You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@spamassassin.apache.org by David B Funk <db...@engineering.uiowa.edu> on 2014/10/29 05:05:11 UTC

Who is "ISIPP IADB" & why are they vouching for spammers?

While grubbing thru messages in one of my spam traps I came across one
that had negative scores from:
-2.2 RCVD_IN_IADB_VOUCHED   RBL: ISIPP IADB lists as vouched-for sender
-0.5 KHOP_RCVD_TRUST        DNS-Whitelisted sender is verified

Since it also hit RAZOR2_CF_RANGE_E8_51_100 & RAZOR2_CF_RANGE_51_100
it didn't get learned as ham, but it still generated a FP.

Is this worth reporting to somebody? Should that IADB be trustworthy
or should I contribute this sort of spam to the scoring engine to
get that -2.2 adjusted down?

It is kind of interesting to track the history of spamtrap fodder.
These are addresses that were mutations of legit business addresses
that I noticed regularly bouncing spam. So I created a "catchall"
(luser relay) handler for them and started tracking the spam fodder.
At first it was clearly just garbage spam but gradually mutated
as spammers sold their address lists to others and now it's gotten
up to legit looking businesses (Verizon, AT&T, PayPal, etc) throwing
their stuff into this spamtrap (IE drank the cool-aid).


-- 
Dave Funk                                  University of Iowa
<dbfunk (at) engineering.uiowa.edu>        College of Engineering
319/335-5751   FAX: 319/384-0549           1256 Seamans Center
Sys_admin/Postmaster/cell_admin            Iowa City, IA 52242-1527
#include <std_disclaimer.h>
Better is not better, 'standard' is better. B{