Hello folks,

To facilitate process automation in larger email systems we have developed a coding scheme and a number of standardized response codes for handling false positive submissions. This will allow you to route our responses to your false positive submissions automatically.

I have attached the file StdFalse.txt which contains the current list of standard responses from our process and a legend for creating new response codes.

We have been working on this project for a while now and the list is fairly stable. However, we are constantly developing and refining our processes so these responses are likely to change from time to time.

Thanks!
_M
[FPR:0]

The message did not match any active black rules as submitted. The rules
may have been modified or removed. If you provide matching log entries
from your system then we can research this further.

Note that sometimes our false processing system may not identify the
rules that matched this message on your system due to changes in the
submitted content that might occur during the forwarding process.

Please also be sure you are running the latest version, that your
rulebase file is up to date, and that you do not have any unresolved
errors in your Sniffer log file. Bug fixes in newer versions may resolve
false positive issues or reduce the risk of false positives through
enhanced features and new technologies. Certain errors in your log file
may indicate a corrupted rulebase.

Note that sometimes our false processing system may not identify the
rules that matched this message on your system due to changes in the
submitted content that might occur during the forwarding process.

-----------------------------------------------------------------------
[FPR:X]

This is an experimental ip rule. These rules are generated from our
spamtraps and removed on the first false positive report. These rules
generally indicate compromized equipment at the IP specified.

The rule has been removed.

-----------------------------------------------------------------------
[FPR:GR]

Rules in group 60 are gray hosting rules. Gray hosting rules are coded
for email sources that transmit both spam and non-spam. The Gray hosting
rule group is coded with a block-first / white-rule-later strategy.
You may wish to weight this rule group differently on your system. You
may also block this group or any of it's rules.

Would you like to add a white rule based on the following?

-----------------------------------------------------------------------
[FPR:GW]

Rules in group 60 are gray hosting rules. Gray hosting rules are coded
for email sources that transmit both spam and non-spam. The Gray hosting
rule group is coded with a block-first / white-rule-later strategy.
You may wish to weight this rule group differently on your system. You
may also block this group or any of it's rules.

A core white rule has been added based on your submission.

-----------------------------------------------------------------------
[FPR:HA]

This rule is coded for a potentially dangerous coding that references
the local file system of the recipient. This is often found in broken
spam and possibly malware.

Would you like to block this rule?

Would you like to add a white rule (please specify source)?

-----------------------------------------------------------------------
[FPR:SN]

The rule is strong.

Would you like to block this rule?

Note:

-----------------------------------------------------------------------
[FPR:SR]

The rule is strong.

Would you like to block this rule?

Would you like to add a white rule based on the following?

-----------------------------------------------------------------------
[FPR:SA]

The rule is strong.

Would you like to block this rule?

Would you like to add a white rule (please specify source)?

-----------------------------------------------------------------------
[FPR:+SR]

These rules are strong.

Would you like to block one or more of these rules (please specify)?

Would you like to add a white rule based on the following?

-----------------------------------------------------------------------
[FPR:+SA]

These rules are strong.

Would you like to block one or more of these rules (please specify)?

Would you like to add a white rule (please specify source)?

-----------------------------------------------------------------------
[FPR:D]

The rule has already been removed.

-----------------------------------------------------------------------
[FPR:P]

This case will be handled by the resolution of a prior - nearly 
identical submission.

-----------------------------------------------------------------------
[FPR:N]

Notes / Response to your notes:

-----------------------------------------------------------------------
[FPR:C]

Your rulebase has been modified as requested.

-----------------------------------------------------------------------
[FPR:U]

Please submit false positives from a registered email address or
authorized alias.

-----------------------------------------------------------------------

Response code legend:

0 - No matches
S - Strong rule
+ - Multiple rules (Modifier use as +S)
R - Recommending a white rule
A - Asking for a white rule recommendation
P - Pending a prior submission
N - Notes/Response to notes
H - Potentially hazardous
D - Already done
G - Gray rules
E - Rule(s) eliminated
M - Rule(s) modified
W - White rule(s) were added to core
C - Complied with your request
U - Unidentified submitter

Reply via email to