SpamAssassin rules
All 1,293 rules of the current SpamAssassin ruleset with their default scores, and plain-English fixes for the 85 rules that most often hit legitimate email.
Test your email with SpamAssassinRules explained
Authentication (SPF, DKIM, DMARC)
ARC_INVALID0.1
ARC signature is invalid
DKIM_ADSP_ALL1.1
Domain says it signs all mail, but this message is unsigned
DKIM_ADSP_DISCARD1.8
Domain asks to discard unsigned mail
DKIM_ADSP_NXDOMAIN0.8
From domain does not exist
DKIM_INVALID0.1
DKIM signature is invalid
DKIM_SIGNED0.1
Message is DKIM-signed
DKIM_VALID-0.1
Valid DKIM signature
DKIM_VALID_AU-0.1
DKIM signature from your own domain
DKIM_VALID_EF-0.1
DKIM signature from the envelope sender's domain
DMARC_MISSING0.001
No DMARC record
DMARC_NONE0.898
DMARC fails (policy none)
DMARC_PASS-0.001
DMARC passes
DMARC_QUAR1.198
DMARC fails (policy quarantine)
DMARC_REJECT1.797
DMARC fails (policy reject)
NML_ADSP_CUSTOM_HIGH2.6
Missing signature from a frequently spoofed domain
NML_ADSP_CUSTOM_LOW0.7
Missing signature from a domain that always signs
NML_ADSP_CUSTOM_MED1.2
Missing signature from a domain that always signs
SPF_FAIL0.919
SPF fails (hard fail)
SPF_HELO_FAIL0.001
HELO name fails SPF
SPF_HELO_NONE0.001
No SPF record for the HELO name
SPF_NEUTRAL0.652
SPF neutral
SPF_NONE0.001
No SPF record
SPF_PASS-0.001
SPF passes
SPF_SOFTFAIL0.972
SPF soft fail
T_SPF_PERMERROR0.01
SPF record is broken
T_SPF_TEMPERROR0.01
SPF lookup error
Blocklists and allowlists
RCVD_IN_BL_SPAMCOP_NET1.246
Sending IP is on the SpamCop list
RCVD_IN_DNSWL_HI-5
Sender is on the DNSWL allowlist (high trust)
RCVD_IN_DNSWL_LOW-0.7
Sender is on the DNSWL allowlist
RCVD_IN_DNSWL_MED-2.3
Sender is on the DNSWL allowlist (medium trust)
RCVD_IN_MSPIKE_BL0.001
Sending IP has a bad Mailspike reputation
RCVD_IN_PBL3.558
Sending IP is on the Spamhaus PBL
RCVD_IN_PSBL2.7
Sending IP is on the PSBL
RCVD_IN_SBL2.596
Sending IP is on the Spamhaus SBL
RCVD_IN_SBL_CSS3.558
Sending IP is on the Spamhaus CSS list
RCVD_IN_XBL0.724
Sending IP is on the Spamhaus XBL
Content
EMPTY_MESSAGE2.344
Message has no text
LOTS_OF_MONEY0.001
Mentions large sums of money
SUBJ_ALL_CAPS0.5
Subject is in capital letters
Headers
FROM_EXCESS_BASE640.001
From header needlessly encoded
INVALID_DATE0.432
Invalid Date header
MAILING_LIST_MULTI1
Looks like mailing-list software
MISSING_DATE1.396
No Date header
MISSING_FROM1
No From header
MISSING_HEADERS1.207
No To header
MISSING_MID0.14
No Message-ID header
MISSING_SUBJECT1.767
No subject
MSGID_FROM_MTA_HEADER0.001
Message-ID added by a relay
REPLYTO_WITHOUT_TO_CC1.946
Reply-To but no To or Cc
TO_NO_BRKTS_HTML_ONLY1.999
To without angle brackets in an HTML-only message
HTML and MIME
HTML_FONT_LOW_CONTRAST0.001
Text color almost matches the background
HTML_IMAGE_ONLY_040.342
Mostly images, almost no text
HTML_IMAGE_ONLY_081.781
Mostly images, little text
HTML_IMAGE_ONLY_121.629
Mostly images, little text
HTML_IMAGE_ONLY_161.048
Many images for the amount of text
HTML_IMAGE_RATIO_020.001
Low text-to-image ratio
HTML_MIME_NO_HTML_TAG0.635
HTML part without an <html> tag
HTML_SHORT_LINK_IMG_10.139
Very short HTML with a linked image
MIME_BASE64_TEXT0.001
Text hidden in base64
MIME_HTML_ONLY0.1
HTML only, no plain-text version
MIME_QP_LONG_LINE0.001
Over-long line in quoted-printable part
MPART_ALT_DIFF0.724
Plain-text and HTML versions differ
MPART_ALT_DIFF_COUNT1.483
Plain-text and HTML versions differ a lot
T_REMOTE_IMAGE0.01
Loads an external image
Links
HTTPS_HTTP_MISMATCH0.1
Link text and target differ
NORMAL_HTTP_TO_IP0.001
Link to a bare IP address
NUMERIC_HTTP_ADDR0.001
Link with a numeric IP address
T_SHORT_SHORTNER0.01
Short email with a link shortener
URIBL_ABUSE_SURBL1.948
A link points to a domain on SURBL
URIBL_BLACK1.7
A link points to a domain on URIBL
URIBL_DBL_SPAM2.5
A link points to a domain on the Spamhaus DBL
URI_NOVOWEL0.5
Linked domain looks random
Sending server
FORGED_GMAIL_RCVD1
Gmail address sent through non-Gmail servers
FREEMAIL_FORGED_REPLYTO2.503
Free-mail Reply-To on a different From
FREEMAIL_FROM0.001
Sent from a free email address
FREEMAIL_REPLYTO1
Different free-mail addresses in From and Reply-To
FROM_FMBLA_NEWDOM1.499
From domain registered in the last 7 days
FROM_FMBLA_NEWDOM140.999
From domain registered in the last 14 days
FROM_FMBLA_NEWDOM280.799
From domain registered in the last 28 days
FSL_HELO_NON_FQDN_10.001
HELO is not a full host name
HEADER_FROM_DIFFERENT_DOMAINS0.249
From and envelope sender use different domains
HELO_DYNAMIC_IPADDR3.243
Server introduced itself with a dynamic-looking name
KHOP_HELO_FCRDNS0.4
HELO name does not match reverse DNS
RDNS_DYNAMIC0.363
Reverse DNS looks like a home connection
RDNS_NONE1.274
Sending server has no reverse DNS
All rules
Ruleset revision 1938714. Scores apply with network tests on and Bayes off.
| Rule | Score | Description |
|---|---|---|
| ACCESSDB | – | Message would have been caught by accessdb |
| ACCT_PHISHING_MANY | 2.999 | Phishing for account information |
| ACT_NOW_CAPS | 0.1 | Talks about 'acting now' with capitals |
| AC_BR_BONANZA | 0.001 | Too many newlines in a row... spammy template |
| AC_DIV_BONANZA | 0.001 | Too many divs in a row... spammy template |
| AC_FROM_MANY_DOTS | 2.5 | Multiple periods in From user name |
| AC_HTML_NONSENSE_TAGS | 1 | Many consecutive multi-letter HTML tags, likely nonsense/spam |
| AC_POST_EXTRAS | 1 | Suspicious URL |
| AC_SPAMMY_URI_PATTERNS1 | 1 | link combos match highly spammy template |
| AC_SPAMMY_URI_PATTERNS10 | 1 | link combos match highly spammy template |
| AC_SPAMMY_URI_PATTERNS11 | 1 | link combos match highly spammy template |
| AC_SPAMMY_URI_PATTERNS12 | 1 | link combos match highly spammy template |
| AC_SPAMMY_URI_PATTERNS2 | 1 | link combos match highly spammy template |
| AC_SPAMMY_URI_PATTERNS3 | 1 | link combos match highly spammy template |
| AC_SPAMMY_URI_PATTERNS4 | 1 | link combos match highly spammy template |
| AC_SPAMMY_URI_PATTERNS8 | 1 | link combos match highly spammy template |
| AC_SPAMMY_URI_PATTERNS9 | 1 | link combos match highly spammy template |
| ADMAIL | 0.001 | "admail" and variants |
| ADMITS_SPAM | 1.999 | Admits this is an ad |
| ADULT_DATING_COMPANY | 20 | |
| ADVANCE_FEE_2_NEW_FORM | 1 | Advance Fee fraud and a form |
| ADVANCE_FEE_2_NEW_FRM_MNY | 1 | Advance Fee fraud form and lots of money |
| ADVANCE_FEE_2_NEW_MONEY | 1.999 | Advance Fee fraud and lots of money |
| ADVANCE_FEE_3_NEW | 2.296 | Appears to be advance fee fraud (Nigerian 419) |
| ADVANCE_FEE_3_NEW_FORM | 1 | Advance Fee fraud and a form |
| ADVANCE_FEE_3_NEW_FRM_MNY | 1 | Advance Fee fraud form and lots of money |
| ADVANCE_FEE_3_NEW_MONEY | 3.099 | Advance Fee fraud and lots of money |
| ADVANCE_FEE_4_NEW | 2.399 | Appears to be advance fee fraud (Nigerian 419) |
| ADVANCE_FEE_4_NEW_FORM | 1 | Advance Fee fraud and a form |
| ADVANCE_FEE_4_NEW_FRM_MNY | 1 | Advance Fee fraud form and lots of money |
| ADVANCE_FEE_4_NEW_MONEY | 0.009 | Advance Fee fraud and lots of money |
| ADVANCE_FEE_5_NEW | 2.499 | Appears to be advance fee fraud (Nigerian 419) |
| ADVANCE_FEE_5_NEW_FORM | 1 | Advance Fee fraud and a form |
| ADVANCE_FEE_5_NEW_FRM_MNY | 1 | Advance Fee fraud form and lots of money |
| ADVANCE_FEE_5_NEW_MONEY | 3 | Advance Fee fraud and lots of money |
| AD_PREFS | 0.25 | Advertising preferences |
| ALIBABA_IMG_NOT_RCVD_ALI | 1 | Alibaba hosted image but message not from Alibaba |
| ALL_TRUSTED | -1 | Passed through trusted hosts only via SMTP |
| AMAZON_IMG_NOT_RCVD_AMZN | 2.499 | Amazon hosted image but message not from Amazon |
| ANY_BOUNCE_MESSAGE | 0.1 | Message is some kind of bounce message |
| APOSTROPHE_FROM | 0.786 | From address contains an apostrophe |
| APP_DEVELOPMENT_FREEM | 1 | App development pitch, freemail or CHN replyto |
| APP_DEVELOPMENT_NORDNS | 1 | App development pitch, no rDNS |
| ARC_INVALID | 0.1 | ARC signature exists, but is not valid |
| ARC_SIGNED | 0.001 | Message has a ARC signature |
| ARC_TRUSTED | 0.001 | Message has valid ARC chain from trusted sealer |
| ARC_VALID | 0.001 | Message has a valid ARC signature |
| AWL | 1 | Adjusted score from AWL reputation of From: address |
| AXB_XMAILER_MIMEOLE_OL_024C2 | 1.793 | Yet another X header trait |
| BAD_CREDIT | 0.1 | Eliminate Bad Credit |
| BAD_ENC_HEADER | 0.001 | Message has bad MIME encoding in the header |
| BANG_GUAR | 1 | Something is emphatically guaranteed |
| BANG_OPRAH | – | Talks about Oprah with an exclamation! |
| BANKING_LAWS | 2.004 | Talks about banking laws |
| BASE64_LENGTH_78_79 | 0.1 | |
| BASE64_LENGTH_79_INF | 2.019 | base64 encoded email part uses line length greater than 79 characters |
| BAYES_00 | – | Bayes spam probability is 0 to 1% |
| BAYES_05 | – | Bayes spam probability is 1 to 5% |
| BAYES_20 | – | Bayes spam probability is 5 to 20% |
| BAYES_40 | – | Bayes spam probability is 20 to 40% |
| BAYES_50 | – | Bayes spam probability is 40 to 60% |
| BAYES_60 | – | Bayes spam probability is 60 to 80% |
| BAYES_80 | – | Bayes spam probability is 80 to 95% |
| BAYES_95 | – | Bayes spam probability is 95 to 99% |
| BAYES_99 | – | Bayes spam probability is 99 to 100% |
| BAYES_999 | – | Bayes spam probability is 99.9 to 100% |
| BEBEE_IMG_NOT_RCVD_BB | 1 | Bebee hosted image but message not from Bebee |
| BIGNUM_EMAILS_FREEM | 1.962 | Lots of email addresses/leads, free email account |
| BIGNUM_EMAILS_MANY | 2.999 | Lots of email addresses/leads, over and over |
| BILLION_DOLLARS | 1.451 | Talks about lots of money |
| BILL_1618 | 1 | Mentions proposed US law supposedly permitting spamming |
| BITCOIN_BOMB | 1 | BitCoin + bomb |
| BITCOIN_DEADLINE | 1.935 | BitCoin with a deadline |
| BITCOIN_DIRECT | 3.499 | Bitcoin + direct-to-MX |
| BITCOIN_EXTORT_01 | 3.535 | Extortion spam, pay via BitCoin |
| BITCOIN_EXTORT_02 | 1 | Extortion spam, pay via BitCoin |
| BITCOIN_IMGUR | 1 | Bitcoin + hosted image |
| BITCOIN_MALF_HTML | 1.554 | Bitcoin + malformed HTML |
| BITCOIN_MALWARE | 1 | BitCoin + malware bragging |
| BITCOIN_OBFU_SUBJ | 1 | Bitcoin + obfuscated subject |
| BITCOIN_ONAN | 2.519 | BitCoin + [censored] |
| BITCOIN_PAY_ME | 1 | Pay me via BitCoin |
| BITCOIN_SPAM_01 | 1 | BitCoin spam pattern 01 |
| BITCOIN_SPAM_02 | 1.525 | BitCoin spam pattern 02 |
| BITCOIN_SPAM_03 | 1.973 | BitCoin spam pattern 03 |
| BITCOIN_SPAM_04 | 1 | BitCoin spam pattern 04 |
| BITCOIN_SPAM_05 | 0.001 | BitCoin spam pattern 05 |
| BITCOIN_SPAM_06 | 1 | BitCoin spam pattern 06 |
| BITCOIN_SPAM_07 | 1.168 | BitCoin spam pattern 07 |
| BITCOIN_SPAM_08 | 1 | BitCoin spam pattern 08 |
| BITCOIN_SPAM_09 | 1 | BitCoin spam pattern 09 |
| BITCOIN_SPAM_10 | 1 | BitCoin spam pattern 10 |
| BITCOIN_SPAM_11 | 1 | BitCoin spam pattern 11 |
| BITCOIN_SPAM_12 | 1 | BitCoin spam pattern 12 |
| BITCOIN_SPF_ONLYALL | 1 | Bitcoin from a domain specifically set to pass +all SPF |
| BITCOIN_TOEQFM | 1.982 | Bitcoin + To same as From |
| BITCOIN_VISTA | 1.674 | Bitcoin + old MSFT msgid format |
| BITCOIN_WFH_01 | 1 | Work-from-Home + bitcoin |
| BITCOIN_XPRIO | 0.334 | Bitcoin + priority |
| BITCOIN_YOUR_INFO | 2.75 | BitCoin with your personal info |
| BLANK_LINES_80_90 | – | Message body has 80-90% blank lines |
| BODY_8BITS | 1.5 | Body includes 8 consecutive 8-bit characters |
| BODY_ENHANCEMENT | 1.611 | Information on growing body parts |
| BODY_ENHANCEMENT2 | 0.1 | Information on getting larger body parts |
