]> source.dussan.org Git - rspamd.git/commitdiff
[Minor] Improve FREEMAIL_AFF catch rate 5208/head
authortwesterhever <40121680+twesterhever@users.noreply.github.com>
Mon, 4 Nov 2024 11:49:34 +0000 (11:49 +0000)
committertwesterhever <40121680+twesterhever@users.noreply.github.com>
Mon, 4 Nov 2024 11:49:34 +0000 (11:49 +0000)
This "Mail message body" Content-Description header appears to be a
common quirk of advance fee fraud e-mails leveraging freemail services.

conf/composites.conf

index 4fb97588f9d118c3bd278f5d2cd9acbf395aca05..c3669a675b4979778057fa2ec8c88e371a8238d3 100644 (file)
@@ -165,7 +165,7 @@ composites {
     group = "scams";
   }
   FREEMAIL_AFF {
-    expression = "(FREEMAIL_FROM | FREEMAIL_ENVFROM | FREEMAIL_REPLYTO | FREEMAIL_MDN) & (TO_DN_RECIPIENTS | R_UNDISC_RCPT) & (INTRODUCTION | FROM_NAME_HAS_TITLE | FREEMAIL_REPLYTO_NEQ_FROM_DOM | SUBJECT_HAS_CURRENCY)";
+    expression = "(FREEMAIL_FROM | FREEMAIL_ENVFROM | FREEMAIL_REPLYTO | FREEMAIL_MDN) & (TO_DN_RECIPIENTS | R_UNDISC_RCPT | CD_MM_BODY) & (INTRODUCTION | FROM_NAME_HAS_TITLE | FREEMAIL_REPLYTO_NEQ_FROM_DOM | SUBJECT_HAS_CURRENCY)";
     score = 4.0;
     policy = "leave";
     description = "Message exhibits strong characteristics of advance fee fraud (AFF a/k/a '419' spam) involving freemail addresses";