Re: sa-update redirecting to ruleqa???

2019-03-05 Thread Dave Jones
On 3/5/19 4:44 PM, John Hardin wrote: On Tue, 5 Mar 2019, Dave Jones wrote: On 3/5/19 12:24 PM, John Hardin wrote: On Tue, 5 Mar 2019, Bill Cole wrote: On 5 Mar 2019, at 12:33, John Hardin wrote: Attempting to grab the latest published rules update (using a utility script I wrote) I get

Re: sa-update redirecting to ruleqa???

2019-03-05 Thread Dave Jones
On 3/5/19 12:24 PM, John Hardin wrote: On Tue, 5 Mar 2019, Bill Cole wrote: On 5 Mar 2019, at 12:33, John Hardin wrote: Attempting to grab the latest published rules update (using a utility script I wrote) I get this:   Latest revision: 1854751   wget

Re: ruleqa redirection from http to https is mangling the url

2019-03-02 Thread Dave Jones
On 3/2/19 10:54 AM, dar...@chaosreigns.com wrote: I have a script which links to: http://ruleqa.spamassassin.org/?daterev=20180922=%2FDNSWL This is a search of the latest network mass-check for rules matching /DNSWL. Between 2018-09-22 and 2018-09-29, that started getting redirected to

Re: Sendgrid is hitting HELO_DYNAMIC_IPADDR

2019-02-20 Thread Dave Jones
On 2/20/19 7:48 AM, Benny Pedersen wrote: Dave Jones skrev den 2019-02-20 03:30: Let's say example.com sent email from sendgrid.net and DMARC passes (SPF_PASS and alignment with the envelope-from domain or DKIM_PASS_AU). I would like to subtract a few points in this case without having to list

Re: Sendgrid is hitting HELO_DYNAMIC_IPADDR

2019-02-19 Thread Dave Jones
On 2/19/19 6:12 PM, Kevin A. McGrail wrote: Hi All, Thoughts on how to fix this issue where sendgrid is hitting this rule? 3.2 HELO_DYNAMIC_IPADDR    Relay HELO'd using suspicious hostname (IP     addr 1) Example helo: o168-245-122-130.outbound-mail.sendgrid.net

Re: Nightly Mass Check results page not available in https

2018-09-24 Thread Dave Jones
On 9/24/18 8:30 AM, Kevin A. McGrail wrote: On 9/24/2018 7:06 AM, Dave Jones wrote: On 9/24/18 5:33 AM, Sidney Markowitz wrote: I was updating links on one of our wiki pages to https when I discovered that http://ruleqa.spamassassin.org does not take a https link. Chrome reports

Re: def_whitelist_auth

2018-09-24 Thread Dave Jones
On 9/23/18 1:42 PM, Henrik Krohns wrote: On Sun, Sep 23, 2018 at 12:25:36PM -0500, Dave Jones wrote: Consider the difference between these two SPF records: # dig email.chase.com txt +short "v=spf1 include:epsl1.com -all" # dig chase.com txt +short "v=spf1 a:spf.jpmchase.com ip

Re: def_whitelist_auth

2018-09-23 Thread Dave Jones
On 9/23/18 10:46 AM, Henrik Krohns wrote: On Sun, Sep 23, 2018 at 09:15:33AM -0500, Dave Jones wrote: Keep in mind that these entries are usually subdomains that will not be user/human mailboxes that can be compromised. These entries are verified to be system-generated and have other rule

Re: def_whitelist_auth

2018-09-23 Thread Dave Jones
On 9/23/18 8:31 AM, Kevin A. McGrail wrote: On 9/23/2018 9:04 AM, Henrik Krohns wrote: I'm curious, are there guidelines on what can be added here? How are these lists generated? Who verifies and checks that old domains don't age and go to some spammers etc? Most of the listed stuff seems

Re: Trunk Rules Question

2018-08-20 Thread Dave Jones
On 08/20/2018 03:53 PM, Kevin A. McGrail wrote: On 8/20/2018 4:47 PM, Dave Jones wrote: You are correct.  Only trunk is used for masscheck and ruleqa promotions so the rules do need to contain version checking. OK, so 3.4 in SVN doesn't affect masscheck or ruleqa, right?  Nothing svn check's

Re: Trunk Rules Question

2018-08-20 Thread Dave Jones
You are correct. Only trunk is used for masscheck and ruleqa promotions so the rules do need to contain version checking. Dave On 08/20/2018 12:20 PM, Kevin A. McGrail wrote: Looking for a sanity check on this. Rules from RuleQA are ONLY published from trunk, correct? So rule development

Re: +#!/usr/bin/env perl -w

2018-05-10 Thread Dave Jones
On 05/10/2018 11:08 AM, Axb wrote: On 05/10/2018 05:09 PM, Bill Cole wrote: On 10 May 2018, at 3:21 (-0400), Axb wrote: Why is this needed? It is not possible to rely on /usr/bin/perl existing or being the "right" perl on some platforms. Most obviously, Perl was removed long ago from the

