On 7/20/2013 1:35 AM, Andrea wrote:
Hi all.

Since a few days ago I'm being buried under spam messages that slip through my amavis/SA setup.
The messages all look alike: plaintext with random junk + URL in the body.
Pastebin with a few examples here: http://g2z.me/ed64d

I've tried running a sa-update but I don't have enough samples (yet). The thing that bothers me is that all the messages have been classified as HAM by the auto learn (which I have now disabled).
What could be an effective rule/ruleset to block emails like this?

I assume you meant to say "sa-learn" rather than "sa-update"?

The main problem that I see with the scoring is that it is hitting on BAYES_00. This may have been caused by auto-learn. You need to manually learn these as spam using sa-learn to couteract that.

--
Bowie

Reply via email to