|
My experience is that SNIFFER-GENERAL and SNIFFER-EXPERIMENTAL are the
two common names for the tests that produce the most such false
positives. SNIFFER-GENERAL contains user submitted spam that wasn't
already tagged, and unfortunately the userbase tends to report what I
consider to be legitimate advertising, and/or the rules generated are
overly generic and can hit both the good and the bad.
SNIFFER-EXPERIMENTAL is where most new rules are generated from the
spamtraps, and due to the cross checking/qualifying primarily with
SURBL, a domain that might have temporarily been a false positive in
SURBL can end up living much longer in SNIFFER-EXPERIMENTAL than it
does in SURBL. On my system in order to lessen the impact of these things, I have been collecting CIDR ranges and reverse DNS entries for bulk-mail services as well as individual bulk-mailers (such as amazon.com, etc.) so that I can treat this E-mail differently by disabling/crediting back points for certain tests. It was a huge undertaking, but it was very much worth it since there seemed to be a never ending stream of random false positives and I got sick of whitelisting E-mail campaigns one at a time. I still score Sniffer at full points for these things, but I credit back points for tests that are primarily targeted at zombies such as BADHEADERS. Essentially it takes a hit from at least two of SURBL, SNIFFER and SPAMCOP to block one of these whereas before just one of these would result in blocking when combined with the other types of tests. I also segregate blocked E-mail from this classification so that it isn't mixed in with the unspecified held messages, making it easier to do review. Matt Markus Gufler wrote:
|
Title: Message
- Re: [Declude.JunkMail] Combo Filter Matt
- RE: [Declude.JunkMail] Combo Filter Markus Gufler
- Re: [Declude.JunkMail] Combo Fi... Matt
- RE: [Declude.JunkMail] Combo Filter Goran Jovanovic
- RE: [Declude.JunkMail] Combo Fi... Markus Gufler
- Re: [Declude.JunkMail] Comb... Scott Fisher
- RE: [Declude.JunkMail] Combo Fi... Robert Grosshandler
- Re: [Declude.JunkMail] Comb... Scott Fisher
- RE: [Declude.JunkMail] Combo Filter Colbeck, Andrew
- RE: [Declude.JunkMail] Combo Filter Goran Jovanovic
- RE: [Declude.JunkMail] Combo Fi... Robert Grosshandler
- RE: [Declude.JunkMail] Combo Filter IS - Systems Eng. \(Karl Drugge\)
- RE: [Declude.JunkMail] Combo Filter Goran Jovanovic
