OK, this rule should *only* hit mails that have never passed through an untrusted host. This seems bizarre, in that case -- could you all check your FPs? (In my case, it was a spam that had been *triple*-encapsulated by report_safe somehow.)
3.143 0.1120 10.4543 0.011 0.93 -0.01 T_ALL_TRUSTED 0.019 0.0398 0.0000 1.000 0.00 -0.01 T_ALL_TRUSTED:jm 1.177 0.0611 2.2922 0.026 0.84 -0.01 T_ALL_TRUSTED:parkerm 13.775 0.1386 26.9110 0.005 0.95 -0.01 T_ALL_TRUSTED:quinlan 0.625 0.2881 1.2595 0.186 0.49 -0.01 T_ALL_TRUSTED:rODbegbie 0.122 0.0458 1.2979 0.034 0.82 -0.01 T_ALL_TRUSTED:theo --j.
