Have you looked into "Day old bread"?  
http://wiki.apache.org/spamassassin/Rules/URIBL_RHS_DOB

 ...Kevin
--
Kevin Miller
Network/email Administrator, CBJ MIS Dept.
155 South Seward Street
Juneau, Alaska 99801
Phone: (907) 586-0242, Fax: (907) 586-4500
Registered Linux User No: 307357
-----Original Message-----
From: James B. Byrne [mailto:byrn...@harte-lyne.ca] 
Sent: Wednesday, May 14, 2014 8:52 AM
To: users@spamassassin.apache.org
Subject: SPAM from a registrar

This AM we received (and are continuing to receive) numerous spam messages from 
multiple domains that were all registered today (2014-05-14) with a company 
called enom, inc.  This firm is also the registrar for the the mail server 
domain BOSJAW.com that is ending some if not all of the UCEM.  That server is 
hosted in CZ.

It seems likely that this is a planned UCEM campaign designed to use disposable 
domains, probably registered with stolen credit cards or some other form of 
fraud, in order to escape blacklisting services.  No doubt by tomorrow they 
will be abandoned.

Is there any test to check how long a domain name has been in existence and set 
a spam score with that information?

Along the same lines, is there any test to determine the country of origin of 
the IP address in the last hop before it connects to our servers?


-- 
***          E-Mail is NOT a SECURE channel          ***
James B. Byrne                mailto:byrn...@harte-lyne.ca
Harte & Lyne Limited          http://www.harte-lyne.ca
9 Brockley Drive              vox: +1 905 561 1241
Hamilton, Ontario             fax: +1 905 561 0757
Canada  L8E 3C3

Reply via email to