----- Original Message ----- From: "mouss" <[EMAIL PROTECTED]>
Cc: <users@spamassassin.apache.org>
Sent: Tuesday, July 01, 2008 12:27 PM
Subject: Re: Lots of spam with the following snip


Justin Mason wrote:
[snip]
On 01.07.08 10:50, Justin Mason wrote:

no -- this is real spam, not a bounce in any way.


same here. not a bounce in any way.

Are you sure it's not just virus message sent by someone and cured by
intermediate relay?


Yes, seeing lots of this exact wording, in high volume, throughout our
traps.


the few ones I checked only contain the cited text followed by noise (random text to poison bayes or whatever).
<snip>

I am receiving this type of spam also.
What I noticed was that the website in the body was entered with a pound sign instead of a period at the domain part.
The ones I am getting have http://www.tldmls#com/string_of_characters
In my version of firefox (2.0.0.14), this will resolve correctly to the domain name as long as it is a .com. Is this form of url picked up by the URI black lists or does this require a body rule?

Thanks,
Gene Lindsey


Reply via email to