2.3 CTYPE_001C_A CTYPE_001C_A
0.1 RDNS_NONE Delivered to trusted network by a host with no rDNS 3.3 FH_MSGID_01C67 Special MSGID
0.0 HTML_MESSAGE BODY: HTML included in message
These rules may have been generated.. at least they are not part of the configuration I have on my own machine, which uses standard SA and RulesDuJour rules.
Pretty hefty scores though. It’s pretty rare for a single rule to have a score over 3.
The new rules released by spamassassin team doesn’t seems to have been tested against a corpus of CDOSYS generated mails and it appears to be faking MS-Outlook to spamassassin. I’ve already reduced scores for both of the rules.
If it still affecting your emails?
Bug reports for these rules are already filed by some users and hopefully the scores will be better thought/tested in upcoming releases. Completely agree the scores are too high.
4.1 FH_HOST_ALMOST_IP The host almost looks like an IP addr.
2.5 FRT_TODAY2 BODY: ReplaceTags: Today (2)
3.4 FUZZY_XPILL BODY: Attempt to obfuscate words in spam
4.1 FH_HOST_ALMOST_IP The host almost looks like an IP addr.
1.0 FH_HOST_EQ_DYNAMICIP Host is dynamicip
0.0 HTML_MESSAGE BODY: HTML included in message
0.1 RDNS_DYNAMIC Delivered to trusted network by host with
dynamic-looking rDNS
2.3 DYN_RDNS_SHORT_HELO_HTML Sent by dynamic rDNS, short HELO, and HTML
The rules seems to be appearing in 2 places. I guess i’ll just disable them all and have client rely on dspam alone that seems to be doing way much better job.
2.3 CTYPE_001C_A CTYPE_001C_A
0.1 RDNS_NONE Delivered to trusted network by a host with no
rDNS
3.3 FH_MSGID_01C67 Special MSGID
0.0 HTML_MESSAGE BODY: HTML included in message
2.5 MPART_ALT_DIFF BODY: HTML and text parts are different