Got a remote sender sending some pictures of property damage to be
fixed. It's all images. The only text is:
Sent from Yahoo Mail for iPhone <https://overview.mail.yahoo.com/?.src=iOS>
It hits Pyzor for some reason. Get a PYZOR_CHECK=1.985. Must've picked
the wrong checksum, chief!
However, his messages also hit: FSL_BULK_SIG=2.623. That's a meta in
72_active.cf that looks ilke this:
meta FSL_BULK_SIG (DCC_CHECK || RAZOR2_CHECK ||
PYZOR_CHECK) && !__FSL_HAS_LIST_UNSUB && !__UNSUB_LINK &&
!__RCVD_IN_DNSWL && !__JM_REACTOR_DATE && !__RCD_RDNS_SMTP_MESSY
DCC_CHECK = 0
RAZOR2_CHECK = 0
PYZOR_CHECK = 1
__FSL_HAS_LIST_UNSUB = 0
__UNSUB_LINK = 0
__RCVD_IN_DNSWL = 0
__JM_REACTOR_DATE = 0
__RCD_RDNS_SMTP_MESSY = 0
It does not appear that the actual rule matches the spirit of the rule.
Thoughts?
-- Jared Hall
fixed. It's all images. The only text is:
Sent from Yahoo Mail for iPhone <https://overview.mail.yahoo.com/?.src=iOS>
It hits Pyzor for some reason. Get a PYZOR_CHECK=1.985. Must've picked
the wrong checksum, chief!
However, his messages also hit: FSL_BULK_SIG=2.623. That's a meta in
72_active.cf that looks ilke this:
meta FSL_BULK_SIG (DCC_CHECK || RAZOR2_CHECK ||
PYZOR_CHECK) && !__FSL_HAS_LIST_UNSUB && !__UNSUB_LINK &&
!__RCVD_IN_DNSWL && !__JM_REACTOR_DATE && !__RCD_RDNS_SMTP_MESSY
DCC_CHECK = 0
RAZOR2_CHECK = 0
PYZOR_CHECK = 1
__FSL_HAS_LIST_UNSUB = 0
__UNSUB_LINK = 0
__RCVD_IN_DNSWL = 0
__JM_REACTOR_DATE = 0
__RCD_RDNS_SMTP_MESSY = 0
It does not appear that the actual rule matches the spirit of the rule.
Thoughts?
-- Jared Hall