Have a look at MailScanner (http://www.mailscanner.info).
It has builtin phishing checks
On 6/28/2005 9:49 PM +0200, Debbie D wrote:
What rules can I add or tweak to stop these??
Over here, they always almost hit bayes_99, dcc and razor.
In about 50% of the cases, they hit some SARE (FRAUD i suppose) rule.
The SARE rules don't come in stock SA (http://www.rulesemporium.com)
Niek
Usually it is the headers that catch these as obvious fakes. However, there
are some SARE rules to look for some of the more obvious text tricks also.
Since you didn't include the headers for that message it is a little hard to
see what might have hit.
That said, between SARE rules and some