Re: HTML_FONT_SIZE_HUGE firing on html that looks ok

Greg Troxel <[email protected]> Mon, 11 May 2026 21:54:23 -0400
Newsgroups gmane.mail.spam.spamassassin.general
Message-ID <[email protected]>
--=-=-=
Content-Type: text/plain

Matija Nalis <[email protected]> writes:

> On Mon, May 11, 2026 at 06:45:03PM -0400, Greg Troxel wrote:
>> Well, it's not ok to send html mail at all.  But I just got a non-spam,
>> actual messages from a human, that other than being html, was not at all
>> spammy.  The HTML_FONT_SIZE_HUGE rule fired.
>
> OK... and why do you think it is a problem? To wit:

I happen to score that up a bit.  That's my issue.

It's a problem because it's asserting something about the message that
is not true and makes no sense.  That's a bug even if the default config
only counts it for one millipoint.

>> I can't post the whole message, but there is
>
> Well, perhaps you should create minimal representative example then.

Thanks for pushing me to do that.  I went through and trimmed and
trimmed, checking each time, and converted identifiers to dummy values.
The result is super short and it still fires.

> At quick glance, Mail/SpamAssassin/HTML.pm (at least in 3.4.6 version
> of SA) does not trigger on CSS style "font-size: *pt" at all, but
> e.g. on (deprecated) HTML "<font size=*>" which is totally different
> metric from "pt", and can range from 1 to 7 (with 3 being "default text size").

Ah, that's what I semi-remember.  Thanks for the doc pointer.

I have attached my "hample" at end as application/octet-stream so it
will arrive unmunged.

Rerunning with -t, I get the following output:

  Content analysis details:   (5.5 points, 1.0 required)

   pts rule name              description
  ---- ---------------------- --------------------------------------------------
  -0.0 RCVD_IN_DNSWL_NONE     RBL: Sender listed at https://www.dnswl.org/, no
                              trust
                              [2607:f8b0:4864:20:0:0:0:1133 listed in]
                              [list.dnswl.org]
   1.9 SPF_FAIL               SPF: sender does not match SPF record (fail)
                              [SPF failed: Rejected by SPF record.]
   0.0 SPF_HELO_NONE          SPF: HELO does not publish an SPF Record
   0.1 MSGID_PROD_OUTLOOK     Message-Id from prod.outlook.com
   1.0 HTML_FONT_SIZE_HUGE    BODY: HTML font size is huge
   0.1 HTML_MESSAGE           BODY: HTML included in message
   1.8 DMARC_REJECT           DMARC reject policy
   0.6 TXREP                  TXREP: Score normalizing based on sender's reputation

The SPF and DMARC are because I've messed with identifiers, so we should
ignore that.

MSGID_PROD_OUTLOOK is a personal meta-rule building block.
TXREP, well I've been messing with it.

But the big deal is I'm still getting HTML_FONT_SIZE_HUGE.

In the stderr with -D

  May 11 21:50:45.236 [29438] dbg: rules: ran eval rule HTML_FONT_SIZE_HUGE ======> got hit (1)


SA 4.0.2, perl 5.42.2, NetBSD 10 amd64.  sa-update nightly: rule files
have mod time of 0500 EDT today.  This setup otherwise works well.


--=-=-=
Content-Type: application/octet-stream
Content-Disposition: attachment; filename=ham.000
Content-Transfer-Encoding: base64

UmV0dXJuLVBhdGg6IDxnZW9yZ2VAZXhhbXBsZS5vcmc+ClJlY2VpdmVkOiBmcm9tIG1haWwteXcx
LXgxMTMzLmdvb2dsZS5jb20gKG1haWwteXcxLXgxMTMzLmdvb2dsZS5jb20gW0lQdjY6MjYwNzpm
OGIwOjQ4NjQ6MjA6OjExMzNdKQoJYnkgbXguZXhhbXBsZS5uZXQgKFBvc3RmaXgpIHdpdGggRVNN
VFBTIGlkIGFyYml0cmFyeUlECglmb3IgPHJpY2hhcmRAZXhhbXBsZS5uZXQ+OyBNb24sIDExIE1h
eSAyMDI2IDE4OjAwOjAyIC0wNDAwIChFRFQpCkZyb206IEdlb3JnZSBXYXNoaW5ndG9uIDxnZW9y
Z2VAZXhhbXBsZS5vcmc+ClRvOiBSaWNoYXJkIE5peG9uIDxyaWNoYXJkQGV4YW1wbGUubmV0PgpT
dWJqZWN0OiBEdW1teSBzdWJqZWN0IHRleHQKRGF0ZTogTW9uLCAxMSBNYXkgMjAyNiAyMjowMDow
MCArMDAwMApNZXNzYWdlLUlEOiA8YXJiaXRyYXJ5LW1lc3NhZ2UtaWRAc3ViZG9tYWluLmZvby5w
cm9kLm91dGxvb2suY29tPgpDb250ZW50LVR5cGU6IG11bHRpcGFydC9hbHRlcm5hdGl2ZTsKCWJv
dW5kYXJ5PSJBcmJpdHJhcnlNaW1lQm91bmRhcnlTdHJpbmciCk1JTUUtVmVyc2lvbjogMS4wCgot
LUFyYml0cmFyeU1pbWVCb3VuZGFyeVN0cmluZwpDb250ZW50LVR5cGU6IHRleHQvcGxhaW4KQ29u
dGVudC1UcmFuc2Zlci1FbmNvZGluZzogcXVvdGVkLXByaW50YWJsZQoKRHVtbXkgYm9keSB0ZXh0
LgoKLS1BcmJpdHJhcnlNaW1lQm91bmRhcnlTdHJpbmcKQ29udGVudC1UeXBlOiB0ZXh0L2h0bWwK
Q29udGVudC1UcmFuc2Zlci1FbmNvZGluZzogcXVvdGVkLXByaW50YWJsZQoKPGh0bWw+Cjxib2R5
PgpEdW1teSBib2R5IHRleHQuCjwvYm9keT4KPC9odG1sPgoKLS1BcmJpdHJhcnlNaW1lQm91bmRh
cnlTdHJpbmctLQo=
--=-=-=--