> I wonder if a test could be setup that checks for the
integrity of the email.
Good
idea!
I've
suggested such a comparison some months ago
For
example the last spam finished in my inbox:
Received: from arti.vub.ac.be
(h222n2fls34o834.telia.com [213.66.187.222])
by relay.aknet.it (8.11.2/8.11.2) with ESMTP id h9BElKp16532
for [EMAIL PROTECTED]; Sat, 11 Oct 2003 16:47:21 +0200
Subject: [s79] =?iso-8859-1?B?SG93IGRvZXMgU2lsZGVuYWZpbCBDaXRyYXRlICB3b3JrPw==?=
From: "Allen B. Case" <[EMAIL PROTECTED]>
X-RBL-Warning: SPAMCHK: Message failed SPAMCHK: 79.
X-Declude-Sender: [EMAIL PROTECTED] [213.66.187.222]
X-Spam-Tests-Failed: NOLEGITCONTENT, SPAMCHK, WEIGHT75 [79]
X-Country-Chain: SWEDEN->ITALY->destination
by relay.aknet.it (8.11.2/8.11.2) with ESMTP id h9BElKp16532
for [EMAIL PROTECTED]; Sat, 11 Oct 2003 16:47:21 +0200
Subject: [s79] =?iso-8859-1?B?SG93IGRvZXMgU2lsZGVuYWZpbCBDaXRyYXRlICB3b3JrPw==?=
From: "Allen B. Case" <[EMAIL PROTECTED]>
X-RBL-Warning: SPAMCHK: Message failed SPAMCHK: 79.
X-Declude-Sender: [EMAIL PROTECTED] [213.66.187.222]
X-Spam-Tests-Failed: NOLEGITCONTENT, SPAMCHK, WEIGHT75 [79]
X-Country-Chain: SWEDEN->ITALY->destination
HELO:
arti.vub.ac.be
REVDNS: h222n2fls34o834.telia.com
FROM:
[EMAIL PROTECTED]ca
ORIGIN
COUNTRY: Sweden
Received: from
microsoft.com (sp121.neoplus.adsl.tpnet.pl [80.54.1.121])
by relay2.aknet.it (8.11.2/8.11.2) with SMTP id h9AGHYo27169
for <[EMAIL PROTECTED]>; Fri, 10 Oct 2003 18:17:35 +0200
Date: Fri, 10 Oct 2003 16:45:30 +0000
From: Ketygukyt <[EMAIL PROTECTED]>
Reply-To: Worivim <[EMAIL PROTECTED]>
Sender: Kizopikar <[EMAIL PROTECTED]>
X-RBL-Warning: DSN: Not supporting null originator (DSN)
X-RBL-Warning: SPAMCHK: Message failed SPAMCHK: 50.
X-Spam-Tests-Failed: DSN, SPAMCHK [60]
X-Country-Chain: POLAND->ITALY->destination
by relay2.aknet.it (8.11.2/8.11.2) with SMTP id h9AGHYo27169
for <[EMAIL PROTECTED]>; Fri, 10 Oct 2003 18:17:35 +0200
Date: Fri, 10 Oct 2003 16:45:30 +0000
From: Ketygukyt <[EMAIL PROTECTED]>
Reply-To: Worivim <[EMAIL PROTECTED]>
Sender: Kizopikar <[EMAIL PROTECTED]>
X-RBL-Warning: DSN: Not supporting null originator (DSN)
X-RBL-Warning: SPAMCHK: Message failed SPAMCHK: 50.
X-Spam-Tests-Failed: DSN, SPAMCHK [60]
X-Country-Chain: POLAND->ITALY->destination
HELO:
microsoft.com
REVDNS: sp121.neoplus.adsl.tpnet.pl
FROM:
[EMAIL PROTECTED]
ORIGIN
COUNTRY: Poland
(From,
Reply-to, Sender are completely different)
But
maybe this is already part of some heuristic/future tests....
?
Markus
