it/cea/istruzioni_spam.htm for more details. Anteprima contenuto: Content preview: Don URI:http://halo.medsforcheap.biz/aff1/??*aster Don't Waste Your Time at the Doctor's Office! RX Medications Delivered Right to Your Door in 24 Hours! [...] Dettagli dell'analisi del contenuto: Content analysis details: (16.0 points, 5.0 required) 0.1 HTML_FONTCOLOR_BLUE BODY: HTML font color is blue 0.1 HTML_MESSAGE BODY: HTML included in message 0.3 HTML_FONT_BIG BODY: HTML has a big font 5.4 BAYES_99 BODY: Bayesian spam probability is 99 to 100% [score: 1.0000] 0.1 HTML_70_80 BODY: Message is 70% to 80% HTML 0.3 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 0.6 HTML_FONT_INVISIBLE BODY: HTML font color is same as background 0.1 BIZ_TLD URI: Contains a URL in the BIZ top-level domain 0.7 RCVD_IN_DSBL RBL: Received via a relay in list.dsbl.org [<http://dsbl.org/listing?ip=24.46.48.96>] 3.5 RCVD_IN_NJABL_DIALUP RBL: NJABL: dialup sender did non-local SMTP [24.46.48.96 listed in dnsbl.njabl.org] 1.5 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net [Blocked - see <http://www.spamcop.net/bl.shtml?24.46.48.96>] 0.1 RCVD_IN_NJABL RBL: Received via a relay in dnsbl.njabl.org [24.46.48.96 listed in dnsbl.njabl.org] 0.1 RCVD_IN_SORBS RBL: SORBS: sender is listed in SORBS [24.46.48.96 listed in dnsbl.sorbs.net] 0.3 DNS_FROM_RFCI_DSN RBL: From: sender listed in dsn.rfc-ignorant.org 1.6 MISSING_MIMEOLE Message has X-MSMail-Priority, but no X-MimeOLE 1.1 MIME_HTML_ONLY_MULTI Multipart message only has text/html MIME parts 0.0 CASHCASHCASH Contains at least 3 dollar signs in a row 0.1 MISSING_OUTLOOK_NAME Message looks like Outlook, but isn't ----------SNIP------------
signature.asc
Description: This is a digitally signed message part