Our mail servers rely on a ' spam filter check ' to identify and filter out spam email messages for our clients. We run various criteria tests to determine an overall score for spam. The email is marked as spam if an overall spam score is too high.
In addition to our checks, we first check to see if the domain / IP the email is being sent from is 'blacklisted'. If your domain or server IP appears on a blacklist, you should aim to have this removed, as you will encounter email delivery issues with others, also. You can check to see if your domain or IP is blacklisted here: https://mxtoolbox.com/blacklists.aspx
If the Blacklist check is passed, the following test looks at the email content itself. Does the email contain unsupported HTML code, such as scripts and forms? Are embedded images present? Does the email have common spam phrases like "Viagra, Pills, Free, SEO, Money etc"?
As part of the Spam filter test, we also check 'SPF records to see if the email is sent from the source it claims to be from. This helps to reduce incoming mail which has been spoofed... i.e. someone sending an email from "joebloggs@hotmail.com" (hotmail.com) but in fact, the email is sent from "joebloggs@spoofemail.com" (spoofmail.com).
If your email is marked as spam and returned to you, you may be asked to confirm that you are a valid sender by clicking a link. If your email is a high-spam score email, it will be deleted without notice to you or the recipient.
SpamAssassin and Config Server check for spam on all DigitalFlare servers. We can manually white-list emails and domains if any email is consistently blocked. Please get in touch with our team via our contact page to arrange this. Below is a list of checks we make before we deliver an email. If your email is blocked, please check that the criteria below are unmet.
If you have any questions about spam, please contact us. You are responsible for following up on any essential emails with a telephone call or postal letter to ensure the recipient has received the email. We will not be held responsible for emails not delivered due to automatic spam filtering.
Area | Test Description | Test Name | Score |
body | Generic Test for Unsolicited Bulk Email | GTUBE | 1000 |
body | Incorporates a tracking ID number | TRACKER_ID | 2.026 |
body | Weird repeated double-quotation marks | WEIRD_QUOTING | 0.001 |
body | The body contains a ROT13-encoded email address | EMAIL_ROT13 | 1 |
body | HTML and text parts are different | MPART_ALT_DIFF | 2.246 |
body | HTML and text parts are different | MPART_ALT_DIFF_COUNT | 2.799 |
body | The message body has 80-90% blank lines | BLANK_LINES_80_90 | 1 |
body | eval:check_ma_non_text() | MULTIPART_ALT_NON_TEXT | 1 |
body | Character set indicates a foreign language | CHARSET_FARAWAY | 3.2 |
rawbody | Extra blank lines in base64 encoding | MIME_BASE64_BLANKS | 0.001 |
rawbody | Message text disguised using base64 encoding | MIME_BASE64_TEXT | 0.001 |
body | Missing blank line between MIME header and body | MISSING_MIME_HB_SEP | 0.001 |
body | Multipart messages mostly text/html MIME | MIME_HTML_MOSTLY | 0.354 |
body | Message only has text/html MIME parts | MIME_HTML_ONLY | 2.199 |
rawbody | Quoted-printable line longer than 76 chars | MIME_QP_LONG_LINE | 0.001 |
body | MIME character set is an unknown ISO charset | MIME_BAD_ISO_CHARSET | 1 |
body | IP to HTTPS link found in HTML | HTTPS_IP_MISMATCH | 1 |
body | The message contained a URI which was truncated | URI_TRUNCATED | 0.001 |
header | Passed through trusted hosts only via SMTP | ALL_TRUSTED | -1 |
header | Informational: the message was not relayed via SMTP | NO_RELAYS | -0.001 |
header | NJABL: sender is confirmed the open relay | RCVD_IN_NJABL_RELAY | 0 |
header | NJABL: sender is a confirmed spam source | RCVD_IN_NJABL_SPAM | 0 |
header | NJABL: sent through multi-stage open relay | RCVD_IN_NJABL_MULTI | 1 |
header | NJABL: sender is an open formmail | RCVD_IN_NJABL_CGI | 1 |
header | NJABL: sender is an open proxy | RCVD_IN_NJABL_PROXY | 0 |
header | SORBS: sender is open HTTP proxy server | RCVD_IN_SORBS_HTTP | 0 |
header | SORBS: sender is open SOCKS proxy server | RCVD_IN_SORBS_SOCKS | 0 |
header | SORBS: sender is an open proxy server | RCVD_IN_SORBS_MISC | 1 |
header | SORBS: sender is open SMTP relay | RCVD_IN_SORBS_SMTP | 1 |
header | SORBS: sender is an abusable web server | RCVD_IN_SORBS_WEB | 0 |
header | SORBS: sender demands never to be tested | RCVD_IN_SORBS_BLOCK | 1 |
header | SORBS: sender is on a hijacked network | RCVD_IN_SORBS_ZOMBIE | 1 |
header | SORBS: sent directly from dynamic IP address | RCVD_IN_SORBS_DUL | 0 |
header | Received via a relay in Spamhaus SBL | RCVD_IN_SBL | 0 |
header | Received via a relay in Spamhaus XBL | RCVD_IN_XBL | 0 |
header | Received via a relay in Spamhaus PBL | RCVD_IN_PBL | 0 |
header | Envelope sender in dsn.rfc-ignorant.org | DNS_FROM_RFC_DSN | 0 |
header | Envelope sender in bogusmx.rfc-ignorant.org | DNS_FROM_RFC_BOGUSMX | 0 |
