I've got spamd running with "-s local3" and "-D" to log to syslog and produce
debug info as a poor-mans _verbose_ option. Anyway, parsing through the logs I
noticed something which made me wonder if it's a bug in SA.

Here's the FROM, TO, and SPAM score from these logs for an email:
Dec 15 22:42:33 mail spamd[10985]: debug: all '*From' addrs:
Dec 15 22:42:34 mail spamd[10985]: debug: all '*To' addrs: [EMAIL PROTECTED]
Dec 15 22:42:39 mail spamd[10985]: logmsg: identified spam (19.6/5.0) for
qmaild:2020 in 5.4 seconds, 1389 bytes.

Here's that emails headers (notice @yahoo has no TLD specified, no .com or .net
or anything of the sort. The from address above is blank [as a result?]):

Return-Path: <[EMAIL PROTECTED]>
Delivered-To: [EMAIL PROTECTED]
Received: (qmail 10984 invoked from network); 16 Dec 2003 03:42:33 -0000
Received: from modemcable207.127-70-69.mc.videotron.ca (69.70.127.207)
by mydomain.com with SMTP; 16 Dec 2003 03:42:33 -0000
Received: from (HELO ri0px) [77.147.227.130]
by modemcable207.127-70-69.mc.videotron.ca with ESMTP id <357670-92051>;
Tue, 16 Dec 2003 08:37:37 +0600
Message-ID: <[EMAIL PROTECTED]>
From: "Lacey Garrett" <[EMAIL PROTECTED]>
Reply-To: "Lacey Garrett" <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
Subject: **SPAM** 19.64 hits - RE:Diazepam.m Xanax.x Valium.m Vicodin.n esygh
Date: Tue, 16 Dec 03 08:37:37 GMT
X-Mailer: Microsoft Outlook Express 5.00.2615.200
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="8.8D99FF_D3.."
X-Priority: 3
X-MSMail-Priority: Normal
X-Spam-Flag: YES
X-Spam-Checker-Version: SpamAssassin 2.61 (1.212.2.1-2003-12-09-exp) on
mail.localdomain
X-Spam-Level: *******************
X-Spam-Status: Yes, hits=19.6 required=5.0 tests=BAYES_99,BIZ_TLD,
DATE_IN_FUTURE_03_06,DATE_SPAMWARE_Y2K,FORGED_MUA_
OUTLOOK,
MISSING_MIMEOLE,NO_DNS_FOR_FROM,RCVD_IN_BL_SPAMCOP
_NET,RCVD_IN_DSBL
autolearn=no version=2.61
X-Spam-Report:
* 4.2 DATE_SPAMWARE_Y2K Date header uses unusual Y2K formatting
* 5.4 BAYES_99 BODY: Bayesian spam probability is 99 to 100%
* [score: 1.0000]
* 0.1 BIZ_TLD URI: Contains a URL in the BIZ top-level domain
* 1.6 NO_DNS_FOR_FROM Domain in From header has no MX or A DNS records
* 1.9 DATE_IN_FUTURE_03_06 Date: is 3 to 6 hours after Received: date
* 0.7 RCVD_IN_DSBL RBL: Received via a relay in list.dsbl.org
* [<http://dsbl.org/listing?ip=69.70.127.207>]
* 1.5 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
* [Blocked - see <http://www.spamcop.net/bl.shtml?69.70.127.207>]
* 1.6 MISSING_MIMEOLE Message has X-MSMail-Priority, but no X-MimeOLE
* 2.6 FORGED_MUA_OUTLOOK Forged mail pretending to be from MS Outlook



-------------------------------------------------------
This SF.net email is sponsored by: IBM Linux Tutorials.
Become an expert in LINUX or just sharpen your skills.  Sign up for IBM's
Free Linux Tutorials.  Learn everything from the bash shell to sys admin.
Click now! http://ads.osdn.com/?ad_id=1278&alloc_id=3371&op=click
_______________________________________________
Spamassassin-talk mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/spamassassin-talk

Reply via email to