Maybe a bit tangential, but I just looked at the headers on a spam message that just made it to my inbox, and it's score was:
QUOTE
X-Spam-Status: hits=0.0 tests=NORMAL_HTTP_TO_IP version=3.2.3
However, the scoring on the same message from the other server through which the message passed was:
QUOTE
X-Barracuda-Spam-Score: 2.71
X-Barracuda-Spam-Status: Yes, SCORE=2.71 using per-user scores of TAG_LEVEL=2.0 QUARANTINE_LEVEL=3.0 KILL_LEVEL=4.0 tests=HELO_DYNAMIC_IPADDR, NORMAL_HTTP_TO_IP, NO_REAL_NAME, RCVD_IN_PBL
X-Barracuda-Spam-Report: Code version 3.1, rules version 3.1.23667
Rule breakdown below
pts rule name description
---- ---------------------- --------------------------------------------------
0.80 RCVD_IN_PBL RBL: Received via a relay in Spamhaus PBL
[86.204.165.228 listed in zen.spamhaus.org]
0.55 NO_REAL_NAME From: does not include a real name
1.36 HELO_DYNAMIC_IPADDR Relay HELO'd using suspicious hostname (IP addr 1)
0.00 NORMAL_HTTP_TO_IP URI: Uses a dotted-decimal IP address in URL
I realize that our BL tests are done *after* the SA analysis (and it would sure be nice to either add the SpamHaus PBL or Zen to our options!), but I wonder why SpamCop's SA didn't pick up on the NO_REAL_NAME or the HELO_DYNAMIC_IPADDR, both of which should have increased the score?
Tracking URL:
http://www.spamcop.net/sc?id=z1445311437ze...134506bc23d898z(some manual munging to protect my info...I didn't actually submit this version, however)
DT