header | The envelope sender is listed in dnsbl.ahbl.org | DNS_FROM_AHBL_RHSBL | 0 |
header | Received via a relay in bl.spamcop.net | RCVD_IN_BL_SPAMCOP_NET | 0 |
header | Relay in RBL, http://www.mail-abuse.com/enduserinfo_rbl.html | RCVD_IN_MAPS_RBL | 1 |
header | Relay in DUL, http://www.mail-abuse.com/enduserinfo_dul.html | RCVD_IN_MAPS_DUL | 1 |
header | Relay in RSS, http://www.mail-abuse.com/enduserinfo_rss.html | RCVD_IN_MAPS_RSS | 1 |
header | Relay in OPS, http://www.mail-abuse.com/enduserinfo_ops.html | RCVD_IN_MAPS_OPS | 1 |
header | Relay in NML, http://www.mail-abuse.com/enduserinfo_nml.html | RCVD_IN_MAPS_NML | 1 |
header | ISIPP IADB lists as vouched-for sender | RCVD_IN_IADB_VOUCHED | 0 |
header | The subject contains a gappy version of 'Cialis.' | SUBJECT_DRUG_GAP_C | 2.108 |
header | The subject contains a gappy version of 'Levitra.' | SUBJECT_DRUG_GAP_L | 2.799 |
header | The subject contains a gappy version of 'Soma.' | SUBJECT_DRUG_GAP_S | 1 |
header | The subject contains a gappy version of 'valium.' | SUBJECT_DRUG_GAP_VA | 1 |
header | The subject contains a gappy version of 'Xanax' | SUBJECT_DRUG_GAP_X | 1 |
body | Talks about price per dose | DRUG_DOSAGE | 1 |
body | Mentions an E.D. drug | DRUG_ED_CAPS | 2.799 |
body | It talks about an E.D. drug using its chemical name | DRUG_ED_SILD | 0.001 |
body | Mentions Generic Viagra | DRUG_ED_GENERIC | 1 |
body | Fast Viagra Delivery | DRUG_ED_ONLINE | 0.696 |
body | Online Pharmacy | ONLINE_PHARMACY | 0.843 |
body | No prescription needed | NO_PRESCRIPTION | 1.915 |
body | Attempts to disguise the word 'Viagra.' | VIA_GAP_GRA | 1 |
body | Two or more drugs crammed together into one word | DRUGS_SMEAR1 | 3.3 |
header | Relay HELO'd with suspicious hostname (mail.com) | FAKE_HELO_MAIL_COM_DOM | 1.887 |
header | Relay HELO'd using a suspicious hostname (Rogers) | HELO_DYNAMIC_ROGERS | 1 |
header | Relay HELO'd using a suspicious hostname (T-Dialin) | HELO_DYNAMIC_DIALIN | 2.629 |
header | Relay HELO'd using a suspicious hostname (Hex IP) | HELO_DYNAMIC_HEXIP | 2.321 |
header | Relay HELO'd using the suspicious hostname (Split IP) | HELO_DYNAMIC_SPLIT_IP | 3.031 |
header | Relay HELO'd using the suspicious hostname (IP address 2) | HELO_DYNAMIC_IPADDR2 | 2.815 |
header | Relay HELO'd using a suspicious hostname (Chello.nl) | HELO_DYNAMIC_CHELLO_NL | 2.412 |
header | Relay HELO'd using a suspicious hostname (Home.nl) | HELO_DYNAMIC_HOME_NL | 2.385 |
header | The sender Email is freemail | FREEMAIL_FROM | 0.001 |
header | Envelope-from freemail username ends in a digit | FREEMAIL_ENVFROM_END_DIGIT | 2.602 |
header | Reply-To freemail username ends in a digit | FREEMAIL_REPLYTO_END_DIGIT | 1.221 |
header | Partial message | FRAGMENTED_MESSAGE | 1 |
header | From: contains an empty name | FROM_BLANK_NAME | 2.099 |
header | From: starts with many numbers | FROM_STARTS_WITH_NUMS | 2.801 |
header | From Address is "at something-offers" | FROM_OFFERS | 2.699 |
header | From: has no local-part before @ sign | FROM_NO_USER | 0.001 |
header | Spam tool Message-Id: (caps variant) | MSGID_SPAM_CAPS | 2.366 |
header | Spam tool Message-Id: (letters variant) | MSGID_SPAM_LETTERS | 1 |
header | Message-ID has ALLCAPS@yahoo.com | MSGID_YAHOO_CAPS | 0.797 |
header | Message ID is unusually short | MSGID_SHORT | 0.001 |
header | Message-ID contains multiple '@' characters | MSGID_MULTIPLE_AT | 0.001 |
header | Date header uses unusual Y2K formatting | DATE_SPAMWARE_Y2K | 1 |
header | Invalid Date: header (not RFC 2822) | INVALID_DATE | 1.701 |
header | Invalid Date: header (timezone does not exist) | INVALID_DATE_TZ_ABSURD | 0.262 |
header | Invalid date in header (wrong CST timezone) | INVALID_TZ_CST | 1 |
header | Invalid date in header (wrong EST timezone) | INVALID_TZ_EST | 1 |
header | Subject contains an English UCE tag | ENGLISH_UCE_SUBJECT | 0.953 |
header | Subject contains a Japanese UCE tag | JAPANESE_UCE_SUBJECT | 1 |
header | Subject: contains Korean unsolicited email tag | KOREAN_UCE_SUBJECT | 1 |
header | Contains forged hostname for a DSL IP in Brazil | FORGED_TELESP_RCVD | 2.499 |
header | Character set doesn't exist | NONEXISTENT_CHARSET | 1 |
header | Message has Prevent-NonDelivery-Report header | PREVENT_NONDELIVERY | 1 |
header | Message has X-IP header | X_IP | 0.001 |
header | Subject contains "As Seen" | SUBJ_AS_SEEN | 2.711 |
header | Subject starts with dollar amount | SUBJ_DOLLARS | 0.6 |
header | Subject contains "Your Bills" or similar | SUBJ_YOUR_DEBT | 3.299 |
header | Subject contains "Your Family" | SUBJ_YOUR_FAMILY | 2.91 |
header | Received contains a faked HELO hostname | RCVD_FAKE_HELO_DOTCOM | 2.799 |
header | Subject talks about losing pounds | SUBJECT_DIET | 1.927 |
header | Header has extraneous Content-type:...type= entry | EXTRA_MPART_TYPE | 1 |
header | Spam tool pattern in MIME boundary | MIME_BOUND_DD_DIGITS | 3.016 |
header | Spam tool pattern in MIME boundary | MIME_BOUND_DIGITS_15 | 0.432 |
header | Spam tool pattern in MIME boundary | MIME_BOUND_MANY_HEX | 1 |