| BODY_URI_ONLY | 0.001 | Message body is only a URI in one line of text or for an image |
| BOGUS_MIME_VERSION | 1 | Mime version header is bogus |
| BOGUS_MSM_HDRS | 1 | Apparently bogus Microsoft email headers |
| BOMB_FREEM | 1 | Bomb + freemail |
| BOMB_MONEY | 1 | Bomb + money: bomb threat? |
| BOUNCE_MESSAGE | 0.1 | MTA bounce message |
| BTC_ORG | 1 | Bitcoin wallet ID + unusual header |
| BULK_RE_SUSP_NTLD | 1 | Precedence bulk and RE: from a suspicious TLD |
| CANT_SEE_AD | 1 | You really want to see our spam. |
| CHALLENGE_RESPONSE | 0.1 | Challenge-Response message for mail you sent |
| CHARSET_FARAWAY | 3.2 | Character set indicates a foreign language |
| CHARSET_FARAWAY_HEADER | 3.2 | A foreign language charset used in headers |
| CN_B2B_SPAMMER | 1 | Chinese company introducing itself |
| CN_PHISH_JP_01 | 1 | Apparent Chinese phishing of Japanese target |
| CN_PHISH_JP_02 | 1 | JP "password" + .cn URL - possible Chinese phishing |
| CN_PHISH_JP_04 | 1.971 | JP "payment" + .cn URL - possible Chinese phishing |
| CN_PHISH_JP_06 | 1 | JP "mastercard" + .cn URL - possible Chinese phishing |
| CN_PHISH_JP_07 | 1 | JP "update payment information" + .cn URL - possible Chinese phishing |
| COMMENT_GIBBERISH | 1 | Nonsense in long HTML comment |
| COMPENSATION | 0.001 | "Compensation" |
| CONFIRMED_FORGED | – | Received headers are forged |
| CONTENT_AFTER_HTML | 0.646 | More content after HTML close tag + other spam signs |
| CONTENT_AFTER_HTML_WEAK | 1 | More content after HTML close tag |
| CORRUPT_FROM_LINE_IN_HDRS | – | Informational: message is corrupt, with a From line in its headers |
| CRBOUNCE_MESSAGE | 0.1 | Challenge-Response bounce message |
| CTE_8BIT_MISMATCH | 0.112 | Header says 7bits but body disagrees |
| CTYPE_001C_A | – | |
| CTYPE_001C_B | 0.001 | |
| CTYPE_8SPACE_GIF | – | Stock spam image part 'Content-Type' found (8 spc) |
| CUM_SHOT | – | Possible porn - Cum Shot |
| CURR_PRICE | 0.001 | |
| DATE_IN_FUTURE_03_06 | 2.426 | Date: is 3 to 6 hours after Received: date |
| DATE_IN_FUTURE_06_12 | 0.001 | Date: is 6 to 12 hours after Received: date |
| DATE_IN_FUTURE_12_24 | 2.489 | Date: is 12 to 24 hours after Received: date |
| DATE_IN_FUTURE_24_48 | 1.248 | Date: is 24 to 48 hours after Received: date |
| DATE_IN_FUTURE_48_96 | 0.813 | Date: is 48 to 96 hours after Received: date |
| DATE_IN_FUTURE_96_Q | 3.702 | Date: is 4 days to 4 months after Received: date |
| DATE_IN_FUTURE_96_XX | – | Date: is 96 hours or more after Received: date |
| DATE_IN_PAST_03_06 | 1.076 | Date: is 3 to 6 hours before Received: date |
| DATE_IN_PAST_06_12 | 1.103 | Date: is 6 to 12 hours before Received: date |
| DATE_IN_PAST_12_24 | 0.804 | Date: is 12 to 24 hours before Received: date |
| DATE_IN_PAST_24_48 | 0.485 | Date: is 24 to 48 hours before Received: date |
| DATE_IN_PAST_48_96 | 1 | Date: is 48 to 96 hours before Received: date |
| DATE_IN_PAST_96_XX | 2.07 | Date: is 96 hours or more before Received: date |
| DATE_SPAMWARE_Y2K | – | Date header uses unusual Y2K formatting |
| DAY_I_EARNED | 1 | Work-at-home spam |
| DCC_CHECK | 1.1 | Detected as bulk mail by DCC (dcc-servers.net) |
| DCC_REPUT_00_12 | -0.8 | DCC reputation between 0 and 12 % (mostly ham) |
| DCC_REPUT_13_19 | -0.1 | DCC reputation between 13 and 19 % |
| DCC_REPUT_70_89 | 0.1 | DCC reputation between 70 and 89 % |
| DCC_REPUT_90_94 | 0.4 | DCC reputation between 90 and 94 % |
| DCC_REPUT_95_98 | 0.7 | DCC reputation between 95 and 98 % (mostly spam) |
| DCC_REPUT_99_100 | 1.2 | DCC reputation between 99 % or higher (spam) |
| DC_GIF_UNO_LARGO | 1.323 | Message contains a single large gif image |
| DC_IMAGE_SPAM_HTML | 0.1 | Possible Image-only spam |
| DC_IMAGE_SPAM_TEXT | 0.1 | Possible Image-only spam with little text |
| DC_PNG_UNO_LARGO | 0.001 | Message contains a single large png image |
| DEAR_BENEFICIARY | 2.699 | Dear Beneficiary: |
| DEAR_FRIEND | 2.604 | Dear Friend? That's not very dear! |
| DEAR_SOMETHING | 1.731 | Contains 'Dear (something)' |
| DEAR_WINNER | 3.099 | Spam with generic salutation of "dear winner" |
| DIET_1 | – | Lose Weight Spam |
| DIGEST_MULTIPLE | 0.001 | Message hits more than one network digest check |
| DKIMDOMAIN_IN_DWL | -3.5 | |
| DKIMDOMAIN_IN_DWL_UNKNOWN | -0.01 | |
| DKIMWL_BL | 2.798 | DKIMwl.org - Blocked sender |
| DKIMWL_BLOCKED | 0.001 | ADMINISTRATOR NOTICE: The query to DKIMWL.org was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists\#dnsbl-block for more information. |
| DKIMWL_WL_HIGH | -0.331 | DKIMwl.org - High trust sender |
| DKIMWL_WL_MED | -0.001 | DKIMwl.org - Medium trust sender |
| DKIMWL_WL_MEDHI | -1 | DKIMwl.org - Medium-high trust sender |
| DKIM_ADSP_ALL | 1.1 | No valid author signature, domain signs all mail |
| DKIM_ADSP_CUSTOM_HIGH | 0.001 | No valid author signature, adsp_override is CUSTOM_HIGH |
| DKIM_ADSP_CUSTOM_LOW | 0.001 | No valid author signature, adsp_override is CUSTOM_LOW |
| DKIM_ADSP_CUSTOM_MED | 0.001 | No valid author signature, adsp_override is CUSTOM_MED |
| DKIM_ADSP_DISCARD | 1.8 | No valid author signature, domain signs all mail and suggests discarding the rest |
| DKIM_ADSP_NXDOMAIN | 0.8 | No valid author signature and domain not in DNS |
| DKIM_INVALID | 0.1 | DKIM or DK signature exists, but is not valid |
| DKIM_POLICY_SIGNALL | – | |
| DKIM_POLICY_SIGNSOME | – | |
| DKIM_POLICY_TESTING | – | |
| DKIM_SIGNED | 0.1 | Message has a DKIM or DK signature, not necessarily valid |
| DKIM_VALID | -0.1 | Message has at least one valid DKIM or DK signature |
| DKIM_VALID_AU | -0.1 | Message has a valid DKIM or DK signature from author's domain |
| DKIM_VALID_EF | -0.1 | Message has a valid DKIM or DK signature from envelope-from domain |
| DKIM_VERIFIED | – | |
| DMARC_MISSING | 0.001 | Missing DMARC policy |
| DMARC_NONE | 0.898 | DMARC none policy |
| DMARC_PASS | -0.001 | DMARC pass policy |
| DMARC_PERMERROR | 2.139 | DMARC permanent error |
| DMARC_QUAR | 1.198 | DMARC quarantine policy |
| DMARC_REJECT | 1.797 | DMARC reject policy |
| DMARC_TEMPERROR | 0.001 | DMARC temporary error |
| DOS_ANAL_SPAM_MAILER | – | X-mailer pattern common to anal porn site spam |
| DOS_BODY_HIGH_NO_MID | 3.999 | High bit body and no message ID header |
| DOS_FIX_MY_URI | – | Looks like a "fix my obfu'd URI please" spam |
| DOS_HIGH_BAT_TO_MX | – | The Bat! Direct to MX with High Bits |
| DOS_LET_GO_JOB | – | Let go from their job and now makes lots of dough! |
| DOS_OE_TO_MX | 3.086 | Delivered direct to MX with OE headers |
| DOS_OE_TO_MX_IMAGE | 1.886 | Direct to MX with OE headers and an image |
| DOS_OUTLOOK_TO_MX | 1.449 | Delivered direct to MX with Outlook headers |
| DOS_RCVD_IP_TWICE_C | 2.06 | Received from the same IP twice in a row (only one external relay; empty or IP helo) |
| DOS_STOCK_BAT | 0.001 | Probable pump and dump stock spam |
| DOS_STOCK_BAT2 | – | |
| DOS_URI_ASTERISK | – | Found an asterisk in a URI |
| DOS_YOUR_PLACE | – | Russian dating spam |
| DOTGOV_IMAGE | 1 | .gov URI + hosted image |
| DRUGS_ANXIETY | 0.1 | Refers to an anxiety control drug |
| DRUGS_ANXIETY_EREC | – | Refers to both an erectile and an anxiety drug |
| DRUGS_ANXIETY_OBFU | – | Obfuscated reference to an anxiety control drug |
| DRUGS_DIET | 0.757 | Refers to a diet drug |
| DRUGS_DIET_OBFU | – | Obfuscated reference to a diet drug |
| DRUGS_ERECTILE | 2.221 | Refers to an erectile drug |
| DRUGS_ERECTILE_OBFU | 1.309 | Obfuscated reference to an erectile drug |
| DRUGS_HDIA | – | Subject mentions "hoodia" |
| DRUGS_MANYKINDS | 1.473 | Refers to at least four kinds of drugs |
| DRUGS_MUSCLE | 2.499 | Refers to a muscle relaxant |
| DRUGS_SLEEP_EREC | – | Refers to both an erectile and a sleep aid drug |
| DRUGS_SMEAR1 | 2.051 | Two or more drugs crammed together into one word |
| DRUGS_STOCK_MIMEOLE | 1.681 | |
| DRUG_DOSAGE | – | Talks about price per dose |
| DRUG_ED_CAPS | 1.023 | Mentions an E.D. drug |
| DRUG_ED_GENERIC | – | Mentions Generic Viagra |
| DRUG_ED_ONLINE | 1.152 | Fast Viagra Delivery |
| DRUG_ED_SILD | 0.001 | Talks about an E.D. drug using its chemical name |
| DSN_NO_MIMEVERSION | 1.999 | Return-Path <> and no MIME-Version: header |
| DX_TEXT_02 | 1 | "change your message stat" |
| DX_TEXT_03 | 1 | "XXX Media Group" |
| DYNAMIC_IMGUR | 3.222 | dynamic IP + hosted image |
| DYN_RDNS_AND_INLINE_IMAGE | 1.344 | Contains image, and was sent by dynamic rDNS |
| DYN_RDNS_SHORT_HELO_HTML | 0.001 | Sent by dynamic rDNS, short HELO, and HTML |
| DYN_RDNS_SHORT_HELO_IMAGE | 2.516 | Short HELO string, dynamic rDNS, inline image |
| EBAY_IMG_NOT_RCVD_EBAY | 1 | E-bay hosted image but message not from E-bay |
| EMAIL_ROT13 | – | Body contains a ROT13-encoded email address |
| EMPTY_MESSAGE | 2.344 | Message appears to have no textual parts |
| EMRCP | 1 | "Excess Maximum Return Capital Profit" scam |
| EM_ROLEX | 1.309 | Message puts emphasis on the watch manufacturer |
| ENCRYPTED_MESSAGE | -0.999 | Message is encrypted, not likely to be spam |
| END_FUTURE_EMAILS | 0.146 | Spammy unsubscribe |
| ENGLISH_UCE_SUBJECT | 1.542 | Subject contains an English UCE tag |
| ENVFROM_GOOG_TRIX | 1 | From suspicious Google subdomain |
| ENV_AND_HDR_SPF_MATCH | -0.5 | Env and Hdr From used in default SPF WL Match |
| EXCUSE_24 | 1 | Claims you wanted this ad |
| EXCUSE_4 | 1.687 | Claims you can be removed from the list |
| EXCUSE_REMOVE | 2.992 | Talks about how to be removed from mailings |
| FACEBOOK_IMG_NOT_RCVD_FB | 1 | Facebook hosted image but message not from Facebook |
| FAKE_OUTBLAZE_RCVD | – | Received header contains faked 'mr.outblaze.com' |
| FAKE_REPLY_C | 0.001 | |
| FBI_MONEY | 1 | The FBI wants to give you lots of money? |
| FBI_SPOOF | 1 | Claims to be FBI, but not from FBI domain |
| FILL_THIS_FORM | 0.001 | Fill in a form with personal information |
| FILL_THIS_FORM_FRAUD_PHISH | 0.396 | |
| FILL_THIS_FORM_LOAN | 2.237 | |
| FILL_THIS_FORM_LONG | 2 | Fill in a form with personal information |
| FIN_FREE | 0.1 | Freedom of a financial nature |
| FONT_INVIS_DIRECT | 1 | Invisible text + direct-to-MX |
| FONT_INVIS_DOTGOV | 1 | Invisible text + .gov URI |
| FONT_INVIS_HTML_NOHTML | 2.999 | Invisible text + malformed HTML |
| FONT_INVIS_LONG_LINE | 1 | Invisible text + long lines |
| FONT_INVIS_MSGID | 2.499 | Invisible text + suspicious message ID |
| FONT_INVIS_NORDNS | 1.225 | Invisible text + no rDNS |
| FONT_INVIS_POSTEXTRAS | 1 | Invisible text + suspicious URI |
| FORGED_GMAIL_RCVD | 1 | 'From' gmail.com does not match 'Received' headers |
| FORGED_HOTMAIL_RCVD2 | 1.187 | hotmail.com 'From' address, but no 'Received:' |
| FORGED_IMS_HTML | – | IMS can't send HTML message only |
| FORGED_IMS_TAGS | – | IMS mailers can't send HTML in this format |
| FORGED_MSGID_AOL | – | Message-ID is forged, (aol.com) |
| FORGED_MSGID_EXCITE | 1.899 | Message-ID is forged, (excite.com) |
| FORGED_MSGID_HOTMAIL | – | Message-ID is forged, (hotmail.com) |
| FORGED_MSGID_MSN | – | Message-ID is forged, (msn.com) |
| FORGED_MSGID_YAHOO | 0.1 | Message-ID is forged, (yahoo.com) |
| FORGED_MUA_EUDORA | 2.51 | Forged mail pretending to be from Eudora |
| FORGED_MUA_IMS | 2.399 | Forged mail pretending to be from IMS |
| FORGED_MUA_MOZILLA | 1.596 | Forged mail pretending to be from Mozilla |
| FORGED_MUA_OIMO | 2.599 | Forged mail pretending to be from MS Outlook IMO |
| FORGED_MUA_OUTLOOK | 2.785 | Forged mail pretending to be from MS Outlook |
| FORGED_MUA_THEBAT_BOUN | 3.22 | Mail pretending to be from The Bat! (boundary) |
