FYI I received another mail from the same list and it doesn't look
like the
problem has been solved (updated KAM to check)
Different problem but a good example. Thanks. KAM Ruleset is updated
to handle it and appreciate you posting about it.
these two are somehow redundant.
uri __KAM_SOMETLD_ARE_BAD_TLD_URI
/:\/{2}([a-z0-9-\.]+)\.(pw|stream|trade|press|top|date|guru|casa|online|cam|shop|club|bar)($|\/|\:)/i
header PDS_OTHER_BAD_TLD eval:check_uri_host_listed('SUSP_URI_NTLD')
They do have overlap but both have good purposes. I use them in concert
with live mail and handle FPs/FNs based on that so the overlap is
considered with the scoring and impact.
Regards,
KAM
--
Kevin A. McGrail
kmcgr...@apache.org
Member, Apache Software Foundation
Chair Emeritus Apache SpamAssassin Project
https://www.linkedin.com/in/kmcgrail - 703.798.0171