Hi, i'm experiencing a strabge problem using Spamassassassin (2.60).. It recognizes a mail as spam, rewrite message (using the rule from safe_report 1) but adds its header with wrong X-Spam-Status..
Any idea??
Luca
PS:look at message attached
From [EMAIL PROTECTED] Thu Dec 4 18:17:14 2003
X-UIDL: 7Qk"!doR"!_9""!?Ia"!
Received: from localhost [127.0.0.1] by mbox.unict.it
with SpamAssassin (2.60 1.212-2003-09-23-exp);
Thu, 04 Dec 2003 18:17:18 +0100
From: "Marguerite Dunham" <[EMAIL PROTECTED]>
To: xxxxxxxxxxxxxxxxxxxx
Subject: **SPAM** Refill your medication online!k
Date: Thu, 04 Dec 2003 16:18:44 GMT
Message-Id: <[EMAIL PROTECTED]>
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----------=_3FCF6C1E.A1272C11"
X-Spam-Checker-Version: SpamAssassin 2.60 (1.212-2003-09-23-exp) on
mbox.unict.it
X-Spam-Level: *
X-Spam-Status: No, hits=1.5 required=5.0
tests=BAYES_50,BIZ_TLD,CASHCASHCASH,
DNS_FROM_RFCI_DSN,HTML_FONTCOLOR_BLUE,HTML_FONT_BIG,
HTML_FONT_INVISIBLE,HTML_MESSAGE autolearn=no version=2.60
Status: RO
X-Status:
X-Keywords:
X-UID: 29
This is a multi-part message in MIME format.
------------=_3FCF6C1E.A1272C11
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
Questo messaggio � probabilmente SPAM. Il messaggio originale � stato
allegato a questo messaggio, cos� sar� possibile riconoscere o bloccare
messaggi sgraditi in futuro. Per ulteriori informazioni visiti
http:/www.unict.it/cea/istruzioni_spam.htm
This mail is probably spam. The original message has been attached
along with this report, so you can recognize or block similar unwanted
mail in future. See http:/www.unict.it/cea/istruzioni_spam.htm for more
details.
Anteprima contenuto:
Content preview: Don URI:http://halo.medsforcheap.biz/aff1/??*aster
Don't Waste Your Time at the Doctor's Office! RX Medications Delivered
Right to Your Door in 24 Hours! [...]
Dettagli dell'analisi del contenuto:
Content analysis details: (16.0 points, 5.0 required)
0.1 HTML_FONTCOLOR_BLUE BODY: HTML font color is blue
0.1 HTML_MESSAGE BODY: HTML included in message
0.3 HTML_FONT_BIG BODY: HTML has a big font
5.4 BAYES_99 BODY: Bayesian spam probability is 99 to
100%
[score: 1.0000]
0.1 HTML_70_80 BODY: Message is 70% to 80% HTML
0.3 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.6 HTML_FONT_INVISIBLE BODY: HTML font color is same as background
0.1 BIZ_TLD URI: Contains a URL in the BIZ top-level
domain
0.7 RCVD_IN_DSBL RBL: Received via a relay in list.dsbl.org
[<http://dsbl.org/listing?ip=24.46.48.96>]
3.5 RCVD_IN_NJABL_DIALUP RBL: NJABL: dialup sender did non-local SMTP
[24.46.48.96 listed in dnsbl.njabl.org]
1.5 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
[Blocked - see
<http://www.spamcop.net/bl.shtml?24.46.48.96>]
0.1 RCVD_IN_NJABL RBL: Received via a relay in dnsbl.njabl.org
[24.46.48.96 listed in dnsbl.njabl.org]
0.1 RCVD_IN_SORBS RBL: SORBS: sender is listed in SORBS
[24.46.48.96 listed in dnsbl.sorbs.net]
0.3 DNS_FROM_RFCI_DSN RBL: From: sender listed in
dsn.rfc-ignorant.org
1.6 MISSING_MIMEOLE Message has X-MSMail-Priority, but no
X-MimeOLE
1.1 MIME_HTML_ONLY_MULTI Multipart message only has text/html MIME
parts
0.0 CASHCASHCASH Contains at least 3 dollar signs in a row
0.1 MISSING_OUTLOOK_NAME Message looks like Outlook, but isn't
----------SNIP------------
signature.asc
Description: This is a digitally signed message part
