Scott-After reading your e-mail recommending that you can hold on bad headers I tripled the weight. Although I really don't care much that this was held right now if virus did really come through my server I would like to get this. Any idea why a Webshield Alert would fail BADHEADERS? (if that is where this is really from...)
Received: from ASSENTOR4.corp.isib.net [199.250.13.98] by mail.prudentialrand.com with ESMTP (SMTPD32-7.15) id A5AE450008A; Tue, 26 Aug 2003 17:48:30 -0400 Received: from MSMP2.corp.isib.net (unverified) by ASSENTOR4.corp.isib.net (Content Technologies SMTPRS 4.2.10) with ESMTP id <[EMAIL PROTECTED]> for <[EMAIL PROTECTED]>; Tue, 26 Aug 2003 16:48:11 -0500 Received: from SMTPAV2.corp.isib.net (unverified) by MSMP2.corp.isib.net (Content Technologies SMTPRS 4.2.5) with SMTP id <[EMAIL PROTECTED]> for <[EMAIL PROTECTED]>; Tue, 26 Aug 2003 16:48:11 -0500 Message-ID: <[EMAIL PROTECTED]> X-Mailer: Network Associates, Inc. Webshield SMTP, Version 4.5 Date: Tue Aug 26 16:48:12 2003 To: <[EMAIL PROTECTED]> From: [EMAIL PROTECTED] Subject: [SPAM]Virus Detected by Network Associates, Inc. Webshield SMTP V4.5 X-RBL-Warning: BADHEADERS: This E-mail was sent from a broken mail client [8010000e]. X-RBL-Warning: HELOBOGUS: Domain ASSENTOR4.corp.isib.net has no MX or A records. X-RBL-Warning: WEIGHT10: Weight of 20 reaches or exceeds the limit of 10. X-Declude-Sender: [EMAIL PROTECTED] [199.250.13.98] X-Declude-Spoolname: Dd5ae0450008aaab3.SMD X-Note: This E-mail was scanned by Declude JunkMail (www.declude.com) for spam. X-Spam-Tests-Failed: BADHEADERS, HELOBOGUS, IPNOTINMX, NOLEGITCONTENT, WEIGHT10, WEIGHT20, WEIGHT15 [20] X-Note: This E-mail was sent from mplfw2.dainrauscher.com ([199.250.13.98]). SMTPAV1: Network Associates WebShield SMTP V4.5 on SMTPAV2 detected virus W32/[EMAIL PROTECTED] in attachment thank_you.pif from <[EMAIL PROTECTED]> and it was Cleaned and Quarantined. RBC Dain Rauscher does not accept buy, sell or cancel orders by e-mail, or any instructions by e-mail that would require your signature. Information contained in this communication is not considered an official record of your account and does not supersede normal trade confirmations or statements. Any information provided has been prepared from sources believed to be reliable but is not guaranteed, does not represent all available data necessary for making investment decisions and is for informational purposes only. This e-mail may be privileged and/or confidential, and the sender does not waive any related rights and obligations. Any distribution, use or copying of this e-mail or the information it contains by other than an intended recipient is unauthorized. If you receive this e-mail in error, please advise me (by return e-mail or otherwise) immediately. Information received by or sent from this system is subject to review by supervisory personnel, is retained and may be produced to regulatory authorities or others with a legal right to the information. --- [This E-mail scanned for viruses by Declude Virus] -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of R. Scott Perry Sent: Tuesday, August 26, 2003 01:54 PM To: [EMAIL PROTECTED] Subject: Re: [Declude.JunkMail] [IMail Forum] Cannot receive messages from Comcast.net accounts >I've found that automated mail including opt-in newsletters, E-commerce >receipts, and product notifications, and renewal notices commonly fail the >BADHEADERS, SPAMHEADERS and HELOBOGUS tests. Just to clarify here for those that aren't aware -- the BADHEADERS and SPAMHEADERS test both look for headers that are rare in mail sent from legitimate mail clients, and are fairly common in spam. The difference in that the BADHEADERS test includes non-RFC-compliant headers, whereas the SPAMHEADERS test includes headers that are technically valid. So a legitimate E-mail should NEVER fail the BADHEADERS test -- and it is therefore normally safe to block on it (since it is not a valid E-mail, and many mailserver will block the E-mail). However, the SPAMHEADERS test will catch a fair amount of legitimate E-mail from poorly designed mail clients. In this case, the weighting system helps out a lot, by only blocking E-mail that fails multiple tests. Note that we will work with any company that is sending out E-mails that fail either test (at no charge) to help them fix their problems. -Scott --- Declude JunkMail: The advanced anti-spam solution for IMail mailservers. Declude Virus: Catches known viruses and is the leader in mailserver vulnerability detection. Find out what you have been missing: Ask for a free 30-day evaluation. --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.JunkMail mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.JunkMail". The archives can be found at http://www.mail-archive.com. --- [This E-mail scanned for viruses by Declude Virus] --- [This E-mail scanned for viruses by Declude Virus] --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] --- This E-mail came from the Declude.JunkMail mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.JunkMail". The archives can be found at http://www.mail-archive.com.