On 30.6.2012 21:32, João Gouveia wrote:
> Hi Jarif,
> 
> Are you the owner of the "jarif" corpus being used on the Spamassassin
> masschecks?
> If so, I'm interested in investigating these classification errors:
> 
> http://ruleqa.spamassassin.org/20120630-r1355665-n/RCVD_IN_MSPIKE_BL?mclog=ham-net-jarif
> 
> I own and operate MailSpike, and naturally I'm a bit concerned about
> this false positives.
> Would it be possible to know the list of IP addresses that caused so
> many false positives?
> 
> Thanks in advance!
> 

I had false alarms in my corpus, thanks for posting me this query!

1. They were mostly old mails from WorldOfTanks.eu and Facebook.com.
They did trigger apparently RCVD_IN_MSPIKE_BL in 2011 and early this year.

2. None of them trigger it now.

3. I have to to remove old SpamAssassin traces from all of my corpus. I
had thought that SA does it automatically when doing masscheck, but I
was wrong! I even asked about it in SA dev mailing list, but got no
answer and made a bad decision to leave the markup to the files.

No worries, I take corrective action now.

Thanks, jarif

ps.

They seem to trigger still

   3.5 FROM_12LTRDOM From a 12-letter domain

Where did that rule come? Really? 12 letters in domain, and it gets 3.5
points??

Received: from wot-slave-54.worldoftanks.ru ([213.252.131.54])
        by ikiaikainen.iki.fi (8.14.4/8.14.4) with ESMTP id p0NIObHR027573
        for <[email protected]>; Sun, 23 Jan 2011 20:24:37 +0200 (EET)
Received: by wot-slave-54.worldoftanks.ru (Postfix, from userid 101)
        id 32686BB83CC; Sun, 23 Jan 2011 18:24:32 +0000 (UTC)


It is  worldoftanks.eu and worldoftanks.ru triggering this strange rule.

All mail from Facebook gets negative points only.

-- 

Tomorrow will be cancelled due to lack of interest.
        


Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to