URIBL plugins are broken

2015-05-11 Thread Reindl Harald
i face false positives where the links are just facebook.com with the http-prefix in front and NOT com between the http-prefix and the real facebook domain the domain with com in front is indeed on both URIBL but it just don#t exist in the messages at all - why does SA extract the domains

Re: URIBL plugins are broken

2015-05-11 Thread Kevin A. McGrail
On 5/11/2015 9:46 AM, Reindl Harald wrote: stripped down and anonymized sample attached the real bad thing is that the part triggering the URIBL rules wrongly is the quote of the signature from the message replied to Am 11.05.2015 um 15:13 schrieb Reindl Harald: i face false positives where

Re: DNSWL fp and other problems

2015-05-11 Thread Joe Quinn
On 5/11/2015 9:42 AM, Alex Regan wrote: Hi, I have a fp that was passed through thomsonreuters, hitting RCVD_IN_DNSWL_HI, receiving -5 points, from an obvious hacked account. http://pastebin.com/5LYS7s2v This is with v3.4.1, but an older bayes database, so perhaps it needs to be rebuilt.

Re: URIBL plugins are broken

2015-05-11 Thread Kevin A. McGrail
On 5/11/2015 9:13 AM, Reindl Harald wrote: i face false positives where the links are just facebook.com with the http-prefix in front and NOT com between the http-prefix and the real facebook domain the domain with com in front is indeed on both URIBL but it just don#t exist in the messages

Re: URIBL plugins are broken

2015-05-11 Thread Reindl Harald
Am 11.05.2015 um 15:43 schrieb Kevin A. McGrail: On 5/11/2015 9:13 AM, Reindl Harald wrote: i face false positives where the links are just facebook.com with the http-prefix in front and NOT com between the http-prefix and the real facebook domain the domain with com in front is indeed on

DNSWL fp and other problems

2015-05-11 Thread Alex Regan
Hi, I have a fp that was passed through thomsonreuters, hitting RCVD_IN_DNSWL_HI, receiving -5 points, from an obvious hacked account. http://pastebin.com/5LYS7s2v This is with v3.4.1, but an older bayes database, so perhaps it needs to be rebuilt. Even with BAYES_99, it still wouldn't have

Re: DNSWL fp and other problems

2015-05-11 Thread Reindl Harald
Am 11.05.2015 um 15:42 schrieb Alex Regan: I have a fp that was passed through thomsonreuters, hitting RCVD_IN_DNSWL_HI, receiving -5 points, from an obvious hacked account. http://pastebin.com/5LYS7s2v This is with v3.4.1, but an older bayes database, so perhaps it needs to be rebuilt. Even

Re: Ignoring Received: header added by real MTA

2015-05-11 Thread Marcin Mirosław
W dniu 06.05.2015 o 14:46, Kevin A. McGrail pisze: On 5/5/2015 3:56 PM, Marcin Mirosław wrote: W dniu 2015-05-05 o 21:47, Kevin A. McGrail pisze: On 5/5/2015 3:38 PM, Marcin Mirosław wrote: I'm thinking about removing all Received headers from email except added by my MTA, storing it,

Re: DNSWL fp and other problems

2015-05-11 Thread Niamh Holding
Hello Reindl, Monday, May 11, 2015, 2:57:57 PM, you wrote: RH complain at dnswl.org Don't complain, report it and the listing will then be reviewed -- Best regards, Niamhmailto:ni...@fullbore.co.uk pgpKsVGuBiYkY.pgp Description: PGP signature