I have used some of the rules.ima posted here and they work on everything but . c o m's (spaced for others with the same rules) for me. I still get false positives on http messages with embedded web site or email address links.
For example, this rule (without the extra spaces): B~name=".*\. c o m":virusbox B~filename=".*\. c o m":virusbox B~Begin 6.*\. c o m:virusbox Catches this offensive line (without the extra spaces) in html messages: <DIV><FONT face=Arial><FONT size=2><SPAN class=502594922-03022002><FONT color=#0000ff>Using the IMail Administration Program, add to the alias field, all of the names by which your users may wish to login, such as <A href="http://www.domain. c o m">www.domain. c o m</A>, mail.theirdomain. c o m, theirdomain. c o m, etc. This is a change required when upgrading to 7.05.</FONT></SPAN></FONT></FONT></DIV> So, I have to go fishing for IMail forum messages sent in HTML format. Joseph Marlin -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Michael E. Middleton Sent: Sunday, February 03, 2002 11:56 AM To: [EMAIL PROTECTED] Subject: [IMail Forum] rules.ima Does anyone have a rules.ima that is effective against the current flood of spam and trojans? Is there a forum where y'all share rules.ima files and ideas? How effective is rules.ima? Mike Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
