Re: moderately personalized spam sneaking past my SA. general approaches to fix it?
pgnd <[email protected]>
| Newsgroups | gmane.mail.spam.spamassassin.general |
|---|---|
| Message-ID | <[email protected]> |
> Well, I'm not sure out-of-the-box rules will help otherwise they'd already be helping. :) I try not to assume -- I have faith in my abilities to mis-configure the magic! That said, I'm leaning to the more-than-just-out-of-the-box solution needed here. > You might want to run it through SA with the rule hits flags on so that you can tell if a new meta with some existing unscored rules might help. +1 on the reminder, thx. For some testing I'm getting rid of rule compilation, too. Just in case I'm foot-shooting somewhere in there. I'll poke around with the flags as soon as I finish migrating the Redis Bayes store to Valkey -- which I was reminded I should have done on this box! > What caught my eye was the unusual TLD in the HELO. That would be trivial for a spammer to bypass, but it might help to look for unusual TLDs there as well... hm. missed the HELO. cloud isn't (yet) *globally* banned @ my postfix edge; tho, it teeters on the fence :-/ unlike '.рф', .jetzt' and a host of others that my SA instance never gets to "enjoy" ;-) in any case, I doubt that .cloud is in all the leak-thrus. but there might be a pattern of 'less-if-not-un-common' TLDs. > I will see about adding that to my sandbox tonight or tomorrow, but no guarantees on how it will do in masschecks. > > It might also be time to update my phishing phrases rules... > > Feel free to send me an archive of spamples if you like. Assuming I can convince myself this ain't PEBKAC, I'll see what I can scrounge up. To be fair, tho the absolute counts are high-enough to be annoying, the %-ages are still minuscule.