Now that the EMPTY_BODY and mis-identified spam issues have been resolved
I've countered a new one creating false positives: the rule (in
/etc/mail/spamassassin/ is:

describe        BOTNET                  Relay might be a spambot or virusbot
header          BOTNET                  eval:botnet()
score           BOTNET                  5.0

  I've read Botnet.txt but I've no clue what to do to reduce the number of
false positives. I could include a specific example that came today from a
client via his Crackberry, if that would help.

  Do I need to build a white list of all such senders? Is there a better way
to tune this rule so it's not triggered so frequently?


Richard B. Shepard, Ph.D.               |  Integrity            Credibility
Applied Ecosystem Services, Inc.        |            Innovation
<>     Voice: 503-667-4517      Fax: 503-667-8863

Reply via email to