I checked the local resolver, but then I realised from tcpdump/ngrep that it wasn't even being queried for
groupon.com on that request.
Also, in the logs I saw multiple lines:
task; rspamd_check_group_score: maximum group score 12.50 for group ...(All SURBL symbols):
URIBL_BLACK, RAMBLER_URIBL, PH_SURBL_MULTI, ABUSE_SURBL ...
Then I saw:
task; rspamd_symbols_cache_check_symbol: slow rule: URL_TAGS_SAVE: 149
ms
I guess the URL_TAGS cache was somehow poisoned. So I disabled the url_tags module and reloaded,
problem solved.