I’ve mentioned this before, but I’m mentioning it again for two reasons:

  1. I just got my highest-rated spam yet (20.50).
  2. It contained the following rule:

    SPAM: FRONTPAGE (0.4 points) BODY: Frontpage used to create the message

That just made my day.

Update: Neil points out that SpamAssassin is holding a high scores contest. I won’t win.

§

Six comments here (latest comments)

  1. Ha! That’s nothing.

    The first one I checked in my spambox scored 23.9 (composed in Netscape 4). And after checking a few more, I found a “refinance” spam that scored 42.1.

    X-MailScanner-SpamCheck: spam, SpamAssassin (score=42.1, required 5, BAYES_90, CLICK_BELOW, COMPLETELY_FREE, EXCUSE_14, FAKED_UNDISC_RECIPS, FORGED_YAHOO_RCVD, HTML_40_50, HTML_FONT_BIG, HTML_LINK_CLICK_HERE, HTML_TABLE_THICK_BORDER, HTML_TITLE_UNTITLED, MIME_HTML_ONLY, MORTGAGE_BEST, MORTGAGE_PITCH, MORTGAGE_RATES,MSGID_OE_SPAM_4ZERO, MSGID_OUTLOOK_TIME, MSGID_SPAMSIGN_ZEROES, NO_REAL_NAME, OFFER, RAZOR2_CF_RANGE_91_100, RAZOR2_CHECK, RCVD_IN_OPM, RCVD_IN_RFCI, SAVE_THOUSANDS, TO_MALFORMED, X_MSMAIL_PRIORITY_HIGH, X_PRIORITY_HIGH)
    X-MailScanner-SpamScore: ssssssssssssssssssssssssssssssssssssssssss

    — Dougal #

  2. I thought I had you beat, but I missed, just barely:

    Content analysis details: (41.50 points, 5 required)
    MSGID_SPAMSIGN_ZEROES (4.3 points) Message-Id generated by spam tool (zeroes variant)
    FROM_ENDS_IN_NUMS (0.7 points) From: ends in numbers
    INVALID_DATE_TZ_ABSURD (4.3 points) Invalid Date: header (timezone does not exist)
    MSGID_OE_SPAM_4ZERO (3.3 points) Message-Id generated by spam tool (4-zeroes variant)
    ONLY_COST (0.2 points) BODY: Only $$$
    WE_HONOR_ALL (4.3 points) BODY: Claims to honor removal requests
    REMOVE_RESPECT (4.3 points) BODY: We respect all removal requests
    EXCUSE_15 (1.8 points) BODY: Claims to be legitimate email
    OFFER (0.1 points) BODY: Free Offer
    OFFERS_ETC (0.6 points) BODY: Stop with the offers, coupons, discounts etc!
    EXCUSE_14 (0.1 points) BODY: Tells you how to stop further spam
    HTML_60_70 (0.1 points) BODY: Message is 60% to 70% HTML
    HTML_FONT_COLOR_RED (0.1 points) BODY: HTML font color is red
    HTML_MESSAGE (0.1 points) BODY: HTML included in message
    HTML_FONT_COLOR_NAME (0.2 points) BODY: HTML font color has unusual name
    HTML_FONT_COLOR_GREEN (0.7 points) BODY: HTML font color is green
    HTML_FONT_BIG (0.1 points) BODY: FONT Size +2 and up or 3 and up
    HTML_FONT_COLOR_UNSAFE (0.1 points) BODY: HTML font color not within safe 6×6x6 palette
    HTML_FONT_COLOR_BLUE (0.1 points) BODY: HTML font color is blue
    HTML_SHOUTING9 (2.7 points) BODY: HTML has very strong “shouting” markup
    HTML_TABLE_THICK_BORDER (1.1 points) BODY: HTML table has thick border
    MSGID_OUTLOOK_TIME (4.4 points) Message-Id is fake (in Outlook Express format)
    RCVD_FAKE_HELO_DOTCOM_2 (2.6 points) Received contains a faked HELO hostname (2)
    DATE_IN_FUTURE_12_24 (2.8 points) Date: is 12 to 24 hours after Received: date
    FORGED_YAHOO_RCVD (2.3 points) ‘From’ yahoo.com does not match ‘Received’ headers
    MIME_HTML_ONLY (0.1 points) Message only has text/html MIME parts

    — Tony Hagale #

  3. The folks who created SpamAssassin are having a “spam high score” contest - the person with the highest SA score wins 12 yummy cans of Spam. The last time I checked, the highest was 48 points.

    (using TinyUrl because the URL from the SA news site is massive. Trust me, this is a legitimate link. Oh, the irony.)

    http://tinyurl.com/93ww

    — Neil #

  4. Haven’t been having nearly as much fun with spam since I changed my email address. :-( I’m using popfile.

    — Glen Stampoultzis #

  5. Ooooh, darn. My highest one so far *just* misses. My top 5 scores:

    dougal:~/> grep SpamCheck: mail/spams | perl -e “while(<>){print m/score=([^,]+),/,qq(\n);}” | sort -n | tail -5
    40.2
    42.1
    43.5
    46.9
    47.8

    — Dougal #

  6. dotdotdot (trackback)

Respond privately

I am no longer accepting public comments on this post, but you can use this form to contact me privately. (Your message will not be published.)



§

firehosecodemusicplanet

© 2001-8 Mark Pilgrim