Hello Phillip,

Tuesday, April 3, 2007, 6:30:22 AM, you wrote:

> I am getting a large number of false positives and not sure  why.

<snip/>

> How do I add a whitelist of domains, or do i send in the false
> positives in hopes they will somehow be added to the rulebase.

<snip/>

Please follow our false positives handling procedure:

http://kb.armresearch.com/index.php?title=Message_Sniffer.FAQ.FalsePositives

We will identify the rules that cause your false positives and either:

* Remove the rules from the core rulebase; or

* Block the rules from your specific rulebase; or

* Create appropriate white rules to compensate.

If you wish we can always add white rules to your rulebase by request,
however this is a dangerous practice since blackhats frequently use
tactics to exploit white rules - for example: by sending spam w/
forged from addresses matching their target delivery domains.

Hope this helps,

Thanks!

_M


-- 
Pete McNeil
Chief Scientist,
Arm Research Labs, LLC.


#############################################################
This message is sent to you because you are subscribed to
  the mailing list <[email protected]>.
To unsubscribe, E-mail to: <[EMAIL PROTECTED]>
To switch to the DIGEST mode, E-mail to <[EMAIL PROTECTED]>
To switch to the INDEX mode, E-mail to <[EMAIL PROTECTED]>
Send administrative queries to  <[EMAIL PROTECTED]>

Reply via email to