From: twesterhever <40121680+twesterhever@users.noreply.github.com> Date: Mon, 4 Nov 2024 11:49:34 +0000 (+0000) Subject: [Minor] Improve FREEMAIL_AFF catch rate X-Git-Tag: 3.11.0~39^2 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=refs%2Fpull%2F5208%2Fhead;p=thirdparty%2Frspamd.git [Minor] Improve FREEMAIL_AFF catch rate This "Mail message body" Content-Description header appears to be a common quirk of advance fee fraud e-mails leveraging freemail services. --- diff --git a/conf/composites.conf b/conf/composites.conf index 4fb97588f9..c3669a675b 100644 --- a/conf/composites.conf +++ b/conf/composites.conf @@ -165,7 +165,7 @@ composites { group = "scams"; } FREEMAIL_AFF { - expression = "(FREEMAIL_FROM | FREEMAIL_ENVFROM | FREEMAIL_REPLYTO | FREEMAIL_MDN) & (TO_DN_RECIPIENTS | R_UNDISC_RCPT) & (INTRODUCTION | FROM_NAME_HAS_TITLE | FREEMAIL_REPLYTO_NEQ_FROM_DOM | SUBJECT_HAS_CURRENCY)"; + expression = "(FREEMAIL_FROM | FREEMAIL_ENVFROM | FREEMAIL_REPLYTO | FREEMAIL_MDN) & (TO_DN_RECIPIENTS | R_UNDISC_RCPT | CD_MM_BODY) & (INTRODUCTION | FROM_NAME_HAS_TITLE | FREEMAIL_REPLYTO_NEQ_FROM_DOM | SUBJECT_HAS_CURRENCY)"; score = 4.0; policy = "leave"; description = "Message exhibits strong characteristics of advance fee fraud (AFF a/k/a '419' spam) involving freemail addresses";