
jhardin at impsec
Oct 27, 2009, 5:42 PM
Post #2 of 2
(349 views)
Permalink
|
|
Re: [SA] How to reject spam where sender = receiver
[In reply to]
|
|
On Tue, 27 Oct 2009, Adam Katz wrote: > John Hardin wrote: >> <mutter>Maybe I should throw a rule like that into the sandbox and see >> how well it does...</mutter> > > I had a dialog with Karsten about this a few years ago ... the regex > is nontrivial and dangerous, so the recommended method is a plugin. > I've actually written such a thing already, though slightly different > in that it ignores the domain. Easy to tailor one way or another. > It's attached. > > Result: Mixed bag. Might be nice to see in the masscheck. I just threw a basic (by no means thorough) rule into my sandbox. We'll see how it does, I can kill it easily enough. > FROM_EQUALS_TO: 1.313% of spam, 0.657% of ham That's a fairly low S/O. -- John Hardin KA7OHZ http://www.impsec.org/~jhardin/ jhardin [at] impsec FALaholic #11174 pgpk -a jhardin [at] impsec key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873 2E79 ----------------------------------------------------------------------- ...the Fates notice those who buy chainsaws... -- www.darwinawards.com ----------------------------------------------------------------------- 4 days until Halloween
|