I receive a lot of spams similar to this one: http://igor.chudov.com/tmp/spam014.txt
It is a spam, however it has a low score and hit my mailbox. When I reran spamassassin -D on this message, it was flagged as spam and I get the following: http://igor.chudov.com/tmp/spam014.trace.txt The difference is that it tripped BAYES50, RAZOR2_CHECK, URIBL_BLACK and URIBL_DBL_SPAM. I re-ran spamassassin a few times, and it does successfully flag this as spam. So, why is it triggering URIBL_BLACK and URIBL_DBL_SPAM etc now, but not when I received the original spam? Are those rules unreliable? Or was the database updated with those URLs after I received that particular spam? i