On 30.6.2012 21:32, João Gouveia wrote: > Hi Jarif, > > Are you the owner of the "jarif" corpus being used on the Spamassassin > masschecks? > If so, I'm interested in investigating these classification errors: > > http://ruleqa.spamassassin.org/20120630-r1355665-n/RCVD_IN_MSPIKE_BL?mclog=ham-net-jarif > > I own and operate MailSpike, and naturally I'm a bit concerned about > this false positives. > Would it be possible to know the list of IP addresses that caused so > many false positives? > > Thanks in advance! >
I had false alarms in my corpus, thanks for posting me this query!
1. They were mostly old mails from WorldOfTanks.eu and Facebook.com.
They did trigger apparently RCVD_IN_MSPIKE_BL in 2011 and early this year.
2. None of them trigger it now.
3. I have to to remove old SpamAssassin traces from all of my corpus. I
had thought that SA does it automatically when doing masscheck, but I
was wrong! I even asked about it in SA dev mailing list, but got no
answer and made a bad decision to leave the markup to the files.
No worries, I take corrective action now.
Thanks, jarif
ps.
They seem to trigger still
3.5 FROM_12LTRDOM From a 12-letter domain
Where did that rule come? Really? 12 letters in domain, and it gets 3.5
points??
Received: from wot-slave-54.worldoftanks.ru ([213.252.131.54])
by ikiaikainen.iki.fi (8.14.4/8.14.4) with ESMTP id p0NIObHR027573
for <[email protected]>; Sun, 23 Jan 2011 20:24:37 +0200 (EET)
Received: by wot-slave-54.worldoftanks.ru (Postfix, from userid 101)
id 32686BB83CC; Sun, 23 Jan 2011 18:24:32 +0000 (UTC)
It is worldoftanks.eu and worldoftanks.ru triggering this strange rule.
All mail from Facebook gets negative points only.
--
Tomorrow will be cancelled due to lack of interest.
signature.asc
Description: OpenPGP digital signature
