commit 38d347e: [Minor] Add rule for forged X-Mailer: Internet Mail Service

Anton Yuzhaninov citrin+git at citrin.ru
Tue Dec 22 15:56:08 UTC 2020


Author: Anton Yuzhaninov
Date: 2020-12-22 13:40:40 +0000
URL: https://github.com/rspamd/rspamd/commit/38d347e23eee471bf19e78804fb0b15382c5a776 (refs/pull/3582/head)

[Minor] Add rule for forged X-Mailer: Internet Mail Service

---
 rules/regexp/headers.lua | 15 +++++++++++++++
 1 file changed, 15 insertions(+)

diff --git a/rules/regexp/headers.lua b/rules/regexp/headers.lua
index ff16fd886..f9d613a14 100644
--- a/rules/regexp/headers.lua
+++ b/rules/regexp/headers.lua
@@ -993,3 +993,18 @@ reconf['FORGED_X_MAILER'] = {
   score = 4.0,
   group = 'headers',
 }
+
+-- X-Mailer headers like: 'Internet Mail Service (5.5.2650.21)' are being
+-- forged by spammers, but MS Exachange 5.5 is still being used (in 2020) on
+-- some mail servers.  Example of genuene headers (DC-EXMPL is a hostname which
+-- can be a FQDN):
+-- Received: by DC-EXMPL with Internet Mail Service (5.5.2656.59)
+-- 	id <HKH4BJQX>; Tue, 8 Dec 2020 07:10:54 -0600
+-- Message-ID: <E7209F9DB64FCC4BB1051420F0E955DD05C9D59F at DC-EXMPL>
+-- X-Mailer: Internet Mail Service (5.5.2656.59)
+reconf['FORGED_IMS'] = {
+  description = 'Forged X-Mailer: Internet Mail Service',
+  re = [[X-Mailer=/^Internet Mail Service \(5\./{header} & !Received=/^by \S+ with Internet Mail Service \(5\./{header}]]
+  score = 3.0,
+  group = 'headers',
+}


More information about the Commits mailing list