From: twesterhever <40121680+twesterhever@users.noreply.github.com> Date: Fri, 3 Nov 2023 13:48:58 +0000 (+0000) Subject: [Enhancement] Add composite rule for suspicious URLs in suspicious messages X-Git-Tag: 3.8.0~89^2 X-Git-Url: https://source.dussan.org/?a=commitdiff_plain;h=refs%2Fpull%2F4681%2Fhead;p=rspamd.git [Enhancement] Add composite rule for suspicious URLs in suspicious messages --- diff --git a/conf/composites.conf b/conf/composites.conf index fe89808fb..df5543be6 100644 --- a/conf/composites.conf +++ b/conf/composites.conf @@ -181,6 +181,12 @@ composites { description = "Fake reply exhibiting characteristics of being injected into a compromised mail server, possibly e-mail thread hijacking"; group = "compromised_hosts"; } + SUSPICIOUS_URL_IN_SUSPICIOUS_MESSAGE { + expression = "(REDIRECTOR_URL | HAS_ANON_DOMAIN | HAS_IPFS_GATEWAY_URL) & (-g+:fuzzy | -g+:statistics | -g+:surbl | -g+:rbl)"; + score = 1.0; + policy = "leave"; + description = "Message contains redirector, anonymous or IPFS gateway URL and is marked by fuzzy/bayes/SURBL/RBL"; + } .include(try=true; priority=1; duplicate=merge) "$LOCAL_CONFDIR/local.d/composites.conf" .include(try=true; priority=10) "$LOCAL_CONFDIR/override.d/composites.conf"