The spam headers are making less and less sense. Here's one I picked up this morning.
X-Daemon-Classification: INNOCENT
Envelope-to:
bob@username.plus.comDelivery-date: Tue, 20 Nov 2007 23:57:42 +0000
Received: from pih-criticalpath01.plus.net ([84.92.7.52] helo=cp3a.criticalpath.priv)
by pih-sunmxcore17.plus.net with esmtp (PlusNet MXCore v2.00) id 1IucyM-0003vn-En
for bob@username.plus.com; Tue, 20 Nov 2007 23:57:42 +0000
X-MAA: Suspected Spam
Received: from 20151061066.user.veloxzone.com.br (201.51.61.66) by cp3a.criticalpath.priv (7.3.118.15)
id 472061DE10280746 for bob@username.plus.com; Tue, 20 Nov 2007 23:57:42 +0000
Received: from [201.51.61.66] by smtp.getontheweb.com; Tue, 20 Nov 2007 21:11:33 -0300
Message-ID: <01c82bb9$ed706790$423d33c9@jbg>
From: "Antoine Sanford" <
jbg@sgri.com>
To: <
bob@username.plus.com>
Subject: EmedsMedsHealthyLife
Date: Tue, 20 Nov 2007 21:11:33 -0300
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0007_01C82BB9.ED706790"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1409
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1409
X-PN-VirusFiltered: by PlusNet MXCore (v4.00)
X-DSPAM-Result: Innocent
X-DSPAM-Processed: Tue Nov 20 23:57:43 2007
X-DSPAM-Confidence: 0.4953
X-DSPAM-Improbability: 1 in 99 chance of being spam
X-DSPAM-Probability: 0.3348
X-DSPAM-Factors: 27,
Received*33+0300, 0.01000,
From*Sanford", 0.99000,
To*<bob, 0.99000,
From*"Antoine, 0.01000,
Date*Tue+20, 0.02219,
Date*33+0300, 0.04305,
size=2><A+">, 0.88328,
1409", 0.87641,
1409"+name=GENERATOR>, 0.87569,
Delivery-date*2007+23, 0.12432,
X-MAA*Suspected, 0.87498,
X-MAA*Spam, 0.87498,
X-MAA*Suspected+Spam, 0.87498,
Received*2007+23, 0.13701,
Received*2007+23, 0.13701,
Received*2007+21, 0.14442,
2800+1409", 0.84898,
Date*21+11, 0.16233,
Date*2007+21, 0.17207,
1250">+<META, 0.78980,
Received*33, 0.21139,
Received*21+11, 0.78763,
Content-Type*charset="windows+1250", 0.78618,
Content-Type*charset="windows+1250", 0.78618,
Content-Type*1250", 0.78614,
Content-Type*1250", 0.78614,
X-PN-VirusFiltered*by+PlusNet, 0.23238
So is it suspected spam or is it innocent - make your mind up. One or the other - but both?
This came through mx-core and criticalpath. K9 identified it as spam with a probability of 97.6% once it arrived here. It will be interesting to see what effect Postini has.