Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

why spamassassin sucks

2 views
Skip to first unread message

Keith Moore

unread,
Mar 29, 2004, 1:59:42 PM3/29/04
to ietf...@imc.org, mo...@cs.utk.edu

People are often asking me why I think spamassassin sucks. Here's an example
of a perfectly valid email that it blocks. The email is a weekly Numerical
Analysis Digest list that uses the group syntax in the To address.

BTW, here are the full headers of the subject message as I received it.
The space between : and ; was added by sendmail somewhere in the path.
It's such a common sendmail bug that there's no way to eradicate it, but
it shouldn't matter as it's still valid group syntax.

There is no URL in the TO address. There are spaces in the To field, but
not within an address - it's perfectly valid syntax to have space between
the : and ; in group syntax, or within a group name. Satan only knows why
this message failed the OPT_HEADER test.

Keith


(begin headers)
Return-Path: <na-diges...@cs.utk.edu>
Received: from localhost (klutz [127.0.0.1])
by smtp.cs.utk.edu (Postfix) with ESMTP
id 0E6FFAFD86; Sun, 28 Mar 2004 11:20:47 -0500 (EST)
Received: from smtp.cs.utk.edu ([127.0.0.1])
by localhost (klutz [127.0.0.1]) (amavisd-new, port 10024) with ESMTP
id 22342-07; Sun, 28 Mar 2004 11:20:40 -0500 (EST)
Received: from netlib2.cs.utk.edu (netlib2.cs.utk.edu [160.36.58.108])
by smtp.cs.utk.edu (Postfix) with ESMTP
id E2FD7AFB5D; Sun, 28 Mar 2004 11:20:36 -0500 (EST)
Received: from netlib2.cs.utk.edu (localhost [127.0.0.1])
by netlib2.cs.utk.edu (8.12.8/8.12.3) with ESMTP id i2SGKSCn005030;
Sun, 28 Mar 2004 11:20:28 -0500 (EST)
Received: from na-net.ornl.gov (root@localhost)
by netlib2.cs.utk.edu (8.12.8/8.12.2/Submit) with SMTP id i2SGKRp6005023;
Sun, 28 Mar 2004 11:20:27 -0500 (EST)
Received: from netlib2.cs.utk.edu (localhost [127.0.0.1])
by netlib2.cs.utk.edu (8.12.8/8.12.3) with ESMTP id i2SElJCn000498
for <na.sen...@na-net.ornl.gov>; Sun, 28 Mar 2004 09:47:19 -0500 (EST)
Received: (from moler@localhost)
by netlib2.cs.utk.edu (8.12.8/8.12.2/Submit) id i2SElJ7t000497
for na.sen...@na-net.ornl.gov; Sun, 28 Mar 2004 09:47:19 -0500 (EST)
Date: Sun, 28 Mar 2004 09:47:19 -0500 (EST)
From: Cleve Moler <mo...@cs.utk.edu>
Message-Id: <200403281447....@netlib2.cs.utk.edu>
To: na-digest list: ;
Subject: NA Digest, V. 04, # 13
Reply-To: na.d...@na-net.ornl.gov
(end headers)

Keith

Begin forwarded message (names of the innocent redacted):

Date: Mon, 29 Mar 2004 02:05:55 -0500 (EST)
From: XXX
To: mo...@cs.utk.edu, XXX
Subject: Re: NA Digest, V. 04, # 13 (fwd)


Hi, Keith and XXX -- I've heard this from several
people now. -- XXX


---------- Forwarded message ----------
Date: Sun, 28 Mar 2004 19:14:04 -0800
From: XXX
To: XXX
Subject: Re: NA Digest, V. 04, # 13

XXX et al, the local spam filter has been filtering
out my na-net news for a few weeks now. It looks
like you could avoid the filter by giving the list
a name that doesn't contain spaces.

Cheers,

- XXX


> From XXX Sun Mar 28 07:01:26 2004
> Date: Sun, 28 Mar 2004 09:47:19 -0500 (EST)
> From: XXX
> To: na-digest list:;
> Subject: NA Digest, V. 04, # 13
> X-UCE-Filter-Settings: XXX redirected to 90_OPT_OUT
> X-Scanned-By: MIMEDefang 2.37
> X-Scanned-By: IEEE UCE Filtering Service
> X-Spam-Flag: YES
> X-Spam-Checker-Version: SpamAssassin 2.63 (2004-01-11) on stamps.cs.ucsb.edu
> X-Spam-Level: *****
> X-Spam-Status: Yes, hits=5.9 required=5.0 tests=AWL,MAILTO_TO_SPAM_ADDR,
> OPT_HEADER,TO_HAS_SPACES autolearn=no version=2.63
> X-Spam-Report:
> * 2.4 TO_HAS_SPACES To: address contains spaces
> * 1.1 MAILTO_TO_SPAM_ADDR URI: Includes a link to a likely spammer email
> * 2.4 OPT_HEADER Headers include an "opt"ed phrase
> * 0.0 AWL AWL: Auto-whitelist adjustment

Keith Moore

unread,
Mar 29, 2004, 3:21:41 PM3/29/04
to Keith Moore, mo...@cs.utk.edu, ietf...@imc.org

followup:

They claim that these problems are already fixed in the development
version. I still don't trust SA, but I do appreciate the fast response.

Keith

--
Power corrupts; Powerpoint corrupts absolutely. - Vint Cerf

0 new messages