header | To: has a malformed address | TO_MALFORMED | 0.892 |
header | Received line contains spam-sign (lowercase smtp) | WITH_LC_SMTP | 1 |
header | Subject line starts with Buy or Buying | SUBJ_BUY | 0.594 |
header | Received headers forged (AM/PM) | RCVD_AM_PM | 1 |
header | Received header contains faked 'mr.outblaze.com' | FAKE_OUTBLAZE_RCVD | 1 |
header | Headers contain an unclosed bracket | UNCLOSED_BRACKET | 2.699 |
header | From: domain has series of non-vowel letters | FROM_DOMAIN_NOVOWEL | 0.5 |
header | From: localpart has series of non-vowel letters | FROM_LOCAL_NOVOWEL | 0.5 |
header | From: localpart has long hexadecimal sequence | FROM_LOCAL_HEX | 0 |
header | From: localpart has long digit sequence | FROM_LOCAL_DIGITS | 0.001 |
header | Cc: after X-Priority: (bulk email fingerprint) | X_PRIORITY_CC | 1 |
header | Message has bad MIME encoding in the header | BAD_ENC_HEADER | 3.099 |
header | Received: contains illegal IP address | RCVD_ILLEGAL_IP | 3.399 |
header | A foreign language charset used in headers | CHARSET_FARAWAY_HEADER | 3.2 |
header | From: has too many raw illegal characters | FROM_ILLEGAL_CHARS | 2.192 |
header | Headers have too many raw illegal characters | HEAD_ILLEGAL_CHARS | 1 |
header | hotmail.com 'From' address, but no 'Received:' | FORGED_HOTMAIL_RCVD2 | 0.001 |
header | From' yahoo.com does not match 'Received' headers | FORGED_YAHOO_RCVD | 2.397 |
header | Recipient list is sorted by Address | SORTED_RECIPS | 1.801 |
header | Similar addresses in recipient list | SUSPICIOUS_RECIPS | 2.499 |
header | Missing To: header | MISSING_HEADERS | 0.915 |
header | Date: is 3 to 6 hours before Received: date | DATE_IN_PAST_03_06 | 2.399 |
header | Date: is 6 to 12 hours before Received: date | DATE_IN_PAST_06_12 | 1.699 |
header | Date: is 12 to 24 hours before Received: date | DATE_IN_PAST_12_24 | 0.001 |
header | Date: is 24 to 48 hours before Received: date | DATE_IN_PAST_24_48 | 1.109 |
header | Date: is 96 hours or more before Received: date | DATE_IN_PAST_96_XX | 2.6 |
header | Date: is 3 to 6 hours after Received: date | DATE_IN_FUTURE_03_06 | 3.399 |
header | Date: is 6 to 12 hours after Received: date | DATE_IN_FUTURE_06_12 | 2.899 |
header | Date: is 12 to 24 hours after Received: date | DATE_IN_FUTURE_12_24 | 2.603 |
header | Date: is 24 to 48 hours after Received: date | DATE_IN_FUTURE_24_48 | 2.598 |
header | Date: is 48 to 96 hours after Received: date | DATE_IN_FUTURE_48_96 | 2.384 |
header | Date: is 96 hours or more after Received: date | DATE_IN_FUTURE_96_XX | 2.614 |
header | Headers contain an unresolved template | UNRESOLVED_TEMPLATE | 3.035 |
header | Subject is all capitals | SUBJ_ALL_CAPS | 0.518 |
header | Local part of To: address appears in Subject | LOCALPART_IN_SUBJECT | 0.001 |
header | Message-Id is fake (in Outlook Express format) | MSGID_OUTLOOK_INVALID | 3.899 |
header | Multiple Content-Type headers found | HEADER_COUNT_CTYPE | 1 |
header | Message headers are very long | HEAD_LONG | 1 |
header | Missing blank line between message header and body | MISSING_HB_SEP | 1 |
header | Informational: message has unparseable relay lines | UNPARSEABLE_RELAY | 0.001 |
header | Received: HELO and IP do not match, but should | RCVD_HELO_IP_MISMATCH | 1.68 |
header | Received: contains an IP address used for HELO | RCVD_NUMERIC_HELO | 0.001 |
header | Host HELO'd as a big ISP, but had no rDNS | NO_RDNS_DOTCOM_HELO | 3.1 |
rawbody | Javascript to hide URLs in browser | HIDE_WIN_STATUS | 0.001 |
body | HTML included in message | HTML_MESSAGE | 0.001 |
body | HTML comment is very short | HTML_COMMENT_SHORT | 1 |
body | HTML message is a saved web page | HTML_COMMENT_SAVED_URL | 0.198 |
body | HTML with embedded plugin object | HTML_EMBEDS | 0.001 |
body | HTML contains far too many close tags | HTML_EXTRA_CLOSE | 0.001 |
body | HTML font size is large | HTML_FONT_SIZE_LARGE | 0.001 |
body | HTML font size is huge | HTML_FONT_SIZE_HUGE | 0.001 |
body | HTML font color similar to background | HTML_FONT_LOW_CONTRAST | 0.713 |
body | HTML font face is not a word | HTML_FONT_FACE_BAD | 0.001 |
body | HTML includes a form which sends mail | HTML_FORMACTION_MAILTO | 1 |
body | HTML: images with 0-400 bytes of words | HTML_IMAGE_ONLY_04 | 1.68 |
body | HTML: images with 400-800 bytes of words | HTML_IMAGE_ONLY_08 | 0.585 |
body | HTML: images with 800-1200 bytes of words | HTML_IMAGE_ONLY_12 | 1.381 |
body | HTML: images with 1200-1600 bytes of words | HTML_IMAGE_ONLY_16 | 1.969 |
body | HTML: images with 1600-2000 bytes of words | HTML_IMAGE_ONLY_20 | 2.109 |
body | HTML: images with 2000-2400 bytes of words | HTML_IMAGE_ONLY_24 | 2.799 |
body | HTML: images with 2400-2800 bytes of words | HTML_IMAGE_ONLY_28 | 2.799 |
body | HTML: images with 2800-3200 bytes of words | HTML_IMAGE_ONLY_32 | 2.196 |
body | HTML has a low ratio of text to image area | HTML_IMAGE_RATIO_02 | 2.199 |
body | HTML has a low ratio of text to image area | HTML_IMAGE_RATIO_04 | 2.089 |
