Tony Finch wrote:
The following headers come from a legitimate message - I have obscured the
sender's name, but that's all. The "SlipStream SP Server" seems to have
appended the client username and IP address to the message-ID, causing the
FP. See also:
http://mail-archives.apache.org/mod_mbox/spamassassin-users/200509.mbox/[EMAIL
PROTECTED]
Yep! That was me! :-)
I investigated with the sender of that message, and since he's a friend,
I could ask him all sorts of questions.
Turned out that he used a dialup connection *and* a "dialup connection
accelerator" offered by the provider itself. I don't know how that [EMAIL PROTECTED]
thing works, but it probably re-routes all IP traffic through a
software-compressed tunnel established between the PC and provider's
servers. Don't know where, Message-IDs are altered, but not by the
client itself.
I tried the same dialup without compression software and everything went
fine.
So, the FORGED rule triggers correctly. Someone deals improperly with
Message-IDs!
Paolo