Here is my /etc/rulesdujour/config, its a modified version of the file from 
Gentoo Portage.

As you can see, I use them all. I've had very little, if any, false positives 
at my location. It doesn't really matter how high the spam scores, just keep an 
eye out for false positives.  

I too am using Amavisd-new

# $Header$
# Gentoo configuration for the RulesDuJour script.

# - the following rulesets _will_ cause some false-positives
# SARE_HTML1 SARE_HTML2 SARE_HTML3 SARE_HTML4
# SARE_HEADER1 SARE_HEADER2 SARE_HEADER3
# SARE_GENLSUBJ1 SARE_GENLSUBJ2 SARE_GENLSUBJ3

# - the following rulesets are no longer supported upstream, and should not be 
used:
# SARE_CODING_HTML SARE_HEADER_ABUSE MRWIGGLY BACKHAIR WEEDS1 WEEDS2 CHICKENPOX

# - the following rulesets _should_ be safe, but you should be careful still.
# Read about them here: http://www.rulesemporium.com/rules.htm
# SARE_REDIRECT SARE_HTML0 SARE_HEADER0 SARE_GENLSUBJ0 SARE_ADULT SARE_FRAUD
# SARE_BML SARE_RATWARE SARE_SPOOF SARE_BAYES_POISON_NXM SARE_OEM SARE_RANDOM
# SARE_SPECIFIC BIGEVIL EVILNUMBERS

# - NOT recommented due to massive memory usage:
# BLACKLIST BLACKLIST_URI

# - these were merged with spamassassin upstream 3.x, but older versions of
# spamassassin may want to use them:
# SARE_GENLSUBJ_X30 SARE_HEADER_X30 SARE_HTML_X30 SARE_REDIRECT

# - for SpamAssassin versions _AFTER_ 3.00 
# SARE_REDIRECT_POST300

# - for SpamAssassin versions _BEFORE_ 2.5x
# SARE_FRAUD_PRE25X SARE_BML_PRE25X

TRUSTED_RULESETS_SAFE=" ANTIDRUG \
                        BOGUSVIRUS \
                        RANDOMVAL \
                        SARE_ADULT \
                        SARE_BAYES_POISON_NXM \
                        SARE_BML \
                        SARE_EVILNUMBERS0 \
                        SARE_FRAUD \
                        SARE_GENLSUBJ \
                        SARE_GENLSUBJ0 \
                        SARE_GENLSUBJ_ENG \
                        SARE_HEADER \
                        SARE_HEADER0 \
                        SARE_HEADER_ENG \
                        SARE_HIGHRISK \
                        SARE_HTML \
                        SARE_HTML0 \
                        SARE_HTML_ENG \
                        SARE_OBFU \
                        SARE_OBFU0 \
                        SARE_OEM \
                        SARE_RANDOM \
                        SARE_RATWARE \
                        SARE_REDIRECT_POST300 \
                        SARE_SPAMCOP_TOP200 \
                        SARE_SPECIFIC \
                        SARE_SPOOF \
                        SARE_STOCKS \
                        SARE_UNSUB \
                        SARE_URI \
                        SARE_URI0 \
                        SARE_URI_ENG \
                        SARE_WHITELIST \
                        SARE_WHITELIST_RCVD \
                        SARE_WHITELIST_SPF \
                        TRIPWIRE "

TRUSTED_RULESETS_FAIRLY_SAFE="  SARE_EVILNUMBERS1 \
                                SARE_HTML1 \
                                SARE_HEADER1 \
                                SARE_GENLSUBJ1 \
                                SARE_OBFU1 \
                                SARE_URI1 "


TRUSTED_RULESETS_DANGEROUS="    SARE_EVILNUMBERS2 \
                                SARE_HTML2 \
                                SARE_HTML3 \
                                SARE_HTML4 \
                                SARE_HEADER2 \
                                SARE_HEADER3 \
                                SARE_GENLSUBJ2 \
                                SARE_GENLSUBJ3 \
                                SARE_OBFU2 \
                                SARE_OBFU3 \
                                SARE_URI2 \
                                SARE_URI3 "

#TRUSTED_RULESETS="${TRUSTED_RULESETS_SAFE}"
#TRUSTED_RULESETS="${TRUSTED_RULESETS_SAFE} ${TRUSTED_RULESET_FAIRLY_SAFE}"
TRUSTED_RULESETS="${TRUSTED_RULESETS_SAFE} ${TRUSTED_RULESETS_FAIRLY_SAFE} 
${TRUSTED_RULESETS_DANGEROUS}"

# do NOT change anything below this point
TAIL="tail -n1"
HEAD="head -n1"
SA_RESTART="/etc/init.d/amavisd restart"
# read in extra rulesets
[ -s /etc/rulesdujour/rulesets ] && source /etc/rulesdujour/rulesets

Reply via email to