body | HTML has a low ratio of text to image area | HTML_IMAGE_RATIO_06 | 0.001 |
body | HTML has a low ratio of text to image area | HTML_IMAGE_RATIO_08 | 0.001 |
body | Message is 5% to 10% HTML obfuscation | HTML_OBFUSCATE_05_10 | 0.601 |
body | Message is 10% to 20% HTML obfuscation | HTML_OBFUSCATE_10_20 | 0.174 |
body | Message is 20% to 30% HTML obfuscation | HTML_OBFUSCATE_20_30 | 2.499 |
body | Message is 30% to 40% HTML obfuscation | HTML_OBFUSCATE_30_40 | 1 |
body | Message is 50% to 60% HTML obfuscation | HTML_OBFUSCATE_50_60 | 1 |
body | Message is 70% to 80% HTML obfuscation | HTML_OBFUSCATE_70_80 | 1 |
body | Message is 90% to 100% HTML obfuscation | HTML_OBFUSCATE_90_100 | 1 |
body | HTML has unbalanced "body" tags | HTML_TAG_BALANCE_BODY | 1.247 |
body | HTML has unbalanced "head" tags | HTML_TAG_BALANCE_HEAD | 0.52 |
body | HTML has "bgsound" tag | HTML_TAG_EXIST_BGSOUND | 1 |
body | HTML message is 40% to 50% bad tags | HTML_BADTAG_40_50 | 1 |
body | HTML message is 50% to 60% bad tags | HTML_BADTAG_50_60 | 1 |
body | HTML message is 60% to 70% bad tags | HTML_BADTAG_60_70 | 1 |
body | HTML message is 90% to 100% bad tags | HTML_BADTAG_90_100 | 1 |
body | 30% to 40% of HTML elements are non-standard | HTML_NONELEMENT_30_40 | 0 |
body | 40% to 50% of HTML elements are non-standard | HTML_NONELEMENT_40_50 | 1 |
body | 60% to 70% of HTML elements are non-standard | HTML_NONELEMENT_60_70 | 1 |
body | 80% to 90% of HTML elements are non-standard | HTML_NONELEMENT_80_90 | 1 |
body | Message has HTML IFRAME tag with SRC URI | HTML_IFRAME_SRC | 1 |
header | Envelope sender has no MX or A DNS records | NO_DNS_FOR_FROM | 0 |
body | Removal phrase right before a link | REMOVE_BEFORE_LINK | 0.406 |
body | One hundred percent guaranteed | GUARANTEED_100_PERCENT | 2.699 |
body | Dear Friend? That's not very dear! | DEAR_FRIEND | 2.683 |
body | Contains 'Dear (something)' | DEAR_SOMETHING | 1.999 |
body | Talks about lots of money | BILLION_DOLLARS | 0.001 |
body | Claims you can be removed from the list | EXCUSE_4 | 2.399 |
body | Claims you wanted this ad | EXCUSE_24 | 2.799 |
body | Talks about how to be removed from mailings | EXCUSE_REMOVE | 2.907 |
body | Tells you about a strong buy | STRONG_BUY | 1 |
body | Offers a alert about a stock | STOCK_ALERT | 1 |
body | Not registered investment advisor | NOT_ADVISOR | 1 |
body | Prestigious Non-Accredited Universities' | PREST_NON_ACCREDITED | 1 |
body | Information on growing body parts | BODY_ENHANCEMENT | 0.927 |
body | Information on getting larger body parts | BODY_ENHANCEMENT2 | 1.691 |
body | Impotence cure | IMPOTENCE | 1.539 |
body | Talks about a million North American dollars | NA_DOLLARS | 3.599 |
body | Mentions millions of (dollar) ((dollar) NN,NNN,NNN.NN) | US_DOLLARS_3 | 2.599 |
body | Talks about millions of dollars | MILLION_USD | 3.799 |
body | Contains urgent matter | URG_BIZ | 1.75 |
body | Money back guarantee | MONEY_BACK | 2.91 |
body | Free express or no-obligation quote | FREE_QUOTE_INSTANT | 2.7 |
body | Eliminate Bad Credit | BAD_CREDIT | 2.799 |
body | Home refinancing | REFINANCE_YOUR_HOME | 1 |
body | Home refinancing | REFINANCE_NOW | 1 |
body | No Medical Exams | NO_MEDICAL | 2.199 |
body | Lose Weight Spam | DIET_1 | 0.714 |
body | Freedom of a financial nature | FIN_FREE | 2.699 |
body | Stock Disclaimer Statement | FORWARD_LOOKING | 1 |
body | One Time Rip Off | ONE_TIME | 1.84 |
body | Join Millions of Americans | JOIN_MILLIONS | 0.7 |
body | Claims you registered with a partner | MARKETING_PARTNERS | 0.553 |
body | Lowest Price | LOW_PRICE | 0.161 |
body | People just leave money laying around | UNCLAIMED_MONEY | 2.699 |
body | Message seems to contain rot13ed Address | OBSCURED_EMAIL | 1 |
body | Talks about Oprah with an exclamation! | BANG_OPRAH | 1 |
body | Talks about 'acting now' with capitals | ACT_NOW_CAPS | 1.404 |
body | Talks about a bigger drive for sex | MORE_SEX | 2.799 |
body | Something is emphatically guaranteed | BANG_GUAR | 2.202 |
body | Message mentions investment advice | INVESTMENT_ADVICE | 0.2 |
body | Message talks about enhancing men | MALE_ENHANCE | 3.1 |
body | Message says that prices aren't too expensive | PRICES_ARE_AFFORDABLE | 0.794 |
body | Message talks about a replica watch | REPLICA_WATCH | 3.487 |
body | Message puts emphasis on the watch manufacturer | EM_ROLEX | 0.595 |
body | Possible porn - Free Porn | FREE_PORN | 1 |
body | Possible porn - Cum Shot | CUM_SHOT | 1 |
body | Possible porn - Live Porn | LIVE_PORN | 1 |
header | Subject indicates sexually-explicit content | SUBJECT_SEXUAL | 1 |
header | Bulk email fingerprint (eGroups) found | RATWARE_EGROUPS | 1.898 |
header | X-Mailer has malformed Outlook Express version | RATWARE_OE_MALFORMED | 1 |
header | Bulk email fingerprint (Mozilla malformed) found | RATWARE_MOZ_MALFORMED | 1 |
header | Bulk email fingerprint (mPOP Web-Mail) | RATWARE_MPOP_WEBMAIL | 1.153 |
rawbody | Contains a hashbuster in Send-Safe format | RATWARE_HASH_DASH | 1 |
