On Thu, 12 Apr 2018, Alex wrote:

We received an email to undisclosed-recipients that contained a google
redirect to an owl.ly site


amavisd knew this single email was delivered to more than 40
recipients. Is there any way to benefit from that in spamassassin?
This seems to be a common denominator with a lot of these.

How did it know that? Was it bcc'd to 40+ local users and there's some side channel communicating that to Amavis? Or are you referring to 40+ separate deliveries of the same message, which would point at Razor et. al. as the solution?

How much of a spam indicator is the google redirects?

I'd say a google redirect to bit.ly or ow.ly is pretty suspicious, potentially poison-pill suspicious...

Can someone look at this redirect as part of the redirector_pattern along with __GOOG_REDIR?

I'll take a look and see about adding it to my sandbox.

