SA is inventing URIs

Alex <[email protected]> Sat, 20 Jun 2026 17:08:44 -0400
Newsgroups gmane.mail.spam.spamassassin.general
Message-ID <CAB1R3sgrfZM+emm5ueBE5ZmWxE0hBrTHpYAdDTfu4hX5XSgB6w@mail.gmail.com>
--00000000000033fbf50654b5d157
Content-Type: text/plain; charset="UTF-8"

SpamAssassin 4.0.3 appears to incorrectly promote a URL query
parameter value into a standalone URI hostname and then performs
URIDNSBL lookups against the generated domain.

Observed behavior:

Input message contains only the following URI:

https://substack.com/signup?r=to8ex

Debug output shows SpamAssassin correctly parsing the original URI:

Jun 20 17:04:48.788 dbg: uri: canonicalizing parsed uri:
https://substack.com/signup?r=to8ex
Jun 20 17:04:48.788 dbg: uri: cleaned uri: https://substack.com/signup?r=to8ex
Jun 20 17:04:48.788 dbg: uri: added host: substack.com domain: substack.com

Immediately afterward, SpamAssassin creates a second URI which does
not exist in the message:

Jun 20 17:04:48.821 dbg: uri: canonicalizing parsed uri: http://to8ex
Jun 20 17:04:48.822 dbg: uri: cleaned uri: http://to8ex
Jun 20 17:04:48.822 dbg: uri: cleaned uri: http://www.to8ex.com
Jun 20 17:04:48.822 dbg: uri: added host: www.to8ex.com domain: to8ex.com

SpamAssassin then performs URIDNSBL lookups against the generated domain:

Jun 20 17:04:48.836 dbg: uridnsbl: considering host=www.to8ex.com,
domain=to8ex.com

Expected behavior:

The query parameter value "to8ex" should remain data associated with the URI:

https://substack.com/signup?r=to8ex

No standalone hostname or domain should be generated from the parameter value.

--00000000000033fbf50654b5d157
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><pre class=3D"gmail-overflow-visible! gmail-px-0!"><div cl=
ass=3D"gmail-relative gmail-w-full gmail-mt-4 gmail-mb-1"><div class=3D"gma=
il-"><div class=3D"gmail-contents"><div class=3D"gmail-relative"><div class=
=3D"gmail-h-full gmail-min-h-0 gmail-min-w-0"><div class=3D"gmail-h-full gm=
ail-min-h-0 gmail-min-w-0"><div class=3D"gmail-border gmail-border-token-bo=
rder-light gmail-border-radius-3xl gmail-corner-superellipse/1.1 gmail-roun=
ded-3xl"><div class=3D"gmail-h-full gmail-w-full gmail-border-radius-3xl gm=
ail-bg-token-bg-elevated-secondary gmail-corner-superellipse/1.1 gmail-over=
flow-clip gmail-rounded-3xl gmail-lxnfua_clipPathFallback"><div class=3D"gm=
ail-relative"><div class=3D"gmail-pe-11 gmail-pt-3"><div class=3D"gmail-rel=
ative gmail-z-0 gmail-flex gmail-max-w-full"><div id=3D"gmail-code-block-vi=
ewer" dir=3D"ltr" class=3D"gmail-q9tKkq_viewer gmail-cm-editor gmail-z-10 g=
mail-light:cm-light gmail-dark:cm-light gmail-flex gmail-h-full gmail-w-ful=
l gmail-flex-col gmail-items-stretch gmail-=CD=BCd gmail-=CD=BCr"><div clas=
s=3D"gmail-cm-scroller"><pre class=3D"gmail-cm-content gmail-q9tKkq_readonl=
y gmail-m-0"><p class=3D"gmail-isSelectedEnd">SpamAssassin 4.0.3 appears to=
 incorrectly promote a URL query parameter value into a standalone URI host=
name and then performs URIDNSBL lookups against the generated domain.</p><p=
 class=3D"gmail-isSelectedEnd">Observed behavior:</p><p class=3D"gmail-isSe=
lectedEnd">Input message contains only the following URI:</p><p class=3D"gm=
ail-isSelectedEnd"><a href=3D"https://substack.com/signup?r=3Dto8ex">https:=
//substack.com/signup?r=3Dto8ex</a></p><p class=3D"gmail-isSelectedEnd">Deb=
ug output shows SpamAssassin correctly parsing the original URI:</p><p clas=
s=3D"gmail-isSelectedEnd">Jun 20 17:04:48.788 dbg: uri: canonicalizing pars=
ed uri: <a href=3D"https://substack.com/signup?r=3Dto8ex">https://substack.=
com/signup?r=3Dto8ex</a><br>Jun 20 17:04:48.788 dbg: uri: cleaned uri: <a h=
ref=3D"https://substack.com/signup?r=3Dto8ex">https://substack.com/signup?r=
=3Dto8ex</a><br>Jun 20 17:04:48.788 dbg: uri: added host: <a href=3D"http:/=
/substack.com">substack.com</a> domain: <a href=3D"http://substack.com">sub=
stack.com</a></p><p class=3D"gmail-isSelectedEnd">Immediately afterward, Sp=
amAssassin creates a second URI which does not exist in the message:</p><p =
class=3D"gmail-isSelectedEnd">Jun 20 17:04:48.821 dbg: uri: canonicalizing =
parsed uri: <a href=3D"http://to8ex">http://to8ex</a><br>Jun 20 17:04:48.82=
2 dbg: uri: cleaned uri: <a href=3D"http://to8ex">http://to8ex</a><br>Jun 2=
0 17:04:48.822 dbg: uri: cleaned uri: <a href=3D"http://www.to8ex.com/">htt=
p://www.to8ex.com</a><br>Jun 20 17:04:48.822 dbg: uri: added host: <a href=
=3D"http://www.to8ex.com/">www.to8ex.com</a> domain: <a href=3D"http://to8e=
x.com">to8ex.com</a></p><p class=3D"gmail-isSelectedEnd">SpamAssassin then =
performs URIDNSBL lookups against the generated domain:</p><p class=3D"gmai=
l-isSelectedEnd">Jun 20 17:04:48.836 dbg: uridnsbl: considering host=3D<a h=
ref=3D"http://www.to8ex.com/">www.to8ex.com</a>, domain=3D<a href=3D"http:/=
/to8ex.com">to8ex.com</a></p><p class=3D"gmail-isSelectedEnd">Expected beha=
vior:</p><p class=3D"gmail-isSelectedEnd">The query parameter value &quot;t=
o8ex&quot; should remain data associated with the URI:</p><p class=3D"gmail=
-isSelectedEnd"><a href=3D"https://substack.com/signup?r=3Dto8ex">https://s=
ubstack.com/signup?r=3Dto8ex</a></p><p class=3D"gmail-isSelectedEnd">No sta=
ndalone hostname or domain should be generated from the parameter value.</p=
><p></p></pre></div></div></div></div></div></div></div></div></div></div><=
/div></div></div></pre></div>

--00000000000033fbf50654b5d157--