header | Bulk email fingerprint (Gecko faked) found | RATWARE_GECKO_BUILD | 1 |
header | Bulk email fingerprint (X-Message-Info) found | X_MESSAGE_INFO | 1 |
header | Bulk email fingerprint (header-based) found | HEADER_SPAM | 2.499 |
header | Bulk email fingerprint (Received PF) found | RATWARE_RCVD_PF | 1 |
header | Bulk email fingerprint (Received @) found | RATWARE_RCVD_AT | 1 |
header | Bulk email fingerprint (envfrom) found | RATWARE_EFROM | 2.999 |
uri | High code page | HIGH_CODEPAGE_URI | 1 |
uri | Uses a numeric IP address in URL | NUMERIC_HTTP_ADDR | 0 |
uri | Uses %-escapes inside a URL's hostname | HTTP_ESCAPED_HOST | 0.807 |
uri | Completely unnecessary %-escapes inside a URL | HTTP_EXCESSIVE_ESCAPES | 0.001 |
uri | Dotted-decimal IP address followed by CGI | IP_LINK_PLUS | 0.001 |
uri | Uses non-standard port number for HTTP | WEIRD_PORT | 0.001 |
uri | Has Yahoo Redirect URI | YAHOO_RD_REDIR | 1 |
uri | Has Yahoo Redirect URI | YAHOO_DRS_REDIR | 1 |
uri | Contains an URL-encoded hostname (HTTP77) | HTTP_77 | 1 |
uri | URI contains ".com" in middle | SPOOF_COM2OTH | 2.999 |
uri | URI contains ".com" in middle and end | SPOOF_COM2COM | 0.001 |
uri | URI contains ".net" or ".org", then ".com" | SPOOF_NET2COM | 1 |
uri | URI hostname has long hexadecimal sequence | URI_HEX | 2.8 |
uri | URI hostname has long non-vowel sequence | URI_NOVOWEL | 0.5 |
uri | URI contains suspicious unsubscribe link | URI_UNSUBSCRIBE | 1 |
uri | CGI in .info TLD other than third-level "www" | URI_NO_WWW_INFO_CGI | 2.299 |
uri | CGI in .biz TLD other than third-level "www" | URI_NO_WWW_BIZ_CGI | 2.399 |
uri | Uses a dotted-decimal IP address in URL | NORMAL_HTTP_TO_IP | 0.159 |
body | Bayes spam probability is 0 to 1% | BAYES_00 | 0 |
body | Bayes spam probability is 1 to 5% | BAYES_05 | 0 |
body | Bayes spam probability is 5 to 20% | BAYES_20 | 0 |
body | Bayes spam probability is 20 to 40% | BAYES_40 | 0 |
body | Bayes spam probability is 40 to 60% | BAYES_50 | 0 |
body | Bayes spam probability is 60 to 80% | BAYES_60 | 0 |
body | Bayes spam probability is 80 to 95% | BAYES_80 | 0 |
body | Bayes spam probability is 95 to 99% | BAYES_95 | 0 |
body | Bayes spam probability is 99 to 100% | BAYES_99 | 0 |
header | Message would have been caught by accessdb | ACCESSDB | 1 |
body | Message includes Microsoft executable program | MICROSOFT_EXECUTABLE | 0.1 |
body | MIME filename does not match content | MIME_SUSPECT_NAME | 0.1 |
full | Listed in DCC | DCC_CHECK | 0 |
full | DCC reputation between 0 and 12 % (mostly ham) | DCC_REPUT_00_12 | 0 |
full | eval:check_dcc_reputation_range(13,19) | DCC_REPUT_13_19 | 0 |
full | DCC reputation between 70 and 89 % | DCC_REPUT_70_89 | 0 |
full | DCC reputation between 90 and 94 % | DCC_REPUT_90_94 | 0 |
full | DCC reputation between 95 and 98 % (mostly spam) | DCC_REPUT_95_98 | 0 |
full | DCC reputation between 99 % or higher (spam) | DCC_REPUT_99_100 | 0 |
full | Message has a DKIM or DK signature, not necessarily valid | DKIM_SIGNED | 0.1 |
full | Message has at least one valid DKIM or DK signature | DKIM_VALID | -0.1 |
full | Message has a valid DKIM or DK signature from author's domain | DKIM_VALID_AU | -0.1 |
header | No valid author signature and domain not in DNS | DKIM_ADSP_NXDOMAIN | 0 |
header | No valid author signature, domain signs all mail and suggests discarding the rest | DKIM_ADSP_DISCARD | 0 |
header | No valid author signature, domain signs all mail | DKIM_ADSP_ALL | 0 |
header | No valid author signature, adsp_override is CUSTOM_LOW | DKIM_ADSP_CUSTOM_LOW | 0.001 |
header | No valid author signature, adsp_override is CUSTOM_MED | DKIM_ADSP_CUSTOM_MED | 0.001 |
header | No valid author signature, adsp_override is CUSTOM_HIGH | DKIM_ADSP_CUSTOM_HIGH | 0.001 |
full | eval:check_dkim_valid() | DKIM_VERIFIED | 1 |
header | eval:check_dkim_testing() | DKIM_POLICY_TESTING | 1 |
header | eval:check_dkim_signsome() | DKIM_POLICY_SIGNSOME | 1 |
header | eval:check_dkim_signall() | DKIM_POLICY_SIGNALL | 1 |
header | Contains valid Hashcash token (20 bits) | HASHCASH_20 | -0.5 |
header | Contains valid Hashcash token (21 bits) | HASHCASH_21 | -0.7 |
header | Contains valid Hashcash token (22 bits) | HASHCASH_22 | -1 |
header | Contains valid Hashcash token (23 bits) | HASHCASH_23 | -2 |
header | Contains valid Hashcash token (24 bits) | HASHCASH_24 | -3 |
header | Contains valid Hashcash token (25 bits) | HASHCASH_25 | -4 |
header | Contains valid Hashcash token (>25 bits) | HASHCASH_HIGH | -5 |
header | Hashcash token already spent in another mail | HASHCASH_2SPEND | 0.1 |
full | Listed in Pyzor (http://pyzor.sf.net/) | PYZOR_CHECK | 0 |
full | Listed in Razor2 (http://razor.sf.net/) | RAZOR2_CHECK | 0 |
full | Razor2 gives confidence level above 50% | RAZOR2_CF_RANGE_51_100 | 0 |
full | Razor2 gives engine 4 confidence level above 50% | RAZOR2_CF_RANGE_E4_51_100 | 0 |
full | Razor2 gives engine 8 confidence level above 50% | RAZOR2_CF_RANGE_E8_51_100 | 0 |
header | Attempt to obfuscate words in Subject: | SUBJECT_FUZZY_MEDS | 1 |