| FORGED_MUA_THEBAT_CS | – | Mail pretending to be from The Bat! (charset) |
| FORGED_OUTLOOK_HTML | 0.001 | Outlook can't send HTML message only |
| FORGED_OUTLOOK_TAGS | 0.565 | Outlook can't send HTML in this format |
| FORGED_QUALCOMM_TAGS | – | QUALCOMM mailers can't send HTML in this format |
| FORGED_TELESP_RCVD | 2.499 | Contains forged hostname for a DSL IP in Brazil |
| FORGED_THEBAT_HTML | – | The Bat! can't send HTML message only |
| FORGED_YAHOO_RCVD | 1.022 | 'From' yahoo.com does not match 'Received' headers |
| FORM_FRAUD | 0.383 | Fill a form and a fraud phrase |
| FORM_FRAUD_3 | 1 | Fill a form and several fraud phrases |
| FORM_FRAUD_5 | 0.001 | Fill a form and many fraud phrases |
| FORWARD_LOOKING | – | Stock Disclaimer Statement |
| FOUND_YOU | 1 | I found you... |
| FRAGMENTED_MESSAGE | – | Partial message |
| FREEMAIL_ENVFROM_END_DIGIT | 0.25 | Envelope-from freemail username ends in digit |
| FREEMAIL_FORGED_FROMDOMAIN | 0.001 | 2nd level domains in From and EnvelopeFrom freemail headers are different |
| FREEMAIL_FORGED_REPLYTO | 2.503 | Freemail in Reply-To, but not From |
| FREEMAIL_FROM | 0.001 | Sender email is commonly abused enduser mail provider |
| FREEMAIL_REPLY | 1 | From and body contain different freemails |
| FREEMAIL_REPLYTO | 1 | Reply-To/From or Reply-To/body contain different freemails |
| FREEMAIL_REPLYTO_END_DIGIT | 0.25 | Reply-To freemail username ends in digit |
| FREEMAIL_WFH_01 | 1 | Work-from-Home + freemail |
| FREEM_FRNUM_UNICD_EMPTY | 1 | Numeric freemail From address, unicode From name and Subject, empty body |
| FREE_PORN | – | Possible porn - Free Porn |
| FREE_QUOTE_INSTANT | 2.699 | Free express or no-obligation quote |
| FRNAME_IN_MSG_XPRIO_NO_SUB | 1 | From name in message + X-Priority + short or no subject |
| FROMSPACE | 1 | Idiosyncratic "From" header format |
| FROM_ADDR_WS | 2.999 | Malformed From address |
| FROM_BANK_NOAUTH | 1 | From Bank domain but no SPF or DKIM |
| FROM_BLANK_NAME | 2.099 | From: contains empty name |
| FROM_DOMAIN_NOVOWEL | 0.5 | From: domain has series of non-vowel letters |
| FROM_EXCESS_BASE64 | 0.001 | From: base64 encoded unnecessarily |
| FROM_FMBLA_NDBLOCKED | 0.001 | ADMINISTRATOR NOTICE: The query to fresh.fmb.la was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists\#dnsbl-block for more information. |
| FROM_FMBLA_NEWDOM | 1.499 | From domain was registered in last 7 days |
| FROM_FMBLA_NEWDOM14 | 0.999 | From domain was registered in last 7-14 days |
| FROM_FMBLA_NEWDOM28 | 0.799 | From domain was registered in last 14-28 days |
| FROM_GOV_DKIM_AU | -1 | From Government address and DKIM signed |
| FROM_GOV_REPLYTO_FREEMAIL | 1 | From Government domain but ReplyTo is FREEMAIL |
| FROM_GOV_SPOOF | 0.999 | From Government domain but matches SPOOFED |
| FROM_ILLEGAL_CHARS | 2.059 | From: has too many raw illegal characters |
| FROM_IN_TO_AND_SUBJ | 1 | From address is in To and Subject |
| FROM_LOCAL_DIGITS | 0.001 | From: localpart has long digit sequence |
| FROM_LOCAL_HEX | 0.331 | From: localpart has long hexadecimal sequence |
| FROM_LOCAL_NOVOWEL | 0.5 | From: localpart has series of non-vowel letters |
| FROM_LONG_DOM | 1 | Absurdly long From domain name |
| FROM_LONG_DOM_MINFP | 1 | Absurdly long From domain name, suspicious relays |
| FROM_MISSPACED | 0.544 | From: missing whitespace |
| FROM_MISSP_EH_MATCH | 1.999 | From misspaced, matches envelope |
| FROM_MISSP_FREEMAIL | 1.931 | From misspaced + freemail provider |
| FROM_MISSP_MSFT | 1.252 | From misspaced + supposed Microsoft tool |
| FROM_MISSP_REPLYTO | 2.401 | From misspaced, has Reply-To |
| FROM_MISSP_SPF_FAIL | 1.893 | |
| FROM_MISSP_USER | 1.485 | From misspaced, from "User" |
| FROM_MISSP_XPRIO | 1.69 | Misspaced FROM + X-Priority |
| FROM_MULTI_NORDNS | 3.11 | Multiple From addresses + no rDNS |
| FROM_NEWDOM_BTC | 1 | Newdomain with Bitcoin ID |
| FROM_NO_USER | 2.599 | From: has no local-part before @ sign |
| FROM_NTLD_LINKBAIT | 1 | From abused NTLD with little more than a URI |
| FROM_NTLD_REPLY_FREEMAIL | 0.004 | From abused NTLD and Reply-To is FREEMAIL |
| FROM_NUMBERO_NEWDOMAIN | 1 | Fingerprint and new domain |
| FROM_OFFERS | 1 | From address is "at something-offers" |
| FROM_PAYPAL_SPOOF | 0.738 | From PayPal domain but matches SPOOFED |
| FROM_STARTS_WITH_NUMS | 0.553 | From: starts with several numbers |
| FROM_SUSPICIOUS_NTLD | 0.499 | From abused NTLD |
| FROM_SUSPICIOUS_NTLD_FP | 1.999 | From abused NTLD |
| FROM_UNBAL1 | 2.699 | From with unbalanced angle brackets, '>' missing |
| FROM_WSP_LEAD | 3.099 | Leading whitespace after '<' in From header field |
| FROM_WSP_TRAIL | 2.9 | Trailing whitespace before '>' in From header field |
| FSL_BULK_SIG | 0.001 | Bulk signature with no Unsubscribe |
| FSL_CTYPE_WIN1251 | 0.328 | Content-Type only seen in 419 spam |
| FSL_FAKE_HOTMAIL_RVCD | 1.816 | |
| FSL_HELO_BARE_IP_1 | 1.426 | |
| FSL_HELO_BARE_IP_2 | 2.104 | |
| FSL_HELO_DEVICE | 0.1 | |
| FSL_HELO_NON_FQDN_1 | 0.001 | |
| FSL_HELO_SETUP | – | |
| FSL_INTERIA_ABUSE | 2.664 | |
| FSL_NEW_HELO_USER | 0.001 | Spam's using Helo and User |
| FUZZY_AFFORDABLE | – | Attempt to obfuscate words in spam |
| FUZZY_AMAZON | 1 | Obfuscated "amazon" |
| FUZZY_ANDROID | 1 | Obfuscated "android" |
| FUZZY_APPLE | 2.299 | Obfuscated "apple" |
| FUZZY_BILLION | – | Attempt to obfuscate words in spam |
| FUZZY_BITCOIN | 1.321 | Obfuscated "Bitcoin" |
| FUZZY_BROWSER | 1 | Obfuscated "browser" |
| FUZZY_BTC_WALLET | 1 | Heavily obfuscated "bitcoin wallet" |
| FUZZY_CLICK_HERE | 1 | Obfuscated "click here" |
| FUZZY_CPILL | 0.001 | Attempt to obfuscate words in spam |
| FUZZY_CREDIT | 1.413 | Attempt to obfuscate words in spam |
| FUZZY_DOLLARS | 1 | Obfuscated "dollar" or "dollars" |
| FUZZY_DR_OZ | 1 | Obfuscated Doctor Oz |
| FUZZY_FACEBOOK | 1 | Obfuscated "facebook" |
| FUZZY_GUARANTEE | – | Attempt to obfuscate words in spam |
| FUZZY_HARRIS | 1 | Obfuscated "Harris" |
| FUZZY_IMPORTANT | 1 | Obfuscated "important" |
| FUZZY_MALICIOUS | 1 | Obfuscated "malicious" |
| FUZZY_MEDICATION | – | Attempt to obfuscate words in spam |
| FUZZY_MERIDIA | – | Obfuscation of the word "meridia" |
| FUZZY_MICROSOFT | 1 | Obfuscated "microsoft" |
| FUZZY_MILLION | 0.1 | Attempt to obfuscate words in spam |
| FUZZY_MONERO | 1 | Obfuscated "Monero" |
| FUZZY_MONEY | – | Attempt to obfuscate words in spam |
| FUZZY_MORTGAGE | – | Attempt to obfuscate words in spam |
| FUZZY_NORTON | 1 | Obfuscated "norton" |
| FUZZY_OBLIGATION | – | Attempt to obfuscate words in spam |
| FUZZY_OFFERS | – | Attempt to obfuscate words in spam |
| FUZZY_OVERSTOCK | 1 | Obfuscated "overstock" |
| FUZZY_PAYPAL | 1 | Obfuscated "paypal" |
| FUZZY_PHARMACY | 3.299 | Attempt to obfuscate words in spam |
| FUZZY_PHENT | 1.647 | Attempt to obfuscate words in spam |
| FUZZY_PORN | 1 | Obfuscated "Pornography" or "Pornographic" |
| FUZZY_PRESCRIPT | – | Attempt to obfuscate words in spam |
| FUZZY_PRICES | 0.72 | Attempt to obfuscate words in spam |
| FUZZY_PRIVACY | 1 | Obfuscated "privacy" |
| FUZZY_PROMOTION | 1 | Obfuscated "promotion" |
| FUZZY_REFINANCE | – | Attempt to obfuscate words in spam |
| FUZZY_REMOVE | – | Attempt to obfuscate words in spam |
| FUZZY_SAVINGS | 1 | Obfuscated "savings" |
| FUZZY_SECURITY | 2.299 | Obfuscated "security" |
| FUZZY_SOFTWARE | – | Attempt to obfuscate words in spam |
| FUZZY_THOUSANDS | – | Attempt to obfuscate words in spam |
| FUZZY_TRUSTWALLET | 1 | Obfuscated "Trust Wallet", probable phishing |
| FUZZY_UNINSTALL | 1 | Obfuscated "uninstall" |
| FUZZY_UNSUBSCRIBE | 1 | Obfuscated "unsubscribe" |
| FUZZY_VIOXX | – | Attempt to obfuscate words in spam |
| FUZZY_VLIUM | – | Attempt to obfuscate words in spam |
| FUZZY_VPILL | 0.494 | Attempt to obfuscate words in spam |
| FUZZY_WALLET | 1 | Obfuscated "Wallet" |
| FUZZY_WELLSFARGO | 1 | Obfuscated "Wells Fargo" |
| FUZZY_XPILL | 0.1 | Attempt to obfuscate words in spam |
| GAPPY_SALES_LEADS_FREEM | 1 | Obfuscated marketing text, freemail or CHN replyto |
| GAPPY_SUBJECT | 0.1 | Subject: contains G.a.p.p.y-T.e.x.t |
| GB_BITCOIN_CP | 0.528 | Localized Bitcoin scam |
| GB_CUSTOM_HTM_URI | 0.012 | Custom html uri |
| GB_FAKE_LISTUNSUB | 1.499 | Fake List-Unsubscribe header |
| GB_FAKE_RF_SHORT | 1 | Fake reply or forward with url shortener |
| GB_FORGED_MUA_POSTFIX | 1 | Forged Postfix mua headers |
| GB_FREEMAIL_DISPTO | 0.499 | Disposition-Notification-To/From or Disposition-Notification-To/body contain different freemails |
| GB_FREEMAIL_DISPTO_NOTFREEM | 0.499 | Disposition-Notification-To/From contain different freemails but mailfrom is not a freemail |
| GB_FROM_METAMASK | 1 | Metamask spam |
| GB_GOOGLE_OBFUR | 0.75 | Obfuscate url through Google redirect |
| GB_HASHBL_BTC | 0.96 | Message contains BTC address found on BTCBL |
| GEO_QUERY_STRING | – | |
| GMD_PDF_EMPTY_BODY | 0.25 | Attached PDF with empty message body |
| GMD_PDF_ENCRYPTED | 0.6 | Attached PDF is encrypted |
| GMD_PDF_HORIZ | 0.25 | Contains pdf 100-240 (high) x 450-800 (wide) |
| GMD_PDF_SQUARE | 0.5 | Contains pdf 180-360 (high) x 180-360 (wide) |
| GMD_PDF_VERT | 0.9 | Contains pdf 450-800 (high) x 100-240 (wide) |
| GMD_PRODUCER_EASYPDF | 0.25 | PDF producer was BCL easyPDF |
| GMD_PRODUCER_GPL | 0.25 | PDF producer was GPL Ghostscript |
| GMD_PRODUCER_POWERPDF | 0.25 | PDF producer was PowerPDF |
| GOOGLE_DOCS_PHISH | 1 | Possible phishing via a Google Docs form |
| GOOGLE_DOCS_PHISH_MANY | 1 | Phishing via a Google Docs form |
| GOOGLE_DOC_SUSP | 1 | Suspicious use of Google Docs |
| GOOGLE_DRIVE_REPLY_BAD_NTLD | 1 | From Google Drive and Reply-To is from a suspicious TLD |
| GOOG_MALWARE_DNLD | 1 | File download via Google - Malware? |
| GOOG_REDIR_DOCUSIGN | 1 | Indirect docusign link, probable phishing |
| GOOG_REDIR_FRAUD | 1 | Google redirect to obscure spamvertised website + fraud keywords |
| GOOG_REDIR_HTML_ONLY | 1.499 | Google redirect to obscure spamvertised website + HTML only |
| GOOG_REDIR_NORDNS | 1.499 | Google redirect to obscure spamvertised website + no rDNS |
| GOOG_REDIR_NOTRDNS | 1.146 | Google redirect to obscure spamvertised website + HELO is not rDNS |
| GOOG_REDIR_SHORT | 1 | Google redirect to obscure spamvertised website + short message |
| GOOG_REDIR_STATICRDNS | 1 | Google redirect to obscure spamvertised website + static rDNS |
| GOOG_STO_EMAIL_PHISH | 2.999 | Possible phishing with google hosted content URI having email address |
| GOOG_STO_HTML_PHISH | 1 | Possible phishing with google content hosting to avoid URIBL |
| GOOG_STO_HTML_PHISH_MANY | 1 | Phishing with google content hosting to avoid URIBL |
| GOOG_STO_IMG_HTML | 1 | Apparently using google content hosting to avoid URIBL |
| GOOG_STO_IMG_NOHTML | 1 | Apparently using google content hosting to avoid URIBL |
| GOOG_STO_NOIMG_HTML | 2.999 | Apparently using google content hosting to avoid URIBL |
| GTUBE | 1000 | Generic Test for Unsolicited Bulk Email |
| GUARANTEED_100_PERCENT | 2.699 | One hundred percent guaranteed |
| HAS_X_NO_RELAY | 1 | Has spammy header |
| HAS_X_OUTGOING_SPAM_STAT | 1 | Has header claiming outbound spam scan - why trust the results? |
| HDRS_LCASE | 0.043 | Odd capitalization of message header |
| HDRS_MISSP | 1 | Misspaced headers |
| HDR_ORDER_FTSDMCXX_001C | – | Header order similar to spam (FTSDMCXX/MID variant) |
| HDR_ORDER_FTSDMCXX_BAT | – | Header order similar to spam (FTSDMCXX/boundary variant) |
