You could try adding the following or something similar at the beginning of your filter
BODY END CONTAINS Content-Transfer-Encoding: base64 Or instead of END a -10 depending n the values in your filter. David B www.declude.com -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Orin Wells Sent: Wednesday, August 31, 2005 3:11 PM To: Declude.JunkMail@declude.com Subject: [Declude.JunkMail] General Filter I am having a problem with a client whose email to other members of her domain is getting trapped by the GeneralFilter (words or phrases we have added because they seem to mostly appear in spam). In this particular case the triggering word seems to be P*O*R*N* without the stars. I suspect what is happening is that the encoded attached word document just happens to have this set of letters in sequence in the encrypted data that is attached to the email file in imail. It does not appear in the word document itself. But when I look at the raw file on the server I can see this. I take it from this that Declude when it scans the body of the message also scans any attachment that is sitting there in the encrypted mode. If so is there a way around this? Can I tell it not to scan the encrypted attachments or to expand them first? If this sort of thing is in the latest Declude Junkmail manual, someone just tell me to read TFM. --- This E-mail came from the Declude.JunkMail mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.JunkMail". The archives can be found at http://www.mail-archive.com. --- This E-mail came from the Declude.JunkMail mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.JunkMail". The archives can be found at http://www.mail-archive.com.