header | Attempt to obfuscate words in Subject: | SUBJECT_FUZZY_CHEAP | 0.641 |
header | Attempt to obfuscate words in Subject: | SUBJECT_FUZZY_PENIS | 1 |
header | Attempt to obfuscate words in Subject: | SUBJECT_FUZZY_TION | 1 |
body | Attempt to obfuscate words in spam | FUZZY_AFFORDABLE | 1 |
body | Attempt to obfuscate words in spam | FUZZY_AMBIEN | 2.199 |
body | Attempt to obfuscate words in spam | FUZZY_BILLION | 1 |
body | Attempt to obfuscate words in spam | FUZZY_CPILL | 0.001 |
body | Attempt to obfuscate words in spam | FUZZY_CREDIT | 1.699 |
body | Attempt to obfuscate words in spam | FUZZY_ERECT | 2.356 |
body | Attempt to obfuscate words in spam | FUZZY_GUARANTEE | 1 |
body | Attempt to obfuscate words in spam | FUZZY_MEDICATION | 1 |
body | Attempt to obfuscate words in spam | FUZZY_MILLION | 2.599 |
body | Attempt to obfuscate words in spam | FUZZY_MONEY | 1 |
body | Attempt to obfuscate words in spam | FUZZY_MORTGAGE | 1 |
body | Attempt to obfuscate words in spam | FUZZY_OBLIGATION | 1 |
body | Attempt to obfuscate words in spam | FUZZY_OFFERS | 1 |
body | Attempt to obfuscate words in spam | FUZZY_PHARMACY | 2.96 |
body | Attempt to obfuscate words in spam | FUZZY_PHENT | 2.799 |
body | Attempt to obfuscate words in spam | FUZZY_PRESCRIPT | 1 |
body | Attempt to obfuscate words in spam | FUZZY_PRICES | 1.821 |
body | Attempt to obfuscate words in spam | FUZZY_REFINANCE | 1 |
body | Attempt to obfuscate words in spam | FUZZY_REMOVE | 1 |
body | Attempt to obfuscate words in spam | FUZZY_ROLEX | 3.399 |
body | Attempt to obfuscate words in spam | FUZZY_SOFTWARE | 1 |
body | Attempt to obfuscate words in spam | FUZZY_THOUSANDS | 1 |
body | Attempt to obfuscate words in spam | FUZZY_VLIUM | 1 |
body | Attempt to obfuscate words in spam | FUZZY_VIOXX | 1 |
body | Attempt to obfuscate words in spam | FUZZY_VPILL | 0.001 |
body | Attempt to obfuscate words in spam | FUZZY_XPILL | 2.202 |
header | SPF: sender matches SPF record | SPF_PASS | -0.001 |
header | SPF: sender does not match SPF record (neutral) | SPF_NEUTRAL | 0 |
header | SPF: sender does not match SPF record (fail) | SPF_FAIL | 0 |
header | SPF: sender does not match SPF record (softfail) | SPF_SOFTFAIL | 0 |
header | SPF: HELO matches SPF record | SPF_HELO_PASS | -0.001 |
header | SPF: HELO does not match SPF record (neutral) | SPF_HELO_NEUTRAL | 0 |
header | SPF: HELO does not match SPF record (fail) | SPF_HELO_FAIL | 0 |
header | SPF: HELO does not match SPF record (softfail) | SPF_HELO_SOFTFAIL | 0 |
body | Message written in an undesired language | UNWANTED_LANGUAGE_BODY | 2.8 |
body | Body includes 8 consecutive 8-bit characters | BODY_8BITS | 1.5 |
body | Contains an URL listed in the SBL blocklist | URIBL_SBL | 0 |
body | Contains an URL listed in the SC SURBL blocklist | URIBL_SC_SURBL | 0 |
body | Contains an URL listed in the WS SURBL blocklist | URIBL_WS_SURBL | 0 |
body | Contains an URL listed in the PH SURBL blocklist | URIBL_PH_SURBL | 0 |
body | Contains an URL listed in the OB SURBL blocklist | URIBL_OB_SURBL | 0 |
body | Contains an URL listed in the AB SURBL blocklist | URIBL_AB_SURBL | 0 |
body | Contains an URL listed in the JP SURBL blocklist | URIBL_JP_SURBL | 0 |
body | Contains an URL listed in the URIBL blacklist | URIBL_BLACK | 0 |
body | Contains an URL listed in the URIBL greylist | URIBL_GREY | 0 |
body | Contains an URL listed in the URIBL redlist | URIBL_RED | 0.001 |
header | From: Address is in the auto white-list | AWL | 1 |
header | Not all rules were run, due to a shortcircuited rule | SHORTCIRCUIT | 1 |
header | From: Address is in the user's black-list | USER_IN_BLACKLIST | 100 |
header | From: Address is in the user's white-list | USER_IN_WHITELIST | -100 |
header | From: Address is in the default white-list | USER_IN_DEF_WHITELIST | -15 |
header | User is listed in 'blacklist_to' | USER_IN_BLACKLIST_TO | 10 |
header | User is listed in 'whitelist_to' | USER_IN_WHITELIST_TO | -6 |
header | User is listed in 'more_spam_to' | USER_IN_MORE_SPAM_TO | -20 |
header | User is listed in 'all_spam_to' | USER_IN_ALL_SPAM_TO | -100 |
header | From: Address is in the user's DKIM whitelist | USER_IN_DKIM_WHITELIST | -100 |
header | From: Address is in the default DKIM white-list | USER_IN_DEF_DKIM_WL | -7.5 |
header | From: Address is in the user's SPF whitelist | USER_IN_SPF_WHITELIST | -100 |
header | From: Address is in the default SPF white-list | USER_IN_DEF_SPF_WL | -7.5 |
header | Subject: contains string in the user's white-list | SUBJECT_IN_WHITELIST | -100 |
header | Subject: contains string in the user's black-list | SUBJECT_IN_BLACKLIST | 100 |
header | From Address contains an apostrophe | APOSTROPHE_FROM | 0.148 |
header | HELO from home - untrusted | AXB_HELO_HOME_UN | 1 |
header | Barbera Fingerprint | AXB_XMID_1212 | 1 |
header | Brunello Fingerprint | AXB_XMID_1510 | 1 |
header | Amarone Fingerprint | AXB_XMID_OEGOESNULL | 1 |
header | Nebbiolo fingerprint | AXB_XM_SENDMAIL_NOT | 1 |