| HDR_ORDER_FTSDMCXX_DIRECT | 1.886 | Header order similar to spam (FTSDMCXX/boundary variant) + direct-to-MX |
| HDR_ORDER_FTSDMCXX_NORDNS | 2.539 | Header order similar to spam (FTSDMCXX/boundary variant) + no rDNS |
| HEADER_COUNT_CTYPE | – | Multiple Content-Type headers found |
| HEADER_COUNT_SUBJECT | – | Multiple Subject headers found |
| HEADER_FROM_DIFFERENT_DOMAINS | 0.249 | From and EnvelopeFrom 2nd level mail domains are different |
| HEADER_SPAM | 2.499 | Bulk email fingerprint (header-based) found |
| HEAD_ILLEGAL_CHARS | – | Headers have too many raw illegal characters |
| HEAD_LONG | – | Message headers are very long |
| HELO_DYNAMIC_CHELLO_NL | 1.918 | Relay HELO'd using suspicious hostname (Chello.nl) |
| HELO_DYNAMIC_DHCP | 0.841 | Relay HELO'd using suspicious hostname (DHCP) |
| HELO_DYNAMIC_DIALIN | 3.233 | Relay HELO'd using suspicious hostname (T-Dialin) |
| HELO_DYNAMIC_HCC | 2.514 | Relay HELO'd using suspicious hostname (HCC) |
| HELO_DYNAMIC_HEXIP | 0.511 | Relay HELO'd using suspicious hostname (Hex IP) |
| HELO_DYNAMIC_HOME_NL | 1.53 | Relay HELO'd using suspicious hostname (Home.nl) |
| HELO_DYNAMIC_IPADDR | 3.243 | Relay HELO'd using suspicious hostname (IP addr 1) |
| HELO_DYNAMIC_IPADDR2 | 3.888 | Relay HELO'd using suspicious hostname (IP addr 2) |
| HELO_DYNAMIC_ROGERS | – | Relay HELO'd using suspicious hostname (Rogers) |
| HELO_DYNAMIC_SPLIT_IP | 2.893 | Relay HELO'd using suspicious hostname (Split IP) |
| HELO_FRIEND | – | |
| HELO_LH_HOME | 2.023 | |
| HELO_LH_LD | – | |
| HELO_LOCALHOST | 3.603 | |
| HELO_MISC_IP | 0.25 | Looking for more Dynamic IP Relays |
| HELO_NO_DOMAIN | 1.941 | Relay reports its domain incorrectly |
| HELO_OEM | 2.899 | |
| HELO_STATIC_HOST | -0.001 | Relay HELO'd using static hostname |
| HEXHASH_WORD | 1 | Multiple instances of word + hexadecimal hash |
| HIDE_WIN_STATUS | 0.001 | Javascript to hide URLs in browser |
| HIGH_CODEPAGE_URI | – | |
| HK_CTE_RAW | 1 | |
| HK_NAME_DRUGS | 0.001 | From name contains drugs |
| HK_NAME_MR_MRS | 0.999 | |
| HK_RANDOM_ENVFROM | 0.742 | Envelope sender username looks random |
| HK_RANDOM_FROM | 1 | From username looks random |
| HK_RANDOM_REPLYTO | 0.999 | Reply-To username looks random |
| HK_RCVD_IP_MULTICAST | 1 | |
| HK_SCAM | 0.001 | |
| HOSTED_IMG_DIRECT_MX | 3.499 | Image hosted at large ecomm, CDN or hosting site, message direct-to-mx |
| HOSTED_IMG_DQ_UNSUB | 1 | Image hosted at large ecomm, CDN or hosting site, IP addr unsub link |
| HOSTED_IMG_FREEM | 1 | Image hosted at large ecomm, CDN or hosting site or redirected, freemail from or reply-to |
| HOSTED_IMG_MULTI | 1 | Multiple images hosted at different large ecomm, CDN or hosting sites, free image sites, or redirected |
| HOSTED_IMG_MULTI_PUB_01 | 2.999 | Multiple hosted images at public site |
| HREF_EMPTY_NORDNS | 1.478 | Empty href + no rDNS |
| HREF_EMPTY_PHPMAIL | 1 | Empty href + PHP Mailer |
| HREF_EMPTY_XANTIABUSE | 1 | Empty href + X-AntiAbuse |
| HREF_EMPTY_XAUTHED | 1 | Empty href + X-Authenticated-Sender |
| HTML_BADTAG_40_50 | – | HTML message is 40% to 50% bad tags |
| HTML_BADTAG_50_60 | – | HTML message is 50% to 60% bad tags |
| HTML_BADTAG_60_70 | – | HTML message is 60% to 70% bad tags |
| HTML_BADTAG_90_100 | – | HTML message is 90% to 100% bad tags |
| HTML_CHARSET_FARAWAY | 0.5 | A foreign language charset used in HTML markup |
| HTML_COMMENT_SAVED_URL | 0.357 | HTML message is a saved web page |
| HTML_COMMENT_SHORT | – | HTML comment is very short |
| HTML_EMBEDS | 0.001 | HTML with embedded plugin object |
| HTML_ENTITY_ASCII | 1 | Obfuscated ASCII |
| HTML_ENTITY_ASCII_TINY | 1 | Obfuscated ASCII + tiny fonts |
| HTML_EXTRA_CLOSE | 0.001 | HTML contains far too many close tags |
| HTML_FONT_FACE_BAD | 0.001 | HTML font face is not a word |
| HTML_FONT_LOW_CONTRAST | 0.001 | HTML font color similar or identical to background |
| HTML_FONT_SIZE_HUGE | 0.001 | HTML font size is huge |
| HTML_FONT_SIZE_LARGE | 0.001 | HTML font size is large |
| HTML_FONT_TINY_NORDNS | 1.999 | Font too small to read, no rDNS |
| HTML_FORMACTION_MAILTO | – | HTML includes a form which sends mail |
| HTML_IFRAME_SRC | – | Message has HTML IFRAME tag with SRC URI |
| HTML_IMAGE_ONLY_04 | 0.342 | HTML: images with 0-400 bytes of words |
| HTML_IMAGE_ONLY_08 | 1.781 | HTML: images with 400-800 bytes of words |
| HTML_IMAGE_ONLY_12 | 1.629 | HTML: images with 800-1200 bytes of words |
| HTML_IMAGE_ONLY_16 | 1.048 | HTML: images with 1200-1600 bytes of words |
| HTML_IMAGE_ONLY_20 | 0.7 | HTML: images with 1600-2000 bytes of words |
| HTML_IMAGE_ONLY_24 | 1.282 | HTML: images with 2000-2400 bytes of words |
| HTML_IMAGE_ONLY_28 | 0.726 | HTML: images with 2400-2800 bytes of words |
| HTML_IMAGE_ONLY_32 | 0.001 | HTML: images with 2800-3200 bytes of words |
| HTML_IMAGE_RATIO_02 | 0.001 | HTML has a low ratio of text to image area |
| HTML_IMAGE_RATIO_04 | 0.001 | HTML has a low ratio of text to image area |
| HTML_IMAGE_RATIO_06 | 0.001 | HTML has a low ratio of text to image area |
| HTML_IMAGE_RATIO_08 | 0.001 | HTML has a low ratio of text to image area |
| HTML_MESSAGE | 0.001 | HTML included in message |
| HTML_MIME_NO_HTML_TAG | 0.635 | HTML-only message, but there is no HTML tag |
| HTML_MISSING_CTYPE | – | Message is HTML without HTML Content-Type |
| HTML_NONELEMENT_30_40 | 0.001 | 30% to 40% of HTML elements are non-standard |
| HTML_NONELEMENT_40_50 | – | 40% to 50% of HTML elements are non-standard |
| HTML_NONELEMENT_60_70 | – | 60% to 70% of HTML elements are non-standard |
| HTML_NONELEMENT_80_90 | – | 80% to 90% of HTML elements are non-standard |
| HTML_OBFUSCATE_05_10 | 0.001 | Message is 5% to 10% HTML obfuscation |
| HTML_OBFUSCATE_10_20 | 1.162 | Message is 10% to 20% HTML obfuscation |
| HTML_OBFUSCATE_20_30 | 2.441 | Message is 20% to 30% HTML obfuscation |
| HTML_OBFUSCATE_30_40 | – | Message is 30% to 40% HTML obfuscation |
| HTML_OBFUSCATE_50_60 | – | Message is 50% to 60% HTML obfuscation |
| HTML_OBFUSCATE_70_80 | – | Message is 70% to 80% HTML obfuscation |
| HTML_OBFUSCATE_90_100 | 2 | Message is 90% to 100% HTML obfuscation |
| HTML_OFF_PAGE | 1 | HTML element rendered well off the displayed page |
| HTML_SHORT_CENTER | 3.421 | HTML is very short with CENTER tag |
| HTML_SHORT_LINK_IMG_1 | 0.139 | HTML is very short with a linked image |
| HTML_SHORT_LINK_IMG_2 | 0.259 | HTML is very short with a linked image |
| HTML_SHORT_LINK_IMG_3 | 0.328 | HTML is very short with a linked image |
| HTML_SHRT_CMNT_OBFU_MANY | 1 | Obfuscation with many short HTML comments |
| HTML_SINGLET_MANY | 1 | Many single-letter HTML format blocks |
| HTML_TAG_BALANCE_BODY | 0.1 | HTML has unbalanced "body" tags |
| HTML_TAG_BALANCE_CENTER | 3.899 | Malformatted HTML |
| HTML_TAG_BALANCE_HEAD | – | HTML has unbalanced "head" tags |
| HTML_TAG_EXIST_BGSOUND | – | HTML has "bgsound" tag |
| HTML_TEXT_INVISIBLE_FONT | 0.001 | HTML hidden text - word obfuscation? |
| HTML_TEXT_INVISIBLE_STYLE | 1 | HTML hidden text + other spam signs |
| HTML_TITLE_SUBJ_DIFF | 2.171 | |
| HTTPS_HTTP_MISMATCH | 0.1 | |
| HTTPS_IP_MISMATCH | – | IP to HTTPS link found in HTML |
| HTTP_77 | – | Contains an URL-encoded hostname (HTTP77) |
| HTTP_ESCAPED_HOST | 0.1 | Uses %-escapes inside a URL's hostname |
| HTTP_EXCESSIVE_ESCAPES | 0.001 | Completely unnecessary %-escapes inside a URL |
| IMG_DIRECT_TO_MX | 3.399 | |
| IMG_ONLY_FM_DOM_INFO | 1 | HTML image-only message from .info domain |
| IMPOTENCE | 2.144 | Impotence cure |
| INVALID_DATE | 0.432 | Invalid Date: header (not RFC 2822) |
| INVALID_DATE_TZ_ABSURD | 0.632 | Invalid Date: header (timezone does not exist) |
| INVALID_MSGID | 1.167 | Message-Id is not valid, according to RFC 2822 |
| INVALID_TZ_CST | – | Invalid date in header (wrong CST timezone) |
| INVALID_TZ_EST | – | Invalid date in header (wrong EST timezone) |
| INVESTMENT_ADVICE | 0.1 | Message mentions investment advice |
| IP_LINK_PLUS | 0.001 | Dotted-decimal IP address followed by CGI |
| JAPANESE_UCE_BODY | – | Body contains Japanese UCE tag |
| JAPANESE_UCE_SUBJECT | – | Subject contains a Japanese UCE tag |
| JH_SPAMMY_HEADERS | 1 | Has unusual message header(s) seen primarily in spam |
| JH_SPAMMY_PATTERN01 | 1 | Unusual pattern seen in spam campaign |
| JH_SPAMMY_PATTERN02 | 1 | Unusual pattern seen in spam campaign |
| JM_I_FEEL_LUCKY | – | |
| JM_RCVD_QMAILV1 | – | |
| JM_TORA_XM | – | |
| JOIN_MILLIONS | 0.1 | Join Millions of Americans |
| JS_FROMCHARCODE | – | Document is built from a Javascript charcode array |
| KB_DATE_CONTAINS_TAB | 3.799 | |
| KB_FAKED_THE_BAT | 3.441 | |
| KB_RATWARE_BOUNDARY | – | |
| KB_RATWARE_MSGID | 2.987 | |
| KB_RATWARE_OUTLOOK_08 | – | |
| KB_RATWARE_OUTLOOK_12 | – | |
| KB_RATWARE_OUTLOOK_16 | – | |
| KB_RATWARE_OUTLOOK_MID | 4.4 | |
| KHOP_FAKE_EBAY | 1 | Sender falsely claims to be from eBay |
| KHOP_HELO_FCRDNS | 0.4 | Relay HELO differs from its IP's reverse DNS |
| KOREAN_UCE_SUBJECT | – | Subject: contains Korean unsolicited email tag |
| LINKEDIN_IMG_NOT_RCVD_LNKN | 1 | Linkedin hosted image but message not from Linkedin |
| LIST_PRTL_PUMPDUMP | 1 | Incomplete List-* headers and stock pump-and-dump |
| LIST_PRTL_SAME_USER | 1 | Incomplete List-* headers and from+to user the same |
| LIVEFILESTORE | 0.1 | |
| LIVE_PORN | – | Possible porn - Live Porn |
| LOCALPART_IN_SUBJECT | 0.73 | Local part of To: address appears in Subject |
| LONGWORDS | 1 | Long string of long words |
| LONG_HEX_URI | 1 | Very long purely hexadecimal URI |
| LONG_IMG_URI | 0.626 | Image URI with very long path component - web bug? |
| LONG_INVISIBLE_TEXT | 0.644 | Long block of hidden text - bayes poison? |
| LONG_TERM_PRICE | 0.001 | |
| LOOPHOLE_1 | – | A loop hole in the banking laws? |
| LOTS_OF_MONEY | 0.001 | Huge... sums of money |
| LOTTERY_1 | 1.488 | |
| LOTTERY_PH_004470 | 0.1 | |
| LOW_PRICE | 0.1 | Lowest Price |
| LUCRATIVE | 0.642 | Make lots of money! |
| L_SPAM_TOOL_13 | 0.485 | |
| MAILING_LIST_MULTI | 1 | Multiple indicators imply a widely-seen list manager |
| MALE_ENHANCE | 3.099 | Message talks about enhancing men |
| MALF_HTML_B64 | 1 | Malformatted base64-encoded HTML content |
| MALWARE_NORDNS | 1 | Malware bragging + no rDNS |
| MALWARE_PASSWORD | 1 | Malware bragging + "password" |
| MALW_ATTACH | 3.5 | Attachment filename suspicious, probable malware exploit |
| MANY_HDRS_LCASE | 0.1 | Odd capitalization of multiple message headers |
| MANY_SPAN_IN_TEXT | 1 | Many <SPAN> tags embedded within text |
| MARKETING_PARTNERS | 0.235 | Claims you registered with a partner |
| MAY_BE_FORGED | 3.099 | Relay IP's reverse DNS does not resolve to IP |
| MC_MSFT_LISTMGR | 1 | Mailchimp campaign uses Microsoft brand as list-manage subdomain |
| MICROSOFT_EXECUTABLE | 0.1 | Message includes Microsoft executable program |
| MID_DEGREES | – | |
| MILLION_HUNDRED | 2.499 | Million "One to Nine" Hundred |
| MILLION_USD | 1.999 | Talks about millions of dollars |
| MIMEOLE_DIRECT_TO_MX | 1.999 | MIMEOLE + direct-to-MX |
| MIMEPART_LIMIT_EXCEEDED | 0.001 | Message has too many MIME parts |
| MIME_BAD_ISO_CHARSET | – | MIME character set is an unknown ISO charset |
| MIME_BASE64_TEXT | 0.001 | Message text disguised using base64 encoding |
| MIME_BOUND_DD_DIGITS | 0.349 | Spam tool pattern in MIME boundary |
| MIME_BOUND_DIGITS_15 | 0.1 | Spam tool pattern in MIME boundary |
| MIME_BOUND_EQ_REL | – | |
| MIME_BOUND_MANY_HEX | – | Spam tool pattern in MIME boundary |
