Here's our very simple BombHeaderRe

# Header will be checked against the Regular Expression.
Notice of Underreported Income
\d\d% 0FF on Pfizer
\d\d% OFF on Pfizer
dear.*\d\d% OFF
dear.*\d\d% oFF
\nfrom:.*pfizer
\nfrom:.*viagra
newslet...@adobe-pdf-pro2009.com
# one.ourdomain.org / two.ourdomain.org no mail from sender.com (but
main ourdomain.org can get them)
\nfrom:[^\r\n]...@sender\.com.+?\nto:[^\r\n]+?\@(one\.ourdomain\.org|two\.ourdomain\.org)
\nto:[^\r\n]+?\@(one\.ourdomain\.org|two\.ourdomain\.org).+?\nfrom:[^\r\n]...@sender\.com

THe block report has an email to one of our users from:
From: Elisa Evans <elisa.a.ev...@somedomain.com>

When I pull up that file I see:
X-ASSP-Message/IP-Score: 20 (BombHeaderRe ' From: Elisa Evans <elisa.a.evan')

What in our BombHeaderRE would have triggered this?

Thanks

------------------------------------------------------------------------------

_______________________________________________
Assp-test mailing list
Assp-test@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/assp-test

Reply via email to