The junk mail filtering has generally been extremely accurate. Current stats show 89.22% accuracy with 1.64 false positives, which is a MUCH better batting average than Sunbelt Software's iHateSpam program running on Outlook 2002 - my previous set-up.
But every now and then a great deal of spam gets through all of a sudden - as if the spammers are using a new trick to get by the filters. This has been occuring in the last few days with an alarming degree of success. For the spammers, that is.
Most troubling is the analysis offered by the Junk Filter dialog when I tried to train it for some new junk mail that got through, and then hit the Test button:
Message "Sweetheart wants a Rolex ?-webmaster extremum inaccessible cranky" would NOT be considered junk mail at any sensitivity. [XPS5]
+3 [X-MAILER=] (X-Mailer)
+2 [FROM=%ADDRESSBOOKS%] (From %Addressbooks%)
I immediately checked my address book to see if the From adddresses were getting added, but they're not. I checked the full header and it is not spoofed to show it's sent from me.
The message with full headers showing is pasted below, with my pertinent info (e-mail adress and IP info) changed and in red, as well as hyperlinks disabled. Nothing offensive, but if this isn't allowed, Moderator please feel free to remove or edit as necessary.
A lot of the recent spam is getting through and being scored this way. What are they doing to trick the filters into thinking the From address is in my address book, and has anyone found a way to thwart this?
Thanks!
From <xhuaaqdma@worldnet.att.net> Mon, 06 Sep 2004 18:13:14 -0700
From: "Rolex is forever." <xhuaaqdma@worldnet.att.net>
To: <---One of my e-mail addresses--->
Return-path: <xhuaaqdma@worldnet.att.net>
Envelope-to: <---One of my e-mail addresses--->
Delivery-date: Mon, 06 Sep 2004 20:11:20 -0400
Received: from [XX.XXX.XXX.XX] (helo=h00e0185d5f47.ne.client2.attbi.com)
by serve.<---My Server--->.net with smtp (Exim 4.34)
id 1C4TZo-0002xh-EU
for <---One of my e-mail addresses--->; Mon, 06 Sep 2004 20:11:19 -0400
X-Message-Info: 1mrhg89kZMZ/jdzFHuyrJwTFDcCP4Odt
Received: from tanh (XXX.XXX.XXX.XX)
by kpm2.planetaria.breakwater.melanin.fuse.net
(InterMail vY.6.74.24.98 07-12829-0-332-667-1887923) with ESMTP
id <209826740.AWVV5799.pktq8-mail.downfall.tommy.net.cable.rogers.com@greenhouse>
for <---One of my e-mail addresses--->; Tue, 07 Sep 2004 00:13:14 -0100
Message-ID: <28210it78846hlxjj$51123496qh818$263tc35vvl525@bell>
Reply-To: "Rolex is forever." <xhuaaqdma@worldnet.att.net>
Date: Mon, 06 Sep 2004 18:13:14 -0700
X-Antivirus: avast! (VPS 0436-4, 09/03/2004), Inbound message
X-Antivirus-Status: Clean
Delivery-Date: Mon, 6 Sep 2004 20:32:36
Status: U
X-Poco-Score-Detail: +3 [X-MAILER=] (X-Mailer )
X-Poco-Score-Detail: +2 [FROM=%ADDRESSBOOKS%] (From %addressbooks%)
X-Poco-Scored: +5
Subject: Sweetheart wants a Rolex ?-Webmaster extremum inaccessible cranky
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Poco-UID: XXXXXXXX
X-Poco-Status: R
X-Account: <---Account name for this e-mail address--->
Hello,
We all want to wear SWISS WATCHS,
they are expensive-we all know that,
Now we have effordable Replica's--
Rolex
--------------from $99 !!
also available :
=================
CARTIER
FRANK MULLER
Jager-LeCoultre
OMEGA
PATEK PHILIPE
=================
AND MORE
.http://itsmyreplica.info/index.php?ref=hp
Italian Crafted Rolex - Complete Watch Store
Reliable Service and Support
Check Here For More Information
.http://itsmyreplica.info/index.php?ref=hp
Regards
Francisco Guevara
-----------
Any help or advice is greatly appreciated!