| MIME_CHARSET_FARAWAY | 2.45 | MIME character set indicates foreign language |
| MIME_HEADER_CTYPE_ONLY | 0.1 | 'Content-Type' found without required MIME headers |
| MIME_HTML_MOSTLY | 0.1 | Multipart message mostly text/html MIME |
| MIME_HTML_ONLY | 0.1 | Message only has text/html MIME parts |
| MIME_HTML_ONLY_MULTI | 0.001 | Multipart message only has text/html MIME parts |
| MIME_NO_TEXT | 0.001 | No (properly identified) text body parts |
| MIME_PHP_NO_TEXT | 2.799 | No text body parts, X-Mailer: PHP |
| MIME_QP_LONG_LINE | 0.001 | Quoted-printable line longer than 76 chars |
| MIME_SUSPECT_NAME | 0.1 | MIME filename does not match content |
| MISSING_DATE | 1.396 | Missing Date: header |
| MISSING_FROM | 1 | Missing From: header |
| MISSING_HB_SEP | – | Missing blank line between message header and body |
| MISSING_HEADERS | 1.207 | Missing To: header |
| MISSING_MID | 0.14 | Missing Message-Id: header |
| MISSING_MIMEOLE | 1.843 | Message has X-MSMail-Priority, but no X-MimeOLE |
| MISSING_MIME_HB_SEP | 0.001 | Missing blank line between MIME header and body |
| MISSING_SUBJECT | 1.767 | Missing Subject: header |
| MIXED_AREA_CASE | 1 | Has area tag in mixed case |
| MIXED_CENTER_CASE | 1 | Has center tag in mixed case |
| MIXED_ES | 0.108 | Too many es are not es |
| MIXED_FONT_CASE | 1 | Has font tag in mixed case |
| MIXED_HREF_CASE | 2 | Has href in mixed case |
| MIXED_IMG_CASE | 1 | Has img tag in mixed case |
| MONERO_DEADLINE | 1 | Monero cryptocurrency with a deadline |
| MONERO_EXTORT_01 | 1 | Extortion spam, pay via Monero cryptocurrency |
| MONERO_MALWARE | 1 | Monero cryptocurrency + malware bragging |
| MONERO_PAY_ME | 1 | Pay me via Monero cryptocurrency |
| MONEY_BACK | 1 | Money back guarantee |
| MONEY_FRAUD_3 | 2.699 | Lots of money and several fraud phrases |
| MONEY_FRAUD_5 | 2.497 | Lots of money and many fraud phrases |
| MONEY_FRAUD_8 | 0.001 | Lots of money and very many fraud phrases |
| MONEY_FREEMAIL_REPTO | 0.838 | Lots of money from someone using free email? |
| MONEY_FROM_41 | 0.989 | Lots of money from Africa |
| MONEY_FROM_MISSP | 0.001 | Lots of money and misspaced From |
| MORE_SEX | 2.765 | Talks about a bigger drive for sex |
| MPART_ALT_DIFF | 0.724 | HTML and text parts are different |
| MPART_ALT_DIFF_COUNT | 1.483 | HTML and text parts are different |
| MSGID_DOLLARS_RANDOM | – | |
| MSGID_DOLLARS_URI_IMG | 1 | Suspicious Message-ID and image |
| MSGID_FROM_MTA_HEADER | 0.001 | Message-Id was added by a relay |
| MSGID_HDR_MALF | 1 | Has invalid message ID header |
| MSGID_MULTIPLE_AT | 1 | Message-ID contains multiple '@' characters |
| MSGID_OUTLOOK_INVALID | 3.899 | Message-Id is fake (in Outlook Express format) |
| MSGID_RANDY | 2.599 | Message-Id has pattern used in spam |
| MSGID_SHORT | 0.337 | Message-ID is unusually short |
| MSGID_SPAM_CAPS | 1.997 | Spam tool Message-Id: (caps variant) |
| MSGID_SPAM_LETTERS | – | Spam tool Message-Id: (letters variant) |
| MSGID_YAHOO_CAPS | 1.413 | Message-ID has ALLCAPS@yahoo.com |
| MSM_PRIO_REPTO | 2.079 | MSMail priority header + Reply-to + short subject |
| MSOE_MID_WRONG_CASE | 3.373 | |
| MULTIPART_ALT_NON_TEXT | – | |
| MULTI_FORGED | – | Received headers indicate multiple forgeries |
| MXG_EMAIL_FRAG | 0.1 | URI with email in fragment |
| MXG_SPOOFED_DOCUSIGN | 0.1 | Docusign spoofing |
| NAME_EMAIL_DIFF | 0.821 | Sender NAME is an unrelated email address |
| NEWEGG_IMG_NOT_RCVD_NEGG | 1 | Newegg hosted image but message not from Newegg |
| NEW_PRODUCTS | 1.249 | |
| NICE_REPLY_A | -0.001 | Looks like a legit reply (A) |
| NML_ADSP_CUSTOM_HIGH | 2.6 | ADSP custom_high hit, and not from a mailing list |
| NML_ADSP_CUSTOM_LOW | 0.7 | ADSP custom_low hit, and not from a mailing list |
| NML_ADSP_CUSTOM_MED | 1.2 | ADSP custom_med hit, and not from a mailing list |
| NONEXISTENT_CHARSET | – | Character set doesn't exist |
| NORDNS_LOW_CONTRAST | 2.499 | No rDNS + hidden text |
| NORMAL_HTTP_TO_IP | 0.001 | URI host has a public dotted-decimal IPv4 address |
| NOT_ADVISOR | – | Not registered investment advisor |
| NOT_SPAM | 1 | I'm not spam! Really! I'm not, I'm not, I'm not! |
| NO_DNS_FOR_FROM | 0.379 | Envelope sender has no MX or A DNS records |
| NO_FM_NAME_IP_HOSTN | 1.515 | No From name + hostname using IP address |
| NO_HEADERS_MESSAGE | 0.001 | Message appears to be missing most RFC-822 headers |
| NO_MEDICAL | 1.254 | No Medical Exams |
| NO_PRESCRIPTION | 1.102 | No prescription needed |
| NO_RDNS_DOTCOM_HELO | 0.433 | Host HELO'd as a big ISP, but had no rDNS |
| NO_RECEIVED | -0.001 | Informational: message has no Received headers |
| NO_RELAYS | -0.001 | Informational: message was not relayed via SMTP |
| NSL_RCVD_FROM_USER | 0.001 | Received from User |
| NSL_RCVD_HELO_USER | 0.864 | Received from HELO User |
| NULL_IN_BODY | 0.498 | Message has NUL (ASCII 0) byte in message |
| NUMBERONLY_BITCOIN_EXP | 0.001 | Domain ends in a large number and very short body with link |
| NUMERIC_HTTP_ADDR | 0.001 | Uses a numeric IP address in URL |
| OBFUSCATING_COMMENT | – | HTML comments which obfuscate text |
| OBFU_BITCOIN | 2.999 | Obfuscated BitCoin references |
| OBFU_HTML_ATTACH | 1.687 | HTML attachment with non-text MIME type |
| OBFU_JVSCR_ESC | 1 | Injects content using obfuscated javascript |
| OBFU_TEXT_ATTACH | – | Text attachment with non-text MIME type |
| OBFU_UNSUB_UL | 1 | Obfuscated unsubscribe text |
| OBSCURED_EMAIL | – | Message seems to contain rot13ed address |
| ODD_FREEM_REPTO | 2.243 | Has unusual reply-to header |
| ONE_TIME | 1.175 | One Time Rip Off |
| ONLINE_PHARMACY | 2.371 | Online Pharmacy |
| OOOBOUNCE_MESSAGE | 0.1 | Out Of Office bounce message |
| PART_CID_STOCK | 0.001 | Has a spammy image attachment (by Content-ID) |
| PART_CID_STOCK_LESS | 0.036 | Has a spammy image attachment (by Content-ID, more specific) |
| PAYPAL_PHISH_07 | 1 | Paypal mail passed through both paypal and MSFT infrastructure; high fraud probability |
| PDS_BAD_THREAD_QP_64 | 0.999 | Bad thread header - short QP |
| PDS_BTC_ID | 0.5 | FP reduced Bitcoin ID |
| PDS_BTC_MSGID | 0.809 | Bitcoin ID with T_MSGID_NOFQDN2 |
| PDS_DBL_URL_TNB_RUNON | 1.999 | Double-url and To no arrows, from runon |
| PDS_FRNOM_TODOM_DBL_URL | 1.499 | From Name to domain, double URL |
| PDS_FRNOM_TODOM_NAKED_TO | 0.13 | Naked to From name equals to Domain |
| PDS_FROM_2_EMAILS | 1.597 | From header has multiple different addresses |
| PDS_FROM_NAME_TO_DOMAIN | 1.696 | From:name looks like To:domain |
| PDS_HELO_SPF_FAIL | 1 | High profile HELO that fails SPF |
| PDS_NAKED_TO_NUMERO | 1.999 | Naked-to, numberonly domain |
| PDS_NO_FULL_NAME_SPOOFED_URL | 0.749 | HTML message short, T_SPOOFED_URL and T_KHOP_NO_FULL_NAME |
| PDS_RDNS_DYNAMIC_FP | 0.01 | RDNS_DYNAMIC with FP steps |
| PERCENT_RANDOM | 2.837 | Message has a random macro in it |
| PHISH_ATTACH | 3.5 | Attachment filename suspicious, probable phishing |
| PHISH_AZURE_CLOUDAPP | 3.5 | Link to known phishing web application |
| PHISH_FBASEAPP | 1 | Probable phishing via hosted web app |
| PHONE_983_NOVEL | 1 | Body contains phone number in unassigned NANP area code 983 |
| PHP_NOVER_MUA | 1 | Mail from PHP with no version number |
| PHP_ORIG_SCRIPT | 0.746 | Sent by bot & other signs |
| PHP_SCRIPT | 2.499 | Sent by PHP script |
| PHP_SCRIPT_MUA | 1 | Sent by PHP script, no version number |
| PLING_QUERY | 0.1 | Subject has exclamation mark and question mark |
| POSSIBLE_AMAZON_PHISH_03 | 1 | Amazon Prime phishing via Google Draw |
| POSSIBLE_APPLE_PHISH_02 | 1 | Claims to be from apple but not processed by any apple MTA |
| POSSIBLE_EBAY_PHISH_02 | 1 | Claims to be from ebay but not processed by any ebay MTA |
| POSSIBLE_GMAIL_PHISHER | 3.694 | Apparent phishing email sent from a gmail account |
| POSSIBLE_PAYPAL_PHISH_01 | 1 | Claims to be from paypal but has non-paypal from email address |
| POSSIBLE_PAYPAL_PHISH_02 | 1 | Claims to be from paypal but not processed by any paypal MTA |
| PP_MIME_FAKE_ASCII_TEXT | 0.238 | MIME text/plain claims to be ASCII but isn't |
| PP_TOO_MUCH_UNICODE02 | 0.5 | Is text/plain but has many unicode escapes |
| PP_TOO_MUCH_UNICODE05 | 1 | Is text/plain but has many unicode escapes |
| PREST_NON_ACCREDITED | – | 'Prestigious Non-Accredited Universities' |
| PREVENT_NONDELIVERY | – | Message has Prevent-NonDelivery-Report header |
| PRICES_ARE_AFFORDABLE | 0.851 | Message says that prices aren't too expensive |
| PUMPDUMP | 1 | Pump-and-dump stock scam phrase |
| PUMPDUMP_MULTI | 1 | Pump-and-dump stock scam phrases |
| PUMPDUMP_TIP | 1 | Pump-and-dump stock tip |
| PYZOR_CHECK | 1.985 | Listed in Pyzor (https://pyzor.readthedocs.io/en/latest/) |
| RAND_HEADER_LIST_SPOOF | 1 | Random gibberish message header(s) + pretending to be a mailing list |
| RAND_HEADER_MANY | 1 | Multiple random gibberish message headers |
| RAND_MKTG_HEADER | 1 | Has partially-randomized marketing/tracking header(s) |
| RATWARE_EFROM | 0.1 | Bulk email fingerprint (envfrom) found |
| RATWARE_EGROUPS | 1.258 | Bulk email fingerprint (eGroups) found |
| RATWARE_HASH_DASH | – | Contains a hashbuster in Send-Safe format |
| RATWARE_MOZ_MALFORMED | – | Bulk email fingerprint (Mozilla malformed) found |
| RATWARE_MPOP_WEBMAIL | 1.338 | Bulk email fingerprint (mPOP Web-Mail) |
| RATWARE_MS_HASH | 1 | Bulk email fingerprint (msgid ms hash) found |
| RATWARE_NAME_ID | 0.309 | Bulk email fingerprint (msgid from) found |
| RATWARE_NO_RDNS | 2.529 | Suspicious MsgID and MIME boundary + no rDNS |
| RATWARE_OE_MALFORMED | – | X-Mailer has malformed Outlook Express version |
| RATWARE_OUTLOOK_NONAME | 1 | Bulk email fingerprint (Outlook no name) found |
| RATWARE_RCVD_AT | – | Bulk email fingerprint (Received @) found |
| RATWARE_RCVD_PF | – | Bulk email fingerprint (Received PF) found |
| RATWARE_ZERO_TZ | 2.535 | Bulk email fingerprint (+0000) found |
| RAZOR2_CF_RANGE_51_100 | 2.43 | Razor2 gives confidence level above 50% |
| RAZOR2_CHECK | 1.729 | Listed in Razor2 (http://razor.sf.net/) |
| RCVD_AM_PM | – | Received headers forged (AM/PM) |
| RCVD_BAD_ID | – | Received header contains id field with bad characters |
| RCVD_DBL_DQ | 1 | Malformatted message header |
| RCVD_DOTEDU_SHORT | 1 | Via .edu MTA + short message |
| RCVD_DOTEDU_SUSP_URI | 1 | Via .edu MTA + suspicious URI |
| RCVD_DOUBLE_IP_LOOSE | 0.96 | Received: by and from look like IP addresses |
| RCVD_DOUBLE_IP_SPAM | 2.777 | Bulk email fingerprint (double IP) found |
| RCVD_FAKE_HELO_DOTCOM | 2.389 | Received contains a faked HELO hostname |
| RCVD_FORGED_WROTE | – | Forged 'Received' header found ('wrote:' spam) |
| RCVD_FORGED_WROTE2 | – | |
| RCVD_HELO_IP_MISMATCH | 1.186 | Received: HELO and IP do not match, but should |
| RCVD_ILLEGAL_IP | 1.3 | Received: contains illegal IP address |
| RCVD_IN_BL_SPAMCOP_NET | 1.246 | Received via a relay in bl.spamcop.net |
| RCVD_IN_DNSWL_BLOCKED | 0.001 | ADMINISTRATOR NOTICE: The query to DNSWL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists\#DnsBlocklists-dnsbl-block for more information. |
| RCVD_IN_DNSWL_HI | -5 | Sender listed at https://www.dnswl.org/, high trust |
| RCVD_IN_DNSWL_LOW | -0.7 | Sender listed at https://www.dnswl.org/, low trust |
| RCVD_IN_DNSWL_MED | -2.3 | Sender listed at https://www.dnswl.org/, medium trust |
| RCVD_IN_DNSWL_NONE | -0.0001 | Sender listed at https://www.dnswl.org/, no trust |
| RCVD_IN_IADB_COURT | 1 | IADB: Court-ordered email |
