On Wednesday, March 9, 2005, 7:50:13 AM, Rikhardur EGILSSON wrote: > Can anyone explain to me what the URIBL_SBL rule does (I.e. which list Is > used)
RTFM? uridnsbl checks a URI domain's nameserver against sbl.spamhaus.org. > I have an email that this rule catches because of a email address inside it. > The SpamAssassin report lists it as : > 0.6 URIBL_SBL Contains an URL listed in the SBL blocklist > [URIs: gov.ru] > But no matter what I try, I canīt find the blacklist that Is used. What this means is that the nameserver for gov.ru is listed in SBL. http://www.spamhaus.org/sbl/sbl.lasso?query=SBL13545 > Ref: SBL13545 > > 213.59.0.0/23 is listed on the Spamhaus Block List (SBL) > > 26-Feb-2005 02:47 GMT | SR01 > > Ruslan Ibragimov / send-safe.com > 213.59.0.0/23 is listed on the Register Of Known Spam > Operations (ROKSO) database as being assigned to, under the > control of, or providing service to a known professional spam > operation run by Ruslan Ibragimov / send-safe.com. > Rostelecom Corporate Mail Relays (escalation) It looks like Spamhaus has listed all of Rostelecom since it hosts send-safe.com. Personally I don't like escalations like that, but I don't run Spamhaus. Fortunately URIBL_SBL usually gets a fairly low score due to false positives like this. I'd say keep it low. Jeff C. -- Jeff Chan mailto:[EMAIL PROTECTED] http://www.surbl.org/