DSPAM SPAM & False Positives

eehost

Perch
This seems a little odd. Last night I received 2 messages coming from [email protected]l. My e-mail is not on the visible "To" and the attached original message (from SpamAssasin) is called original message before SpamAssasin.eml.

Why would a spammer be using an account @dspam1.local now?

Here's the mail:

Spam detection software, running on the system "mail6.m****here.biz", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
the administrator of that system for details.

Content preview: Attention men! By taking just one simple pill per day (filled
with a scientific formulation of ALL NATURAL ingredients) you can improve
your sex life dramatically. Achieve greater physical stamina, larger and
harder ohZerectionSpamions, greater ejaculatory control (extremely effective for those
who have premature ejaculation issues), more enjoyable orgasms and greatly
improved sexual performance overall. [...]

Content analysis details: (26.6 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
1.0 DSPAM_BOUNCE_FROM DSPAM_BOUNCE_FROM
20 DSPAM_SPAM "dspam marked spam"
1.0 HEADER_COUNT_SUBJECT Multiple Subject headers found
2.1 IMPOTENCE BODY: Impotence cure
1.3 ALL_NATURAL BODY: Spam is 100% natural?!
0.8 MONEY_BACK BODY: Money back guarantee
0.3 MAILTO_TO_SPAM_ADDR URI: Includes a link to a likely spammer email

===

Also, most SPAM marked as DSPAM are false positives. What can I do about that?

Thank you very much.
 
The MTA on anti-spam gateway(postfix) tries to correct any problems in sender address and this is why you see dspam.local appended. For false positives, kindly report via a ticket as you have been doing.
 
Back
Top