| RCVD_IN_IADB_DK | -0.223 | IADB: Sender publishes Domain Keys record |
| RCVD_IN_IADB_DMARC | 0.001 | IADB: Sender has DMARC record |
| RCVD_IN_IADB_DOPTIN | -4 | IADB: All mailing list mail is confirmed opt-in |
| RCVD_IN_IADB_DOPTIN_GT50 | – | IADB: Confirmed opt-in used more than 50% of the time |
| RCVD_IN_IADB_DOPTIN_LT50 | -0.001 | IADB: Confirmed opt-in used less than 50% of the time |
| RCVD_IN_IADB_ECARD | 1 | IADB: ecard, e-invitation, or similar e-correspondence service |
| RCVD_IN_IADB_EDDB | – | |
| RCVD_IN_IADB_EPIA | – | |
| RCVD_IN_IADB_ESP | -0.001 | IADB: Email Service Provider (ESP) |
| RCVD_IN_IADB_GOODMAIL | – | |
| RCVD_IN_IADB_LEG_BNPROFIT | 1 | IADB: email sent on behalf of a non-profit organization |
| RCVD_IN_IADB_LEG_MAND | 1 | IADB: Legally mandated email |
| RCVD_IN_IADB_LEG_NPROFIT | 1 | IADB: email sent from a non-profit organization |
| RCVD_IN_IADB_LISTED | -0.38 | Participates in the IADB system |
| RCVD_IN_IADB_LOOSE | – | IADB: Adds relationship addrs w/out opt-in |
| RCVD_IN_IADB_MI_CPEAR | – | IADB: Complies with Michigan's CPEAR law |
| RCVD_IN_IADB_MI_CPR_30 | – | |
| RCVD_IN_IADB_MI_CPR_MAT | 0.001 | |
| RCVD_IN_IADB_ML_DOPTIN | -6 | IADB: Mailing list email only, confirmed opt-in |
| RCVD_IN_IADB_NOCONTROL | – | IADB: Has absolutely no mailing controls in place |
| RCVD_IN_IADB_OOO | – | IADB: One-to-one/transactional email only |
| RCVD_IN_IADB_OPTIN | -2.057 | IADB: All mailing list mail is opt-in |
| RCVD_IN_IADB_OPTIN_GT50 | -1.208 | IADB: Opt-in used more than 50% of the time |
| RCVD_IN_IADB_OPTIN_LT50 | – | IADB: Opt-in used less than 50% of the time |
| RCVD_IN_IADB_OPTOUTONLY | – | IADB: Scrapes addresses, pure opt-out only |
| RCVD_IN_IADB_RDNS | -0.167 | IADB: Sender has reverse DNS record |
| RCVD_IN_IADB_SENDERID | -0.001 | IADB: Sender publishes Sender ID record |
| RCVD_IN_IADB_SOCIAL | 1 | IADB: social networking service email |
| RCVD_IN_IADB_SPF | -0.001 | IADB: Sender publishes SPF record |
| RCVD_IN_IADB_TRACK | 1 | IADB: email with open and read tracking services |
| RCVD_IN_IADB_UNVERIFIED_1 | – | IADB: Accepts unverified sign-ups |
| RCVD_IN_IADB_UNVERIFIED_2 | – | IADB: Accepts unverified sign-ups, gives chance to opt out |
| RCVD_IN_IADB_URG | 1 | IADB: time-critical urgent or emergency communications |
| RCVD_IN_IADB_UT_CPEAR | – | IADB: Complies with Utah's CPEAR law |
| RCVD_IN_IADB_UT_CPR_30 | – | |
| RCVD_IN_IADB_UT_CPR_MAT | 0.001 | |
| RCVD_IN_IADB_VOUCHED | -2.2 | ISIPP IADB lists as vouched-for sender |
| RCVD_IN_MAPS_DUL | – | Relay in DUL, http://www.mail-abuse.com/enduserinfo_dul.html |
| RCVD_IN_MAPS_NML | – | Relay in NML, http://www.mail-abuse.com/enduserinfo_nml.html |
| RCVD_IN_MAPS_OPS | – | Relay in OPS, http://www.mail-abuse.com/enduserinfo_ops.html |
| RCVD_IN_MAPS_RBL | – | Relay in RBL, http://www.mail-abuse.com/enduserinfo_rbl.html |
| RCVD_IN_MAPS_RSS | – | Relay in RSS, http://www.mail-abuse.com/enduserinfo_rss.html |
| RCVD_IN_MSPIKE_BL | 0.001 | Mailspike blocklisted |
| RCVD_IN_MSPIKE_H2 | 0.001 | Average reputation (+2) |
| RCVD_IN_MSPIKE_H3 | 0.001 | Good reputation (+3) |
| RCVD_IN_MSPIKE_H4 | 0.001 | Very Good reputation (+4) |
| RCVD_IN_MSPIKE_H5 | 0.001 | Excellent reputation (+5) |
| RCVD_IN_MSPIKE_L2 | 0.001 | Suspicious reputation (-2) |
| RCVD_IN_MSPIKE_L3 | 0.001 | Low reputation (-3) |
| RCVD_IN_MSPIKE_L4 | 0.001 | Bad reputation (-4) |
| RCVD_IN_MSPIKE_L5 | 0.001 | Very bad reputation (-5) |
| RCVD_IN_MSPIKE_WL | 0.001 | Mailspike good senders |
| RCVD_IN_MSPIKE_ZBI | 0.001 | |
| RCVD_IN_PBL | 3.558 | Received via a relay in Spamhaus PBL |
| RCVD_IN_PSBL | 2.7 | Received via a relay in PSBL |
| RCVD_IN_SBL | 2.596 | Received via a relay in Spamhaus SBL |
| RCVD_IN_SBL_CSS | 3.558 | Received via a relay in Spamhaus SBL-CSS |
| RCVD_IN_VALIDITY_CERTIFIED | – | Sender in Validity Certification - Contact certification@validity.com |
| RCVD_IN_VALIDITY_CERTIFIED_BLOCKED | – | ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. |
| RCVD_IN_VALIDITY_RPBL | – | Relay in Validity RPBL, https://senderscore.org/blocklistlookup/ |
| RCVD_IN_VALIDITY_RPBL_BLOCKED | – | ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. |
| RCVD_IN_VALIDITY_SAFE | – | Sender in Validity Safe - Contact certification@validity.com |
| RCVD_IN_VALIDITY_SAFE_BLOCKED | – | ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. |
| RCVD_IN_XBL | 0.724 | Received via a relay in Spamhaus XBL |
| RCVD_IN_ZEN_BLOCKED | 0.001 | ADMINISTRATOR NOTICE: The query to zen.spamhaus.org was blocked. See https://www.spamhaus.org/returnc/vol/ |
| RCVD_IN_ZEN_BLOCKED_OPENDNS | 0.001 | ADMINISTRATOR NOTICE: The query to zen.spamhaus.org was blocked due to usage of an open resolver. See https://www.spamhaus.org/returnc/pub/ |
| RCVD_MAIL_COM | – | Forged Received header (contains post.com or mail.com) |
| RCVD_NUMERIC_HELO | 0.865 | |
| RDNS_DYNAMIC | 0.363 | Delivered to internal network by host with dynamic-looking rDNS |
| RDNS_LOCALHOST | 0.969 | Sender's public rDNS is "localhost" |
| RDNS_NONE | 1.274 | Delivered to internal network by a host with no rDNS |
| RDNS_NUM_TLD_ATCHNX | 1 | Relay rDNS has numeric TLD + suspicious attachment |
| RDNS_NUM_TLD_XM | 1 | Relay rDNS has numeric TLD + suspicious headers |
| REDIR_URL_CHAINED | 0.01 | Message has redirected URL chained to other redirectors |
| REDIR_URL_LOOP | 0.01 | Message has redirected URL that loops back to itself |
| REDIR_URL_MAXCHAIN | 0.01 | Message has redirected URL that causes too many redirections |
| REFINANCE_NOW | – | Home refinancing |
| REFINANCE_YOUR_HOME | – | Home refinancing |
| REMOVE_BEFORE_LINK | 0.1 | Removal phrase right before a link |
| REPLICA_WATCH | 3.164 | Message talks about a replica watch |
| REPLYTO_WITHOUT_TO_CC | 1.946 | |
| REPTO_419_FRAUD | 1 | Reply-To is known advance fee fraud collector mailbox |
| REPTO_419_FRAUD_AOL | 1 | Reply-To is known advance fee fraud collector mailbox |
| REPTO_419_FRAUD_AOL_LOOSE | 1 | Ends-in-digits Reply-To is similar to known advance fee fraud collector mailbox |
| REPTO_419_FRAUD_CNS | 1 | Reply-To is known advance fee fraud collector mailbox |
| REPTO_419_FRAUD_GM | 0.001 | Reply-To is known advance fee fraud collector mailbox |
| REPTO_419_FRAUD_GM_LOOSE | 1 | Ends-in-digits Reply-To is similar to known advance fee fraud collector mailbox |
| REPTO_419_FRAUD_HM | 1 | Reply-To is known advance fee fraud collector mailbox |
| REPTO_419_FRAUD_HM_LOOSE | 1 | Ends-in-digits Reply-To is similar to known advance fee fraud collector mailbox |
| REPTO_419_FRAUD_OL | 1.819 | Reply-To is known advance fee fraud collector mailbox |
| REPTO_419_FRAUD_PM | 1 | Reply-To is known advance fee fraud collector mailbox |
| REPTO_419_FRAUD_QQ | 1 | Reply-To is known advance fee fraud collector mailbox |
| REPTO_419_FRAUD_YH | 1 | Reply-To is known advance fee fraud collector mailbox |
| REPTO_419_FRAUD_YH_LOOSE | 1 | Ends-in-digits Reply-To is similar to known advance fee fraud collector mailbox |
| REPTO_419_FRAUD_YJ | 1 | Reply-To is known advance fee fraud collector mailbox |
| REPTO_419_FRAUD_YN | 1 | Reply-To is known advance fee fraud collector mailbox |
| REPTO_INFONUMSCOM | 1 | |
| REPTO_QUOTE_AOL | – | AOL doesn't do quoting like this |
| REPTO_QUOTE_IMS | – | IMS doesn't do quoting like this |
| REPTO_QUOTE_MSN | – | MSN doesn't do quoting like this |
| REPTO_QUOTE_QUALCOMM | – | Qualcomm/Eudora doesn't do quoting like this |
| REPTO_QUOTE_YAHOO | 0.49 | Yahoo! doesn't do quoting like this |
| RISK_FREE | 2.327 | No risk! |
| RP_MATCHES_RCVD | -0.001 | |
| RUDE_HTML | – | Spammer message says you need an HTML mailer |
| SB_GIF_AND_NO_URIS | 2.199 | |
| SCC_CANSPAM_1 | 2.282 | Interesting compliance language |
| SCC_CANSPAM_2 | 1.335 | Interesting compliance language |
| SCC_ISEMM_LID_1 | 1 | Fingerprint of a particular spammer using an old spamware |
| SCC_ISEMM_LID_1B | 1 | Genericized spammer fingerprint |
| SCC_SPECIAL_GUID | 1 | Unique in a similar way |
| SENDGRID_REDIR | 0.001 | |
| SENDGRID_REDIR_PHISH | 1 | Redirect URI via Sendgrid + phishing signs |
| SEO_SUSP_NTLD | 1 | SEO offer from suspicious TLD |
| SHOPIFY_IMG_NOT_RCVD_SFY | 1 | Shopify hosted image but message not from Shopify |
| SHORTCIRCUIT | – | Not all rules were run, due to a shortcircuited rule |
| SHORTENER_SHORT_IMG | 2.499 | Short HTML + image + URL shortener |
| SHORT_HELO_AND_INLINE_IMAGE | 0.1 | Short HELO string, with inline image |
| SHORT_IMG_SUSP_NTLD | 1.019 | Short HTML + image + suspicious TLD |
| SHORT_TERM_PRICE | 0.001 | |
| SHY_OBFU_EXPIRE | 1 | Obfuscation, probable phishing |
| SHY_OBFU_PASSWORD | 1 | Obfuscation, probable phishing |
| SORTED_RECIPS | 2.474 | Recipient list is sorted by address |
| SPAMMY_XMAILER | 0.862 | X-Mailer string is common in spam and not in ham |
| SPF_FAIL | 0.919 | SPF: sender does not match SPF record (fail) |
| SPF_HELO_FAIL | 0.001 | SPF: HELO does not match SPF record (fail) |
| SPF_HELO_NEUTRAL | 0.001 | SPF: HELO does not match SPF record (neutral) |
| SPF_HELO_NONE | 0.001 | SPF: HELO does not publish an SPF Record |
| SPF_HELO_PASS | -0.001 | SPF: HELO matches SPF record |
| SPF_HELO_SOFTFAIL | 0.896 | SPF: HELO does not match SPF record (softfail) |
| SPF_NEUTRAL | 0.652 | SPF: sender does not match SPF record (neutral) |
| SPF_NONE | 0.001 | SPF: sender does not publish an SPF Record |
| SPF_PASS | -0.001 | SPF: sender matches SPF record |
| SPF_SOFTFAIL | 0.972 | SPF: sender does not match SPF record (softfail) |
| SPOOFED_FREEMAIL | 0.747 | |
| SPOOFED_FREEMAIL_NO_RDNS | 1.1 | From SPOOFED_FREEMAIL and no rDNS |
| SPOOFED_FREEM_REPTO | 1.489 | Forged freemail sender with freemail reply-to |
| SPOOFED_FREEM_REPTO_CHN | 1 | Forged freemail sender with Chinese freemail reply-to |
| SPOOFED_FREEM_REPTO_RUS | 1 | Forged freemail sender with Russian freemail reply-to |
| SPOOF_COM2COM | 0.001 | URI contains ".com" in middle and end |
| SPOOF_COM2OTH | 0.001 | URI contains ".com" in middle |
| SPOOF_GMAIL_MID | 0.001 | From Gmail but it doesn't seem to be... |
| SPOOF_NET2COM | – | URI contains ".net" or ".org", then ".com" |
| STATIC_XPRIO_OLE | 1.16 | Static RDNS + X-Priority + MIMEOLE |
| STOCK_ALERT | – | Offers a alert about a stock |
| STOCK_IMG_CTYPE | 0.005 | Stock spam image part, with distinctive Content-Type header |
| STOCK_IMG_HDR_FROM | 0.001 | Stock spam image part, with distinctive From line |
| STOCK_IMG_HTML | 0.028 | Stock spam image part, with distinctive HTML |
| STOCK_IMG_OUTLOOK | 0.702 | Stock spam image part, with Outlook-like features |
| STOCK_PRICES | – | |
| STOCK_TIP | 1 | Stock tips |
| STOX_AND_PRICE | – | |
| STOX_REPLY_TYPE | 0.212 | |
| STOX_REPLY_TYPE_WITHOUT_QUOTES | 1.86 | |
| STRONG_BUY | – | Tells you about a strong buy |
| SUBJECT_DIET | 1.563 | Subject talks about losing pounds |
| SUBJECT_DRUG_GAP_C | 0.989 | Subject contains a gappy version of 'cialis' |
| SUBJECT_DRUG_GAP_L | 2.304 | Subject contains a gappy version of 'levitra' |
| SUBJECT_DRUG_GAP_S | – | Subject contains a gappy version of 'soma' |
| SUBJECT_DRUG_GAP_X | – | Subject contains a gappy version of 'xanax' |
| SUBJECT_FUZZY_CHEAP | 1.831 | Attempt to obfuscate words in Subject: |
| SUBJECT_FUZZY_MEDS | – | Attempt to obfuscate words in Subject: |
| SUBJECT_FUZZY_PENIS | – | Attempt to obfuscate words in Subject: |
| SUBJECT_FUZZY_TION | – | Attempt to obfuscate words in Subject: |
| SUBJECT_FUZZY_VPILL | – | Attempt to obfuscate words in Subject: |