header | Received =~ /(8.12.3 da nor stuldap/8.12.3)/ | AXB_XR_STULDAP | 1 |
body | Talks about banking laws | BANKING_LAWS | 2.399 |
body | eval:check_base64_length('78','79') | BASE64_LENGTH_78_79 | 2.37 |
body | eval:check_base64_length('79') | BASE64_LENGTH_79_INF | 1.379 |
header | Invalid Date | BUG6152_INVALID_DATE_TZ_ABSURD | 1.802 |
header | Content-Type =~ /multipart.{0,200}boundary... | CTYPE_001C_B | 0.001 |
body | /bCurrent Price:/ | CURR_PRICE | 0.001 |
body | Dear Beneficiary: | DEAR_BENEFICIARY | 1 |
body | Message contains Dear email address | DEAR_EMAIL | 1 |
body | /bdear.{1,20}winner/i | DEAR_WINNER | 3.099 |
header | X-mailer pattern common to anal porn site spam | DOS_ANAL_SPAM_MAILER | 1 |
header | Received from the same IP twice in a row (only one external relay; empty or IP helo) | DOS_RCVD_IP_TWICE_C | 2.599 |
uri | Found an asterisk in a URI | DOS_URI_ASTERISK | 1 |
header | Subject =~ /bhoodiab/i | DRUGS_HDIA | 1 |
body | Add / Gain inches | FB_ADD_INCHES | 1 |
body | It's almost sex, but not! | FB_ALMOST_SEX | 1 |
body | Broken AnaTrim phrase. | FB_ANA_TRIM | 1 |
body | Phrase: A_U_N_I | FB_ANUI | 1 |
body | Phrase: [BM]Illi0n | FB_BILLI0N | 1 |
body | Phrase: C0mpany | FB_C0MPANY | 1 |
body | Phrase: can last longer | FB_CAN_LONGER | 1 |
body | Uses a mis-spelled version of cialis. | FB_CIALIS_LEO3 | 1.688 |
body | Looks like double 0 words | FB_DOUBLE_0WORDS | 1 |
body | Phrase: email hier | FB_EMAIL_HIER | 1 |
body | Phrase: extra inches | FB_EXTRA_INCHES | 0.289 |
body | Looks like numbers with O's insted of 0's | FB_FAKE_NUMBERS | 1 |
body | Looks like fake numbers (4) | FB_FAKE_NUMS4 | 1 |
body | Phrase: Farmacy | FB_FHARMACY | 1 |
body | Phrase: forward look with 0's | FB_FORWARD_LOOK | 1 |
body | Too much spacing in Address | FB_GAPPY_ADDRESS | 1 |
body | Looks like trying to sell meds | FB_GET_MEDS | 2.314 |
body | Looks like generic viagra | FB_GVR | 2.34 |
body | Phrase hey bro, | FB_HEY_BRO_COMMA | 1 |
body | Phrase: HGH | FB_HG_H_CAP | 1 |
body | Phrase (dollar) x home loan | FB_HOMELOAN | 1 |
body | Phrase: impress ... girl | FB_IMPRESS_GIRL | 1 |
body | Phrase: Increase your energy | FB_INCREASE_YOUR | 2.699 |
body | Phrase: independent reward | FB_INDEPEND_RWD | 2.799 |
body | Phrase: L0an | FB_L0AN | 1 |
body | Special people leave special signs! | FB_LETTERS_21B | 1 |
body | Phrase: LOSE WEIGHT | FB_LOSE_WEIGHT_CAP | 0.001 |
body | Phrase: lower your monthly payments | FB_LOWER_PAYM | 1 |
body | Phrase: more size | FB_MORE_SIZE | 1 |
body | Looks like a fake phone number (1) | FB_NOT_PHONE_NUM1 | 1 |
body | Looks like a fake phone number (3) | FB_NOT_PHONE_NUM3 | 1 |
body | Looks like school but it's not! | FB_NOT_SCHOOL | 1 |
body | Phrase: no prescription needed. | FB_NO_SCRIP_NEEDED | 1.656 |
body | Speaks of teenager. | FB_NUMYO | 1 |
body | Speaks of 20+ year old. | FB_NUMYO2 | 1 |
body | Looks like money but has odd spacing. | FB_ODD_SPACED_MONEY | 1 |
body | Mis-spelled online | FB_ONIINE | 1 |
body | Phrase: p1ll | FB_P1LL | 1 |
body | Phrase: penis growth | FB_PENIS_GROWTH | 1 |
body | Phrase: Dollar, with pipes or 0's. | FB_PIPEDOLLAR | 1 |
body | Looks like illion, but it's not | FB_PIPE_ILLION | 1 |
body | Talks about prolonged hardness | FB_PROLONGED_HARD | 1 |
body | Phrase: quality replica | FB_QUALITY_REPLICA | 3.313 |
body | Refcode with spacing | FB_REF_CODE_SPACE | 1 |
body | Phrase: Replica Rolex | FB_REPLICA_ROLEX | 1.674 |
body | Phrase: REPLICA | FB_REPLIC_CAP | 1 |
body | Looks like refi. | FB_RE_FI | 1 |
body | Phrase: Roller is th | FB_ROLLER_IS_T | 1 |
body | Phrase: rolx | FB_ROLX | 1 |
body | Phrase: save ... prescription. | FB_SAVE_PERSC | 2.799 |
body | Phrase: Softabs | FB_SOFTTABS | 2.887 |
body | Phrase: F R E E | FB_SPACED_FREE | 2.499 |
body | Phone number with -- spacing. (B) | FB_SPACED_PHN_3B | 0.001 |
body | Looks like a s p a c e d zipcode. | FB_SPACEY_ZIP | 1 |
body | Phrase: SPUR-M | FB_SPUR_M | 1 |
body | Phrase: ssex | FB_SSEX | 1 |
body | Looks like stocks exploding. | FB_STOCK_EXPLODE | 1 |
body | Mis-spelled symbol. | FB_SYMBLO | 1 |
body | Phrase: this advertiser | FB_THIS_ADVERT | 3.599 |
body | Phrase: thousand personal | FB_THOUS_PERSONAL | 1 |
body | Phrase: to stop further distribution | FB_TO_STOP_DISTRO | 3.399 |
body | Phrase: Ultra Allure | FB_ULTRA_ALLURE | 2.352 |
body | Phrase: lock to your girlfriend | FB_UNLOCK_YOUR_G | 1 |
body | Pattern Replacement PROV_D | FB_UNRESOLV_PROV | 1 |
body | Phrase: yourself master | FB_YOURSELF_MASTER | 1 |
body | Phrase: Your refi | FB_YOUR_REFI | 1 |
header | Bad X-Mailer version | FH_BAD_OEV1441 | 1 |
header | The date is not 19xx. | FH_DATE_IS_19XX | 0 |
header | RCVD line looks faked (A) | FH_FAKE_RCVD_LINE | 2.167 |
header | RCVD line looks faked (B) | FH_FAKE_RCVD_LINE_B | 4 |
header | E-mail address doesn't have TLD (.com, etc.) | FH_FROMEML_NOTLD | 1.708 |
header | From name has "cash" | FH_FROM_CASH | 2.599 |
header | From name says Get | FH_FROM_GET_NAME | 2.699 |
