Hi,
note the following header.
As you can see from the X-Declude headers, it "Failed BADHEADERS, IPNOTINMX"
with a weight of 5 for the bad headers.
It DOES list "China" on the Countrychain.
But, it did not pick up the COUNTRY line from the Weight Filter (last line):
HELO 8 CONTAINS $domain
REMOTEIP 8 IS 218.17.92.184
REVDNS 8 ENDSWITH .are.net
REVDNS 8 ENDSWITH .azogle.com
REVDNS 8 ENDSWITH .consumerinfo.com
REVDNS 8 ENDSWITH .DailyInBox.com
REVDNS 8 ENDSWITH .deliverenetworks.com
REVDNS 8 ENDSWITH .dartmail.net
REVDNS 8 ENDSWITH .emailcourrier.com
REVDNS 8 ENDSWITH .emailoffers.biz
REVDNS 8 ENDSWITH .emailsvc.net
REVDNS 8 ENDSWITH .emipsusa.com
REVDNS 8 ENDSWITH .evaluemail.com
REVDNS 8 ENDSWITH .hispeedmediaoffers.com
REVDNS 8 ENDSWITH .hot-info.net
REVDNS 8 ENDSWITH .IConNet.net
REVDNS 8 ENDSWITH .mail-gw.net
REVDNS 8 ENDSWITH .ramosglobalmarketing.com
REVDNS 8 ENDSWITH .real-net.net
REVDNS 8 ENDSWITH .superstorespecials.com
REVDNS 8 ENDSWITH .temd.net
REVDNS 8 ENDSWITH .truemail.net
REVDNS 8 ENDSWITH .tepmail.com
REVDNS 8 ENDSWITH .webmailer.de
SUBJECT 5 CONTAINS viagra
BODY 3 CONTAINS As seen on
BODY 3 CONTAINS Nigeria
BODY 5 CONTAINS opt-in
COUNTRY 3 CONTAINS cn
Received: from mr3.ash.ops.us.uu.net [198.5.241.88] by hm-software.com with
ESMTP
(SMTPD32-7.07) id A38E9F00154; Mon, 25 Nov 2002 10:36:46 -0500
Received: from ps0.ash.ops.us.uu.net by mr3.ash.ops.us.uu.net with ESMTP
(peer crosschecked as: ps0.ash.ops.us.uu.net [198.5.241.41])
id QQnqne06890
for <[EMAIL PROTECTED]>; Mon, 25 Nov 2002 15:36:46 GMT
Received: from 213.172.81.9 by ps0.ash.ops.us.uu.net with ESMTP
(peer crosschecked as: [61.177.56.178])
id QQnqne17722;
Mon, 25 Nov 2002 15:33:28 GMT
Message-ID: <00005cfe27e8$00001ecf$[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Cc: <[EMAIL PROTECTED]>, <[EMAIL PROTECTED]>, <[EMAIL PROTECTED]>,
<[EMAIL PROTECTED]>, <[EMAIL PROTECTED]>,
<[EMAIL PROTECTED]>, <[EMAIL PROTECTED]>,
<[EMAIL PROTECTED]>, <[EMAIL PROTECTED]>,
<[EMAIL PROTECTED]>, <[EMAIL PROTECTED]>,
<[EMAIL PROTECTED]>, <[EMAIL PROTECTED]>,
<[EMAIL PROTECTED]>, <[EMAIL PROTECTED]>
From: "Daniel" <[EMAIL PROTECTED]>
Subject: I can't reject this7190
Date: Mon, 25 Nov 2002 07:41:04 -2000
MIME-Version: 1.0
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
X-Declude-Note: This E-mail was sent from a broken mail client [8040000f].
See: http://www.declude.com/tools/header.php?code=8040000f
X-Declude: Version 1.62iA; D438e09f00154c6b5.SMD from mr3.ash.ops.us.uu.net
[198.5.241.88]
X-Declude: Failed BADHEADERS, IPNOTINMX [5]
X-Countries: CHINA->UNITED STATES->destination
Return-Path: <[EMAIL PROTECTED]>
X-RCPT-TO: <[EMAIL PROTECTED]>
Status: U
X-UIDL: 337264044
---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
---
This E-mail came from the Declude.JunkMail mailing list. To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.JunkMail". The archives can be found
at http://www.mail-archive.com.