https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6460

--- Comment #2 from Phil Randal <[email protected]> 2010-07-02 
10:28:57 EDT ---
(In reply to comment #1)
> Hmm, I'm seeing similar occasional FPs here with numerically-named mail 
> relays.
> Example:
> 
> dbg: metadata: X-Spam-Relays-Untrusted: [ ip=213.186.36.34
> rdns=5.mail-out.ovh.net helo=5.mail-out.ovh.net by=extranet.tradoc.fr ident=
> envfrom= intl=0 id=79A4E334033 auth= msa=0 ] [ ip=213.186.33.62 
> rdns=a2.ovh.net
> helo=mozg.ha.ovh.net by=5.mail-out.ovh.net ident= envfrom= intl=0 id= auth=
> msa=0 ]
> dbg: rules: ran header rule RCVD_ILLEGAL_IP ======> got hit: " by=5."
> 
> 
> I'd suggest that the regex needs to ensure that it is hitting on an IP address
> rather than a host name that happens to start with a number and a dot.

That's exactly it.

We've has 395 rule hits (on corpus of 55253) over the last 39.5 hours, ALL
false-positives.

-- 
Configure bugmail: 
https://issues.apache.org/SpamAssassin/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.

Reply via email to