Re: [Declude.JunkMail] False positive -- Declude + Sniffer

2009-02-06 Thread Pete McNeil


Katie LaSalle-Lowery wrote:


I have a situation I haven't seen before. 

Declude logs show that the message failed Sniffer, which caused the 
message to exceed our weight threshold and be deleted.


Sniffer logs show that the message did not fail Sniffer.

Actually that is not correct. The message did fail SNF with a "Caution" 
result.



m='c:\IMAIL\spool\proc\work\D4a6d019b50e3.smd' s='40' r='0'/>




r='Caution'/>




The caution result (symbol 40) will resolve itself almost immediately in 
most cases because the caution range in GBUdb is very "thin". When a 
caution result is produced it indicates that there was no pattern match 
but the IP is suspicious. Since the message did not match a pattern 
result code the statistics for the IP are usually moved out of the 
caution range on the first event.


 


How do I prevent recurrence of this false positive deletion?

Note that the statistics show this IP has produced spam about 75% of the 
time (probability figure = 0.5). You may want to look into what other 
messages this IP has sent to you that were filtered out - and why.


If you would like to be more lenient on your system (especially during 
spam storms) then you could turn off the caution range or you could 
adjust it's envelope settings.


Hope this helps,

_M



---
This E-mail came from the Declude.JunkMail mailing list.  To
unsubscribe, just send an E-mail to imail...@declude.com, and
type "unsubscribe Declude.JunkMail".  The archives can be found
at http://www.mail-archive.com.

[Declude.JunkMail] False positive -- Declude + Sniffer

2009-02-06 Thread Katie LaSalle-Lowery
I have a situation I haven't seen before.  
Declude logs show that the message failed Sniffer, which caused the message
to exceed our weight threshold and be deleted.
Sniffer logs show that the message did not fail Sniffer.
 
Declude log snippet:
02/06/2009 07:34:33.083 q4a6d019b50e3.smd MXRATE-ALLOW:-5
nFROMNOMATCH:-1 SNIFFER:12 .  Total weight = 6.
02/06/2009 07:34:33.083 q4a6d019b50e3.smd Tests failed [weight=6]:
CATCHALLMAILS=IGNORE[0] NOLEGITCONTENT=IGNORE[0] IPNOTINMX=IGNORE[0]
MXRATE-ALLOW=WARN[-5] SNIFFER=DELETE[12]
 
Sniffer log snippet:





 
How do I prevent recurrence of this false positive deletion?  
 
Thanks, 
Katie
 
 


---
This E-mail came from the Declude.JunkMail mailing list.  To
unsubscribe, just send an E-mail to imail...@declude.com, and
type "unsubscribe Declude.JunkMail".  The archives can be found
at http://www.mail-archive.com.