On Thu, Aug 11, 2005 at 03:31:57AM -0700, Jeff Chan wrote: > > the IP > > 219 dot 144 dot 194 dot 158 > > is shown as listed by http://www.rulesemporium.com/cgi-bin/uribl.cgi - a > > phishing mail with > > http://219dot144dot194dot158:8081/secure.dresdner-privat.de/fb/privat/login/login.htm > > in it's body does not trigger any uribl rules tho. Why is that so? > > What happens if you give the message to SpamAssassin in debug > mode:
Unless I'm missing something obvious, the URIBL plugin doesn't check IPs, only domains. (At least I don't see where it differentiates and checks IPs.) -- Randomly Generated Tagline: I'll give you a definite maybe.
pgpImOXITUeWd.pgp
Description: PGP signature