header | From name is giveaway. | FH_FROM_GIVEAWAY | 2.599 |
header | From has Hoodia!!? | FH_FROM_HOODIA | 1 |
header | Has X-AIMC-AUTH header | FH_HAS_XAIMC | 1.602 |
header | Has X-ID | FH_HAS_XID | 3.299 |
header | Helo is almost an IP addr. | FH_HELO_ALMOST_IP | 3.699 |
header | Helo ends with a dot. | FH_HELO_ENDS_DOT | 1 |
header | Helo is 6-10 hex chr's. | FH_HELO_EQ_610HEX | 1 |
header | Helo is d-d-d-d charter.com | FH_HELO_EQ_CHARTER | 0.607 |
header | Helo is d-d-d-d | FH_HELO_EQ_D_D_D_D | 2.361 |
header | Faked helo of gmail-smtp-in | FH_HELO_GMAILSMTP | 1 |
header | Host is dynamicip | FH_HOST_EQ_DYNAMICIP | 2.632 |
header | Host is pacbell.net dsl | FH_HOST_EQ_PACBELL_D | 0.001 |
header | Host is pool-.+verizon.net | FH_HOST_EQ_VERIZON_P | 2.681 |
header | HOST dns says "in-addr.arpa" | FH_HOST_IN_ADDRARPA | 3.199 |
header | Special MSGID | FH_MSGID_000000 | 1 |
header | Special MSGID | FH_MSGID_01C67 | 1 |
header | MESSAGE ID seen often!!! | FH_MSGID_01C70XXX | 1 |
header | Broken Replace Template | FH_MSGID_REPLACE | 1 |
header | Common sign in msg-id's 12/21/2006 | FH_MSGID_XXBLAH | 1 |
header | Message-Id = @xxx | FH_MSGID_XXX | 2.399 |
header | Subject is Re: new ddd | FH_RE_NEW_DDD | 1 |
header | Broken Replace Template | FH_XMAIL_REPLACE | 1 |
body | Fill in a form with personal information | FILL_THIS_FORM_LONG | 3.8 |
header | Looks like Fake Outlook? | FM_XMAIL_F_OUT | 1 |
header | X-Spam-Relays-External =~ /^[ ip=(?!12... | FORGED_RELAY_MUA_TO_MX | 1 |
body | ReplaceTags: Adobe | FRT_ADOBE2 | 0.001 |
body | ReplaceTags: Approve | FRT_APPROV | 2.499 |
body | ReplaceTags: Bigger / Larger, Penis / Member | FRT_BIGGERMEM1 | 2.523 |
body | ReplaceTags: Diploma | FRT_DIPLOMA | 0 |
body | ReplaceTags: Discount | FRT_DISCOUNT | 1 |
body | ReplaceTags: Dollar | FRT_DOLLAR | 1 |
body | ReplaceTags: Establish (2) | FRT_ESTABLISH2 | 1 |
body | ReplaceTags: Fuck (2) | FRT_FUCK2 | 1 |
body | ReplaceTags: Guarantee (1) | FRT_GUARANTEE1 | 1 |
body | ReplaceTags: Investor | FRT_INVESTOR | 1 |
body | ReplaceTags: Levitra | FRT_LEVITRA | 1 |
body | ReplaceTags: Meeting | FRT_MEETING | 1 |
body | ReplaceTags: Offer (2) | FRT_OFFER2 | 1.681 |
body | ReplaceTags: Oppertun (2) | FRT_OPPORTUN2 | 1 |
body | ReplaceTags: Penis | FRT_PENIS1 | 2.299 |
body | ReplaceTags: Pharmac | FRT_PHARMAC | 1 |
body | ReplaceTags: Price | FRT_PRICE | 0.001 |
body | ReplaceTags: Refinance (1) | FRT_REFINANCE1 | 1 |
body | ReplaceTags: Rolex | FRT_ROLEX | 2.699 |
body | ReplaceTags: Sexual | FRT_SEXUAL | 1 |
body | ReplaceTags: Soma | FRT_SOMA | 0 |
body | ReplaceTags: Soma (2) | FRT_SOMA2 | 0.001 |
body | ReplaceTags: Strong (1) | FRT_STRONG1 | 1 |
body | ReplaceTags: Strong (2) | FRT_STRONG2 | 1 |
body | ReplaceTags: Symbol | FRT_SYMBOL | 1 |
body | ReplaceTags: Today (2) | FRT_TODAY2 | 0.48 |
body | ReplaceTags: Valium | FRT_VALIUM1 | 1 |
body | ReplaceTags: Valium (2) | FRT_VALIUM2 | 1 |
body | ReplaceTags: Weight (2) | FRT_WEIGHT2 | 1 |
body | ReplaceTags: Xanax (1) | FRT_XANAX1 | 1 |
body | ReplaceTags: Xanax (2) | FRT_XANAX2 | 1 |
rawbody | Looks like 3 small tags. | FR_3TAG_3TAG | 1 |
rawbody | Almost looks like viagra. | FR_ALMOST_VIAG2 | 2.299 |
rawbody | Phrase class=cantseetext | FR_CANTSEETEXT | 1 |
rawbody | Sign often seen in spams | FR_MIDER | 1 |
rawbody | HTML Title is only numbers | FR_TITLE_NUMS | 2.899 |
header | X-Spam-Relays-External =~ /gmail-smtp-in.l.google.com/ | FSL_FAKE_GMAIL_RCVD | 3.099 |
header | X-Spam-Relays-External =~ /mx[1234].hotmail.com/ | FSL_FAKE_HOTMAIL_RVCD | 2.631 |
uri | //geocities.com/S+(dollar) / | FSL_GEO_ABUSE | 2.699 |
header | X-Spam-Relays-External =~ /^[^]]+ helo=d+.d+.d+.d+ /i | FSL_HELO_BARE_IP_1 | 2.598 |
header | X-Spam-Relays-External =~ /bhelo=(?:(?:dsl)?device| speedtouch).lanb/i | FSL_HELO_DEVICE | 1.682 |
header | X-Spam-Relays-External =~ /^[^]]+ helo=[a-zA-Z0-9-_]+ /i | FSL_HELO_NON_FQDN_1 | 2.361 |
header | X-Spam-Relays-External =~ /bhelo=S+.setupb/i | FSL_HELO_SETUP | 1 |
uri | //S+.(?:w| eu| fm).interia.pl/ | FSL_INTERIA_ABUSE | 3.899 |
uri | /cid-S+.spaces.live.com/ | FSL_LSPACES_ABUSE | 1 |
uri | //groups.yahoo.com/group/S+/message/1(dollar) / | FSL_YG_ABUSE | 4.199 |
header | Subject has "a bigger" | FS_ABIGGER | 1.693 |
header | Subject says approve you | FS_APPROVE_YOU | 2.499 |
header | Subject says "At No Cost" | FS_AT_NO_COST | 2.499 |
header | Phrase: Cheap in Caps in Subject. | FS_CHEAP_CAP | 1 |
header | Subject talks about money bonus! | FS_DOLLAR_BONUS | 1 |
header | Phrase: ejaculation in subject. | FS_EJACULA | 1 |
header | Phrase: erection in subject. | FS_ERECTION | 1 |
header | Phrase: Huge Cock | FS_HUGECOCK | 1 |
header | Larger than 100% in subj. | FS_LARGE_PERCENT2 | 2.645 |
header | Subject says low rates | FS_LOW_RATES | 1 |
header | Subj starts with New software uploaded | FS_NEW_SOFT_UPLOAD | 1 |
header | Subject looks like Fharmacy spams. | FS_NEW_XXX | 1 |
header | Subject almost says No prescription | FS_NO_SCRIP | 1 |
header | Subject says Nude | FS_NUDE | 1 |