| SUBJECT_IN_BLACKLIST | 100 | DEPRECATED: See SUBJECT_IN_BLOCKLIST |
| SUBJECT_IN_BLOCKLIST | 0.01 | Subject: contains string in the user's block-list |
| SUBJECT_IN_WELCOMELIST | -0.01 | Subject: contains string in the user's welcome-list |
| SUBJECT_IN_WHITELIST | -100 | DEPRECATED: See SUBJECT_IN_WELCOMELIST |
| SUBJECT_NEEDS_ENCODING | 0.1 | Subject includes non-encoded illegal characters |
| SUBJECT_SEXUAL | – | Subject indicates sexually-explicit content |
| SUBJ_ALL_CAPS | 0.5 | Subject is all capitals |
| SUBJ_AS_SEEN | 3.099 | Subject contains "As Seen" |
| SUBJ_BRKN_WORDNUMS | 1 | Subject contains odd word breaks and numbers |
| SUBJ_BUY | 1.498 | Subject line starts with Buy or Buying |
| SUBJ_DOLLARS | 0.1 | Subject starts with dollar amount |
| SUBJ_ILLEGAL_CHARS | 1.105 | Subject: has too many raw illegal characters |
| SUBJ_UNNEEDED_HTML | 1 | Unneeded HTML formatting in Subject: |
| SUBJ_YOUR_FAMILY | 2.999 | Subject contains "Your Family" |
| SURBL_BLOCKED | 0.001 | ADMINISTRATOR NOTICE: The query to SURBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists\#dnsbl-block for more information. |
| SUSPICIOUS_RECIPS | 2.497 | Similar addresses in recipient list |
| SYSADMIN | 1 | Supposedly from your IT department |
| TAGSTAT_IMG_NOT_RCVD_TGST | 1 | Tagstat hosted image but message not from Tagstat |
| TARINGANET_IMG_NOT_RCVD_TN | 1 | media.taringa.net hosted image but message not from taringa.net |
| TBIRD_SUSP_MIME_BDRY | 2.4 | Unlikely Thunderbird MIME boundary |
| TELEGRAM_MESSAGE | 1 | Sent a Telegram message, probable phishing exfil |
| TEQF_USR_IMAGE | 1 | To and from user nearly same + image |
| TEQF_USR_MSGID_HEX | 1 | To and from user nearly same + unusual message ID |
| TEQF_USR_MSGID_MALF | 1 | To and from user nearly same + malformed message ID |
| TEQF_USR_POLITE | 0.963 | To and from user nearly same + polite greeting |
| THEBAT_UNREG | 1.843 | |
| THIS_AD | 2.699 | "This ad" and variants |
| THIS_IS_ADV_SUSP_NTLD | 1 | This is an advertisement from a suspicious TLD |
| TONLINE_FAKE_DKIM | 1 | t-online.de doesn't do DKIM |
| TO_EQ_FM_DIRECT_MX | 0.001 | To == From and direct-to-MX |
| TO_EQ_FM_DOM_HTML_IMG | 2.499 | To domain == From domain and HTML image link |
| TO_EQ_FM_DOM_HTML_ONLY | 0.001 | To domain == From domain and HTML only |
| TO_EQ_FM_DOM_SPF_FAIL | 0.001 | To domain == From domain and external SPF failed |
| TO_EQ_FM_HTML_DIRECT | 0.001 | To == From and HTML only, direct-to-MX |
| TO_EQ_FM_HTML_ONLY | 0.001 | To == From and HTML only |
| TO_EQ_FM_SPF_FAIL | 0.001 | To == From and external SPF failed |
| TO_IN_SUBJ | 0.099 | To address is in Subject |
| TO_MALFORMED | 0.1 | To: has a malformed address |
| TO_NAME_SUBJ_NO_RDNS | 2.999 | Recipient username in subject + no rDNS |
| TO_NO_BRKTS_DYNIP | 3.999 | To: lacks brackets and dynamic rDNS |
| TO_NO_BRKTS_FROM_MSSP | 2.499 | Multiple header formatting problems |
| TO_NO_BRKTS_HTML_IMG | 0.001 | To: lacks brackets and HTML and one image |
| TO_NO_BRKTS_HTML_ONLY | 1.999 | To: lacks brackets and HTML only |
| TO_NO_BRKTS_MSFT | 2.499 | To: lacks brackets and supposed Microsoft tool |
| TO_NO_BRKTS_NORDNS_HTML | 1.999 | To: lacks brackets and no rDNS and HTML only |
| TO_NO_BRKTS_PCNT | 2.499 | To: lacks brackets + percentage |
| TO_TOO_MANY_WFH_01 | 1 | Work-from-Home + many recipients |
| TRACKER_ID | 0.1 | Incorporates a tracking ID number |
| TT_MSGID_TRUNC | 0.023 | Scora: Message-Id ends after left-bracket + digits |
| TT_OBSCURED_VALIUM | – | Scora: obscured "VALIUM" in subject |
| TT_OBSCURED_VIAGRA | – | Scora: obscured "VIAGRA" in subject |
| TVD_ACT_193 | – | Message refers to an act passed in the 1930s |
| TVD_APPROVED | 1 | Body states that the recipient has been approved |
| TVD_DEAR_HOMEOWNER | – | Spam with generic salutation of "dear homeowner" |
| TVD_EB_PHISH | – | |
| TVD_ENVFROM_APOST | – | Envelope From contains single-quote |
| TVD_FINGER_02 | 0.001 | |
| TVD_FLOAT_GENERAL | – | Message uses CSS float style |
| TVD_FROM_1 | 0.999 | From address appears to be a throwaway domain |
| TVD_FUZZY_DEGREE | – | Obfuscation of the word "degree" |
| TVD_FUZZY_FINANCE | – | Obfuscation of the word "finance" |
| TVD_FUZZY_FIXED_RATE | – | Obfuscation of the phrase "fixed rate" |
| TVD_FUZZY_MICROCAP | – | Obfuscation of the word "micro-cap" |
| TVD_FUZZY_PHARMACEUTICAL | – | Obfuscation of the word "pharmaceutical" |
| TVD_FUZZY_SYMBOL | – | Obfuscation of the word "symbol" |
| TVD_FW_GRAPHIC_NAME_LONG | 0.648 | Long image attachment name |
| TVD_FW_GRAPHIC_NAME_MID | 0.001 | Medium sized image attachment name |
| TVD_INCREASE_SIZE | 0.601 | Advertising for penis enlargement |
| TVD_LINK_SAVE | – | Spam with the text "link to save" |
| TVD_PH_BODY_ACCOUNTS_PRE | 0.001 | The body matches phrases such as "accounts suspended", "account credited", "account verification" |
| TVD_PH_REC | 0.1 | Message includes a phrase commonly used in phishing mails |
| TVD_PH_SEC | 0.1 | Message includes a phrase commonly used in phishing mails |
| TVD_PP_PHISH | – | |
| TVD_QUAL_MEDS | 2.397 | The body matches phrases such as "quality meds" or "quality medication" |
| TVD_RATWARE_CB | – | Content-Type header that is commonly indicative of ratware |
| TVD_RATWARE_CB_2 | – | Content-Type header that is commonly indicative of ratware |
| TVD_RATWARE_MSGID_02 | – | Ratware with a Message-ID header that is entirely lower-case |
| TVD_RCVD_IP | 0.001 | Message was received from an IP address |
| TVD_RCVD_IP4 | 0.001 | Message was received from an IPv4 address |
| TVD_SECTION | – | References to specific legal codes |
| TVD_SILLY_URI_OBFU | – | URI obfuscation that can fool a URIBL or a uri rule |
| TVD_SPACED_SUBJECT_WORD3 | – | Entire subject is "UPPERlowerUPPER" with no whitespace |
| TVD_SPACE_ENCODED | 2.499 | Space ratio & encoded subject |
| TVD_SPACE_RATIO | 0.001 | |
| TVD_SPACE_RATIO_MINFP | 0.001 | Space ratio (vertical text obfuscation?) |
| TVD_STOCK1 | – | Spam related to stock trading |
| TVD_SUBJ_ACC_NUM | 0.1 | Subject has spammy looking monetary reference |
| TVD_SUBJ_FINGER_03 | – | Entire subject is enclosed in asterisks "* like so *" |
| TVD_SUBJ_OWE | – | Subject line states that the recipieint is in debt |
| TVD_SUBJ_WIPE_DEBT | 2.291 | Spam advertising a way to eliminate debt |
| TVD_VISIT_PHARMA | 1.196 | Body mentions online pharmacy |
| TVD_VIS_HIDDEN | – | Invisible textarea HTML tags |
| TW_GIBBERISH_MANY | 1 | Lots of gibberish text to spoof pattern matching filters |
| TXREP | 1 | Score normalizing based on sender's reputation |
| T_ACH_CANCELLED_EXE | 0.01 | "ACH cancelled" probable malware |
| T_ANY_PILL_PRICE | 0.01 | Prices for pills |
| T_CDISP_SZ_MANY | – | Suspicious MIME header |
| T_CTE_BAS64 | 0.01 | Malformated Content-Type-Encoding |
| T_CTYPE_NULL | 0.01 | Malformed Content-Type header |
| T_DATE_IN_FUTURE_Q_PLUS | 0.01 | Date: is over 4 months after Received: date |
| T_DOC_ATTACH_NO_EXT | 0.01 | Document attachment with suspicious name |
| T_DOS_OUTLOOK_TO_MX_IMAGE | 0.01 | Direct to MX with Outlook headers and an image |
| T_DOS_ZIP_HARDCORE | – | hardcore.zip file attached; quite certainly a virus |
| T_DRUGS_ERECTILE_SHORT_SHORTNER | 0.01 | Short erectile drugs advert with T_URL_SHORTENER |
| T_FILL_THIS_FORM_FRAUD_PHISH | 0.01 | Answer suspicious question(s) |
| T_FILL_THIS_FORM_LOAN | 0.01 | Answer loan question(s) |
| T_FILL_THIS_FORM_SHORT | 0.01 | Fill in a short form with personal information |
| T_FKO_CAL_RAND_START | 0.01 | Calendar invite with random start time |
| T_FORGED_TBIRD_IMG_SIZE | 0.01 | Likely forged Thunderbird image spam |
| T_FREEMAIL_DOC_PDF | 0.01 | MS document or PDF attachment, from freemail |
| T_FREEMAIL_DOC_PDF_BCC | 0.01 | MS document or PDF attachment, from freemail, all recipients hidden |
| T_FREEMAIL_RVW_ATTCH | 0.01 | Please review attached document, from freemail |
| T_FROMNAME_EQUALS_TO | 0.01 | From:name matches To: |
| T_FROMNAME_SPOOFED_EMAIL | 0.01 | From:name looks like a spoofed email |
| T_FROM_MULTI_SHORT_IMG | 0.01 | Multiple From addresses + short message with image |
| T_FUZZY_OPTOUT | 0.01 | Obfuscated opt-out text |
| T_FUZZY_TELEGRAM | 0.01 | Obfuscated "telegram" |
| T_FUZZY_TRUMP | 0.01 | Obfuscated "Trump" |
| T_GB_FROMNAME_SPOOFED_EMAIL_IP | 0.01 | From:name looks like a spoofed email from a spoofed ip |
| T_GB_STORAGE_GOOGLE_EMAIL | 0.01 | Google storage cloud abuse |
| T_GB_WEBFORM | 0.01 | Webform with url shortener |
| T_GB_YOUTUBE_EMAIL | 0.01 | Youtube attribution links abuse |
| T_HTML_ATTACH | 0.01 | HTML attachment to bypass scanning? |
| T_ISO_ATTACH | 0.01 | ISO attachment - possible malware delivery |
| T_KAM_HTML_FONT_INVALID | 0.01 | Test for Invalidly Named or Formatted Colors in HTML |
| T_LARGE_PCT_AFTER_MANY | 0.01 | Many large percentages after... |
| T_LOTTO_AGENT | 0.01 | Claims Agent |
| T_LOTTO_AGENT_FM | 0.01 | Claims Agent |
| T_LOTTO_AGENT_RPLY | 0.01 | Claims Agent |
| T_LOTTO_URI | 0.01 | Claims Department URL |
| T_MANY_PILL_PRICE | 0.01 | Prices for many pills |
| T_MIME_MALF | 0.01 | Malformed MIME: headers in body |
| T_MONEY_PERCENT | 0.01 | X% of a lot of money for you |
| T_MXG_BING_REDIR_SUSP | – | Suspicious Bing redirect |
| T_MXG_LOWER_HDR_SPAM | 0.01 | Lower case header spam |
| T_OBFU_ATTACH_MISSP | 0.01 | Obfuscated attachment type and misspaced From |
| T_OBFU_DOC_ATTACH | – | MS Document attachment with generic MIME type |
| T_OBFU_GIF_ATTACH | – | GIF attachment with generic MIME type |
| T_OBFU_HTML_ATT_MALW | 0.01 | HTML attachment with incorrect MIME type - possible malware |
| T_OBFU_JPG_ATTACH | – | JPG attachment with generic MIME type |
| T_OBFU_PDF_ATTACH | – | PDF attachment with generic MIME type |
| T_OFFER_ONLY_AMERICA | 0.01 | Offer only available to US |
| T_PDS_BTC_AHACKER | 0.01 | Bitcoin Hacker |
| T_PDS_BTC_HACKER | 0.01 | Bitcoin Hacker |
| T_PDS_BTC_NTLD | 0.01 | Bitcoin suspect NTLD |
| T_PDS_EMPTYSUBJ_URISHRT | 0.01 | Empty subject with little more than URI shortener |
| T_PDS_FREEMAIL_REPLYTO_URISHRT | 0.01 | Freemail replyto with URI shortener |
| T_PDS_FROM_2_EMAILS_SHRTNER | 0.01 | From 2 emails short email with little more than a URI shortener |
| T_PDS_LTC_AHACKER | 0.01 | Litecoin Hacker |
| T_PDS_LTC_HACKER | 0.01 | Litecoin Hacker |
| T_PDS_OTHER_BAD_TLD | 0.01 | Untrustworthy TLDs |
| T_PDS_PRO_TLD | 0.01 | .pro TLD |
| T_PDS_SHORTFWD_URISHRT | 0.01 | Threaded email with URI shortener |
| T_PDS_SHORTFWD_URISHRT_FP | 0.01 | Apparently a short fwd/re with URI shortener |
| T_PDS_SHORTFWD_URISHRT_QP | 0.01 | Apparently a short fwd/re with URI shortener |
| T_PDS_SHORT_SPOOFED_URL | 0.01 | HTML message short and T_SPOOFED_URL (S_U_FP) |
| T_PDS_TINYSUBJ_URISHRT | 0.01 | Short subject with URL shortener |
| T_PDS_TO_EQ_FROM_NAME | 0.01 | From: name same as To: address |
| T_PDS_URISHRT_LOCALPART_SUBJ | 0.01 | Localpart of To in subject |
| T_PHOTO_EDITING_DIRECT | 0.01 | Image editing service, direct to MX |
| T_PHOTO_EDITING_FREEM | 0.01 | Image editing service, freemail or CHN replyto |
| T_REMOTE_IMAGE | 0.01 | Message contains an external image |
| T_SCC_BOGUS_CTE_1 | 0.01 | Bogus Content-Transfer-Encoding header |
| T_SCC_CTMPP | 0.01 | Uncommon Content-Type |
| T_SENT_TO_EMAIL_ADDR | 0.01 | Email was sent to email address |
| T_SHARE_50_50 | 0.01 | Share the money 50/50 |
| T_SHORT_SHORTNER | 0.01 | Short body with little more than a link to a shortener |