Re: +#!/usr/bin/env perl -w

2018-05-10 Thread Dave Jones
On 05/10/2018 07:07 AM, Kevin A. McGrail wrote: Agreed that is a mistake.  I am on the road.  Who made the change? Author: billcole Date: Wed May 9 17:35:07 2018 New Revision: 1831272 On Thu, May 10, 2018, 07:57 Dave Jones <da...@apache.org <mailto:da...@apache.org>> wrote:

Re: +#!/usr/bin/env perl -w

2018-05-10 Thread Dave Jones
On 05/10/2018 04:53 AM, Axb wrote: Seems this also blew up my SA nightly masschecks my temp fix for rule generation was do reinstate #!/usr/bin/perl -w and disable SA svn updates. On 05/10/2018 09:21 AM, Axb wrote: Index: mass-check

Re: svn commit: r1828937 - /spamassassin/trunk/rules/60_whitelist_auth.cf

2018-04-12 Thread Dave Jones
On 04/11/2018 05:18 PM, Bill Cole wrote: On 11 Apr 2018, at 17:50 (-0400), Dave Jones wrote: On 04/11/2018 04:29 PM, billc...@apache.org wrote: Author: billcole Date: Wed Apr 11 21:29:08 2018 New Revision: 1828937 URL: http://svn.apache.org/viewvc?rev=1828937=rev Log: Google Forms has

Re: svn commit: r1828937 - /spamassassin/trunk/rules/60_whitelist_auth.cf

2018-04-11 Thread Dave Jones
On 04/11/2018 04:29 PM, billc...@apache.org wrote: Author: billcole Date: Wed Apr 11 21:29:08 2018 New Revision: 1828937 URL: http://svn.apache.org/viewvc?rev=1828937=rev Log: Google Forms has generated spam, befouling the google.com reputation Modified:

Re: GSOC 2018 SpamAssassin Statistical Classifier Plugin

2018-03-14 Thread Dave Jones
On 03/14/2018 01:06 AM, Saahil Sirowa wrote: Hi Kevin, I have a few questions regarding the GSoC project. They goes as follows:- 1) How am I supposed to share my first draft with the community. Should I post the link in the mail or submit it on Apache website? 2) Can I take some ideas from this

Re: Rule updates are too old - 2018-03-11 3.3.2:2018-03-10

2018-03-11 Thread Dave Jones
On 03/11/2018 12:08 PM, dar...@chaosreigns.com wrote: On 03/11, Dave Jones wrote: On 03/11/2018 04:00 AM, dar...@chaosreigns.com wrote: SpamAssassin version 3.3.2 has not had a rule update since 2018-03-10. 20180310: Spam and ham are above threshold of 150,000: http

Re: Rule updates are too old - 2018-03-11 3.3.2:2018-03-10

2018-03-11 Thread Dave Jones
On 03/11/2018 04:00 AM, dar...@chaosreigns.com wrote: SpamAssassin version 3.3.2 has not had a rule update since 2018-03-10. 20180310: Spam and ham are above threshold of 150,000: http://ruleqa.spamassassin.org/?daterev=20180310 20180310: Spam: 416659, Ham: 418483 The spam and ham counts

Re: [Bug 3972] Hotmail forged header error

2018-02-13 Thread Dave Jones
On 02/13/2018 01:25 PM, Michael Peddemors wrote: On 18-02-13 11:16 AM, bugzilla-dae...@bugzilla.spamassassin.org wrote: https://bz.apache.org/SpamAssassin/show_bug.cgi?id=3972 Dave Jones <da...@apache.org> changed:     What    |Removed

Bug 7417 - remove RCVD_IN_BRBL_LASTEXT

2018-02-08 Thread Dave Jones
of the 50_scores.cf would have done the trick. https://bz.apache.org/SpamAssassin/show_bug.cgi?id=7417 -- Dave Jones

Extending the entries in 60_whitelist_spf.cf

2017-11-26 Thread Dave Jones
The current 60_whitelist_spf.cf is 11 years old.  What does everyone think about starting a 60_whitelist_auth.cf and extending this list to known good senders like *@alertsp.chase.com and *@email.dropboxmail.com? My SA platform has very good results with thousands of whitelist_auth entries

Re: svn commit: r1813573 - in /spamassassin/trunk/rules: 25_dkim.cf 50_scores.cf

2017-10-27 Thread Dave Jones
This update was to allow us to enable sa-update again in a couple of days. I did not experience this problem in my SA instances because I had manually patched the DKIM.pm plugin to test out the new DKIM_VALID_EF rule. Someone on the users list noted this so I did this minor commit 1813573