Martin Hepworth skrev:
Anders Norrbring wrote: <snip>Anders heres my analysis Content analysis details: (12.0 points, 5.0 required) pts rule name description---- ---------------------- --------------------------------------------------0.7 HOST_EQ_D_D_D_D HOST_EQ_D_D_D_D 0.9 HOST_EQ_D_D_D_DB HOST_EQ_D_D_D_DB 0.9 DATE_IN_PAST_24_48 Date: is 24 to 48 hours before Received: date 0.5 FB_NIGERIAN1 BODY: FB_NIGERIAN1 0.6 J_CHICKENPOX_44 BODY: {4}Letter - punctuation - {4}Letter 5.4 BAYES_99 BODY: Bayesian spam probability is 99 to 100% [score: 1.0000] 0.5 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/) 1.5 RAZOR2_CF_RANGE_E4_51_100 Razor2 gives engine 4 confidence level above 50% [cf: 70] 0.5 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50% [cf: 70] 0.6 HELO_MISMATCH_NET HELO_MISMATCH_NET 0.0 ADVANCE_FEE_1 Appears to be advance fee fraud (Nigerian 419)
I admit there's something weird with this.. If I save the text I posted in the post here, and then feed it into SA by invoking 'spamassassin -t < letter', then I get this:
Content analysis details: 7.7 points. Pts Rule name Description---- ---------------------- --------------------------------------------------
4.2 HELO_DYNAMIC_IPADDR Relay HELO'd using suspicious hostname (IP addr 1) 3.1 HELO_DYNAMIC_DHCP Relay HELO'd using suspicious hostname (DHCP) 0.1 FORGED_RCVD_HELO Received: contains a forged HELO 0.9 DATE_IN_PAST_24_48 Date: is 24 to 48 hours before Received: date -2.6 BAYES_00 BODY: Bayesian spam probability is 0 to 1% [score: 0.0000]2.0 RCVD_IN_SORBS_DUL RBL: SORBS: sent directly from dynamic IP address
[196.217.101.248 listed in dnsbl.sorbs.net] 0.0 ADVANCE_FEE_1 Appears to be advance fee fraud (Nigerian 419) -- Anders Norrbring Norrbring Consulting
smime.p7s
Description: S/MIME Cryptographic Signature