Personal SpamAssassin Spam Score Record Broken.

Holy shit. I wasn’t going to post so soon after yesterday’s but this is insane. I am running SpamAssassin on this server which awards to emails it considers spam based on various criteria. Bearing in mind the default (afaik – mine is anyway) cut off is 6 points, I was somewhat suprised to see a message that scored a whopping 49.8 points in my junk tray – a good five points over my previous record.

Here’s the summary – why the hell did the sender think this would ever get anywhere?


Spam detection software, running on the system "xxxxxxxxxxxxxx", has
identified this incoming email as possible spam.  The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email.  If you have any questions, see the administrator
of that system for details.
Content preview:  email advertise like this to 8,000,000 people... free..
  http://www.advertisingemailcorporation.com/ the above noncommercial
  offer is only for noncommercial charities only. press on charity info on
  our web site for full and complete details. this offer is not a
  commercial service and is not at all for sale or lease or trade of any
  kind. [...]
Content analysis details:   (49.8 points, 6.0 required)
 pts rule name              description
---- ---------------------- --------------------------------------------------
 2.4 MSGID_YAHOO_CAPS       Message-ID has ALLCAPS@yahoo.com
 4.5 MIME_BOUND_DD_DIGITS   Spam tool pattern in MIME boundary
 1.0 NO_REAL_NAME           From: does not include a real name
 1.5 FROM_BLANK_NAME        From: contains empty name
 2.2 HELO_DYNAMIC_SPLIT_IP  Relay HELO'd using suspicious hostname (Split
                            IP)
 4.4 MSGID_SPAM_CAPS        Spam tool Message-Id: (caps variant)
 0.0 UNPARSEABLE_RELAY      Informational: message has unparseable relay lines
 3.5 BAYES_99               BODY: Bayesian spam probability is 99 to 100%
                            [score: 1.0000]
 1.5 RAZOR2_CF_RANGE_E8_51_100 Razor2 gives engine 8 confidence level
                            above 50%
                            [cf: 100]
 1.5 RAZOR2_CF_RANGE_E4_51_100 Razor2 gives engine 4 confidence level
                            above 50%
                            [cf: 100]
 1.0 RAZOR2_CHECK           Listed in Razor2 (http://razor.sf.net/)
 0.5 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
                            [cf: 100]
 2.2 DCC_CHECK              Listed in DCC (http://rhyolite.com/anti-spam/dcc/)
 3.9 RCVD_IN_XBL            RBL: Received via a relay in Spamhaus XBL
                            [83.45.130.42 listed in sbl-xbl.spamhaus.org]
 1.9 RCVD_IN_NJABL_DUL      RBL: NJABL: dialup sender did non-local SMTP
                            [83.45.130.42 listed in combined.njabl.org]
 3.7 RCVD_DOUBLE_IP_SPAM    Bulk email fingerprint (double IP) found
 1.8 MISSING_SUBJECT        Missing Subject: header
 0.8 DIGEST_MULTIPLE        Message hits more than one network digest check
 1.6 MISSING_MIMEOLE        Message has X-MSMail-Priority, but no X-MimeOLE
 2.1 REPTO_QUOTE_YAHOO      Yahoo! doesn't do quoting like this
 3.7 FORGED_MSGID_YAHOO     Message-ID is forged, (yahoo.com)
 4.1 FORGED_MUA_OUTLOOK     Forged mail pretending to be from MS Outlook
The original message was not completely plain text, and may be unsafe to open with
some email clients; in particular, it may contain a virus, or confirm that your address
can receive spam.  If you wish to view it, it may be safer to save it to a file and open
it with an editor.
--
No virus found in this incoming message.
Checked by AVG Free Edition.
Version: 7.5.432 / Virus Database: 268.15.25/593 - Release Date: 19/12/2006 13:17

Tags: , , ,

Leave a Reply