Re: moderately personalized spam sneaking past my SA. general approaches to fix it?

pgnd <[email protected]>
Newsgroups gmane.mail.spam.spamassassin.general
Message-ID <[email protected]>
> Well, I'm not sure out-of-the-box rules will help otherwise they'd already be helping. :)

I try not to assume -- I have faith in my abilities to mis-configure the magic!

That said, I'm leaning to the more-than-just-out-of-the-box solution needed here.

> You might want to run it through SA with the rule hits flags on so that you can tell if a new meta with some existing unscored rules might help.

+1 on the reminder, thx.
For some testing I'm getting rid of rule compilation, too.  Just in case I'm foot-shooting somewhere in there.

I'll poke around with the flags as soon as I finish migrating the Redis Bayes store to Valkey -- which I was reminded I should have done on this box!

> What caught my eye was the unusual TLD in the HELO. That would be trivial for a spammer to bypass, but it might help to look for unusual TLDs there as well...

hm.  missed the HELO.
cloud isn't (yet) *globally* banned @ my postfix edge; tho, it teeters on the fence :-/
unlike '.рф', .jetzt' and a host of others that my SA instance never gets to "enjoy" ;-)
in any case, I doubt that .cloud is in all the leak-thrus.  but there might be a pattern of 'less-if-not-un-common' TLDs.

> I will see about adding that to my sandbox tonight or tomorrow, but no guarantees on how it will do in masschecks.
> 
> It might also be time to update my phishing phrases rules...
> 
> Feel free to send me an archive of spamples if you like.

Assuming I can convince myself this ain't PEBKAC, I'll see what I can scrounge up.

To be fair, tho the absolute counts are high-enough to be annoying, the %-ages are still minuscule.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.