Re: header inventory

"David Harris" <[email protected]> Fri, 12 Mar 2004 01:07:11 +1300
Newsgroups gmane.ietf.asrg.filtering
Organization Pegasus Mail, Dunedin, NZ
Message-ID <40510D7F.26761.3651F2CD@localhost>
While I really like the idea of getting some community of interest 
together on spam header processing, I have a suspicion that we may all 
be too disparate and set in our ways to be able to change... 
Nonetheless, the interchange of information is certainly useful and 
worthwhile, so here's what I do in Mercury/32, my mail server. (I do the 
same thing in Pegasus Mail, which has the same content control 
engine, but I regard client-level content filtering as a sideshow, so I'll 
concentrate on Mercury/32 here).

Mercury/32 allows the user to add any header they wish in any form 
they wish, but it has a default set that is probably used in the majority of 
cases.

The program calculates a weight for the message, and distinguishes 
between messages that have a negative weight (I call this "white-
weighting) and those that have a positive weight (i.e, are likely to be 
spam).

If a message earns a weight that is greater than or equal to 0 but less 
than the user-defined trigger level for the rule set, no specific header is 
added. For scores equal to or above the trigger level, the program adds 
"X-UC-Weight", which consists of a graphic and the numeric weight - 
like this:

  X-UC-Weight: [#   ] 55

For messages that have 2x, 3x and 4x the trigger score (i.e, are 
progressively "spammier"), the graphic adds a '#', like this:

  X-UC-Weight: [### ] 180

For white-weighted messages (weights lower than zero), the same 
header layout is used, but the header itself is "X-AC-Weight". (Think of 
the headers as meaning "X-Unacceptable-Content-Weight" and "X-
Acceptable-Content-Weight" - Mercury's content control is designed to 
have purposes other than spam detection).

We went the graphic route because it was easier to explain to users 
how to filter on it than it was to use more complex layouts that required 
regular expressions (remember that we're predominantly 
accommodating Windows users and you can't expect too much from a 
significant proportion of that population).

We can also add a diagnostic header, "X-CC-Diagnostic", which lists 
the tests that contributed to the calculated weight. This header is 
essentially user-informational, and is not really intended to be parsed or 
filtered.

Cheers!

-- David --

------------------ David Harris -+- Pegasus Mail ----------------------
  Box 5451, Dunedin, New Zealand | e-mail: [email protected]
           Phone: +64 3 453-6880 | Fax: +64 3 453-6612

Real book titles from history (really!):
   "Frog Raising for Pleasure and Profit".