| T_SPF_HELO_PERMERROR | 0.01 | SPF: test of HELO record failed (permerror) |
| T_SPF_HELO_TEMPERROR | 0.01 | SPF: test of HELO record failed (temperror) |
| T_SPF_PERMERROR | 0.01 | SPF: test of record failed (permerror) |
| T_SPF_TEMPERROR | 0.01 | SPF: test of record failed (temperror) |
| T_STY_INVIS_DIRECT | 0.01 | HTML hidden text + direct-to-MX |
| T_SUSPNTLD_EXPIRATION_EXTORT | 0.01 | Susp NTLD with an expiration notice and lotsa money |
| T_TONOM_EQ_TOLOC_SHRT_PSHRTNER | 0.01 | Short subject with potential shortener and To:name eq To:local |
| T_TONOM_EQ_TOLOC_SHRT_SHRTNER | 0.01 | Short email with shortener and To:name eq To:local |
| T_URI_GOOG_STO_SUBD_SPAMMY | 0.01 | Link to spammy content hosted by google storage |
| T_WON_MONEY_ATTACH | 0.01 | You won lots of money! See attachment. |
| T_WON_NBDY_ATTACH | 0.01 | You won lots of money! See attachment. |
| T_XPRIO_URL_SHORTNER | 0.01 | X-Priority header and short URL |
| T_ZW_OBFU_BITCOIN | 0.01 | Obfuscated text + bitcoin ID - possible extortion |
| T_ZW_OBFU_FREEM | 0.01 | Obfuscated text + freemail |
| UC_GIBBERISH_OBFU | 1 | Multiple instances of "word VERYLONGGIBBERISH word" |
| UNCLAIMED_MONEY | 2.699 | People just leave money laying around |
| UNCLOSED_BRACKET | 1.329 | Headers contain an unclosed bracket |
| UNDISC_FREEM | 3 | Undisclosed recipients + freemail reply-to |
| UNDISC_MONEY | 2.999 | Undisclosed recipients + money/fraud signs |
| UNICODE_OBFU_ASC | 2.499 | Obfuscating text with unicode |
| UNICODE_OBFU_ZW | 0.001 | Obfuscating text with hidden characters |
| UNICODE_OBFU_ZW_MANY | 0.001 | Heavily obfuscating text with hidden characters |
| UNICODE_RTL_OBFU | 1 | Word obfuscation using Unicode right-to-left markers |
| UNPARSEABLE_RELAY | 0.001 | Informational: message has unparseable relay lines |
| UNRESOLVED_TEMPLATE | 0.716 | Headers contain an unresolved template |
| UNSUB_GOOG_FORM | 1 | Unsubscribe via Google Docs form |
| UNWANTED_LANGUAGE_BODY | 2.8 | Message written in an undesired language |
| UPPERCASE_50_75 | 0.791 | message body is 50-75% uppercase |
| UPPERCASE_75_100 | 1.189 | message body is 75-100% uppercase |
| UPPERCASE_URI | 2.749 | Link protocol has unexpected mixed case |
| URG_BIZ | 0.941 | Contains urgent matter |
| URIBL_ABUSE_SURBL | 1.948 | Contains an URL listed in the ABUSE SURBL blocklist |
| URIBL_BLACK | 1.7 | Contains an URL listed in the URIBL blacklist |
| URIBL_BLOCKED | 0.001 | ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists\#dnsbl-block for more information. |
| URIBL_CR_SURBL | 1.263 | Contains an URL listed in the CR SURBL blocklist |
| URIBL_CSS | 0.1 | Contains an URL's NS IP listed in the Spamhaus CSS blocklist |
| URIBL_CSS_A | 0.1 | Contains URL's A record listed in the Spamhaus CSS blocklist |
| URIBL_CT_SURBL | 1.699 | Contains an URL listed in the CT SURBL blocklist |
| URIBL_DBL_ABUSE_BOTCC | 2.5 | Contains an abused botnet C&C URL listed in the Spamhaus DBL blocklist |
| URIBL_DBL_ABUSE_MALW | 2.5 | Contains an abused malware URL listed in the Spamhaus DBL blocklist |
| URIBL_DBL_ABUSE_PHISH | 2.5 | Contains an abused phishing URL listed in the Spamhaus DBL blocklist |
| URIBL_DBL_ABUSE_REDIR | 0.001 | Contains an abused redirector URL listed in the Spamhaus DBL blocklist |
| URIBL_DBL_ABUSE_SPAM | 2 | Contains an abused spamvertized URL listed in the Spamhaus DBL blocklist |
| URIBL_DBL_BLOCKED | 0.001 | ADMINISTRATOR NOTICE: The query to dbl.spamhaus.org was blocked. See https://www.spamhaus.org/returnc/vol/ |
| URIBL_DBL_BLOCKED_OPENDNS | 0.001 | ADMINISTRATOR NOTICE: The query to dbl.spamhaus.org was blocked due to usage of an open resolver. See https://www.spamhaus.org/returnc/pub/ |
| URIBL_DBL_BOTNETCC | 2.5 | Contains a botned C&C URL listed in the Spamhaus DBL blocklist |
| URIBL_DBL_ERROR | 0.001 | Error: queried the Spamhaus DBL blocklist for an IP |
| URIBL_DBL_MALWARE | 2.5 | Contains a malware URL listed in the Spamhaus DBL blocklist |
| URIBL_DBL_PHISH | 2.5 | Contains a Phishing URL listed in the Spamhaus DBL blocklist |
| URIBL_DBL_SPAM | 2.5 | Contains a spam URL listed in the Spamhaus DBL blocklist |
| URIBL_DM_SURBL | 0.001 | Contains an URL listed in the DM SURBL blocklist |
| URIBL_GREY | 1.084 | Contains an URL listed in the URIBL greylist |
| URIBL_MULTI_SURBL_HEADERS | 1 | Domain found in surbl multi for from or reply-to |
| URIBL_MW_SURBL | 1.263 | Contains a URL listed in the MW SURBL blocklist |
| URIBL_PH_SURBL | 0.001 | Contains an URL listed in the PH SURBL blocklist |
| URIBL_RED | 0.001 | Contains an URL listed in the URIBL redlist |
| URIBL_RHS_DOB | 0.276 | Contains an URI of a new domain (Day Old Bread) |
| URIBL_SBL | 0.644 | Contains an URL's NS IP listed in the Spamhaus SBL blocklist |
| URIBL_SBL_A | 0.1 | Contains URL's A record listed in the Spamhaus SBL blocklist |
| URIBL_ZEN_BLOCKED | 0.001 | ADMINISTRATOR NOTICE: The query to zen.spamhaus.org was blocked. See https://www.spamhaus.org/returnc/vol/ |
| URIBL_ZEN_BLOCKED_OPENDNS | 0.001 | ADMINISTRATOR NOTICE: The query to zen.spamhaus.org was blocked due to usage of an open resolver. See https://www.spamhaus.org/returnc/pub/ |
| URI_ADOBESPARK | 1 | |
| URI_AZURE_CLOUDAPP | 1 | Link to hosted azure web application, possible phishing |
| URI_CLOUDFLAREIPFS | 1 | References Interplanetary File System PtP content via CloudFlare, likely phishing |
| URI_DASHGOVEDU | 1 | Suspicious domain name |
| URI_DATA | 1 | "data:" URI - possible malware or phish |
| URI_DOTCN_LOGIN | 1 | Login page in .cn subdomain - possible Chinese phishing |
| URI_DOTCN_SPOOF | 2.997 | .CN TLD for non-.CN visible URL - likely Chinese phishing |
| URI_DOTEDU | 1 | Has .edu URI |
| URI_DOTEDU_ENTITY | 1 | Via .edu MTA + suspicious HTML content |
| URI_DOTTY_HEX | 1 | Suspicious URI format |
| URI_DQ_UNSUB | 1 | IP-address unsubscribe URI |
| URI_DWEBIPFS | 2.192 | References Interplanetary File System PtP content via dweb.link, likely phishing |
| URI_EXCESS_SLASHES | 2.499 | Too many slashes in URI, possible attempt to bypass spam filtering |
| URI_FIREBASEAPP | 2.999 | Link to hosted firebase web application, possible phishing |
| URI_GLITCHME | 1 | References glitch.me content, possible phishing |
| URI_GOOGDRAWPREVIEW_MINFP | 3 | Link to image at Google Docs, probable phishing |
| URI_GOOGLE_PROXY | 2.099 | Accessing a blacklisted URI or obscuring source of phish via Google proxy? |
| URI_GOOG_STO_SPAMMY | 1 | Link to spammy content hosted by google storage |
| URI_HEX | 0.1 | URI hostname has long hexadecimal sequence |
| URI_HEX_IP | 1 | URI with hex-encoded IP-address host |
| URI_HOST_IN_BLACKLIST | 100 | DEPRECATED: See URI_HOST_IN_BLOCKLIST |
| URI_HOST_IN_BLOCKLIST | 0.01 | Host or Domain is listed in the user's URI block-list |
| URI_HOST_IN_WELCOMELIST | -0.01 | Host or Domain is listed in the user's URI welcome-list |
| URI_HOST_IN_WHITELIST | -100 | DEPRECATED: See URI_HOST_IN_WELCOMELIST |
| URI_IMG_CWINDOWSNET | 0.734 | Non-MSFT image hosted by Microsoft Azure infra, possible phishing |
| URI_IMG_WP_REDIR | 1 | Image via WordPress "accelerator" proxy |
| URI_IPFS | 1.782 | References Interplanetary File System PtP content, probable phishing |
| URI_IPFSIO | 3.192 | References Interplanetary File System PtP content via ipfs.io, likely phishing |
| URI_LONG_REPEAT | 1 | Long identical host+domain |
| URI_MALWARE_SCMS | 1 | Link to malware exploit download (.SettingContent-ms file) |
| URI_NOVOWEL | 0.5 | URI hostname has long non-vowel sequence |
| URI_NO_WWW_BIZ_CGI | 1 | CGI in .biz TLD other than third-level "www" |
| URI_NO_WWW_INFO_CGI | 1 | CGI in .info TLD other than third-level "www" |
| URI_ONLY_MSGID_MALF | 1 | URI only + malformed message ID |
| URI_OPTOUT_3LD | 1 | Opt-out URI, suspicious hostname |
| URI_OPTOUT_USME | 1 | Opt-out URI, unusual TLD |
| URI_PHISH | 2.499 | Phishing using web form |
| URI_PHP_REDIR | 1 | PHP redirect to different URL (link obfuscation) |
| URI_REPLIT_DEV | 3 | replit.dev URL, probably phishing |
| URI_TRUNCATED | 0.001 | Message contained a URI which was truncated |
| URI_TRY_3LD | 0.744 | "Try it" URI, suspicious hostname |
| URI_TRY_USME | 1 | "Try it" URI, unusual TLD |
| URI_UNSUBSCRIBE | – | URI contains suspicious unsubscribe link |
| URI_WPADMIN | 1.512 | WordPress login/admin URI, possible phishing |
| URI_WP_DIRINDEX | 1 | URI for compromised WordPress site, possible malware |
| URI_WP_HACKED | 2.486 | URI for compromised WordPress site, possible malware |
| URI_WP_HACKED_2 | 1.851 | URI for compromised WordPress site, possible malware |
| URL_SHORTENER_CHAINED | 0.01 | Message contains shortened URL chained to other shorteners |
| URL_SHORTENER_DISABLED | 2 | Message contains shortened URL that has been disabled due to abuse |
| USB_DRIVES | 1 | Trying to sell custom USB flash drives |
| USER_IN_ALL_SPAM_TO | -100 | User is listed in 'all_spam_to' |
| USER_IN_BLACKLIST | 100 | DEPRECATED: See USER_IN_BLOCKLIST |
| USER_IN_BLACKLIST_TO | 10 | DEPRECATED: See USER_IN_BLOCKLIST_TO |
| USER_IN_BLOCKLIST | 0.01 | From: user is listed in the block-list |
| USER_IN_BLOCKLIST_TO | 0.01 | User is listed in 'blocklist_to' |
| USER_IN_DEF_DKIM_WL | -7.5 | From: address is in the default DKIM welcome-list |
| USER_IN_DEF_SPF_WL | -7.5 | From: address is in the default SPF welcome-list |
| USER_IN_DEF_WELCOMELIST | -0.01 | From: user is listed in the default welcome-list |
| USER_IN_DEF_WHITELIST | -15 | DEPRECATED: See USER_IN_DEF_WELCOMELIST |
| USER_IN_DKIM_WELCOMELIST | -0.01 | From: address is in the user's DKIM welcomelist |
| USER_IN_DKIM_WHITELIST | -100 | DEPRECATED: See USER_IN_DKIM_WELCOMELIST |
| USER_IN_MORE_SPAM_TO | -20 | User is listed in 'more_spam_to' |
| USER_IN_SPF_WELCOMELIST | -0.01 | From: address is in the user's SPF welcomelist |
| USER_IN_SPF_WHITELIST | -100 | DEPRECATED: See USER_IN_SPF_WELCOMELIST |
| USER_IN_WELCOMELIST | -0.01 | User is listed in 'welcomelist_from' |
| USER_IN_WELCOMELIST_TO | -0.01 | User is listed in 'welcomelist_to' |
| USER_IN_WHITELIST | -100 | DEPRECATED: See USER_IN_WELCOMELIST |
| USER_IN_WHITELIST_TO | -6 | DEPRECATED: See USER_IN_WELCOMELIST_TO |
| VBOUNCE_MESSAGE | 0.1 | Virus-scanner bounce message |
| VFY_ACCT_NORDNS | 1.705 | Verify your account to a poorly-configured MTA - probable phishing |
| VIA_GAP_GRA | – | Attempts to disguise the word 'viagra' |
| VISTA_COST | 1 | Old MSFT msgid format + "cost" |
| VISTA_TONOM_EQ_TOLOC | 1 | Old MSFT msgid format + To display name = username |
| VPS_NO_NTLD | 1 | vps[0-9] domain at a suspiscious TLD |
| WALMART_IMG_NOT_RCVD_WAL | 1 | Walmart hosted image but message not from Walmart |
| WEIRD_PORT | 0.001 | Uses non-standard port number for HTTP |
| WEIRD_QUOTING | 0.001 | Weird repeated double-quotation marks |
| WIKI_IMG | 2.499 | Image from wikipedia |
| WITH_LC_SMTP | – | Received line contains spam-sign (lowercase smtp) |
| WORD_INVIS | 1.933 | A hidden word |
| WORD_INVIS_MANY | 2.999 | Multiple individual hidden words |
| XM_DIGITS_ONLY | 1 | X-Mailer malformed |
| XM_LIGHT_HEAVY | 2.499 | Special edition of a MUA |
| XM_PHPMAILER_FORGED | 1 | Apparently forged header |
| XM_RANDOM | 2.499 | X-Mailer apparently random |
| XPRIO | 2.249 | Has X-Priority header |
| XPRIO_SHORT_SUBJ | 1 | Has X Priority header + short subject |
| XPRIO_VISTA | 1.589 | X-Priority + old MSFT msgid format |
| X_IP | 0.001 | Message has X-IP header |
| X_MAILER_CME_6543_MSN | 2.004 | |
| X_MESSAGE_INFO | – | Bulk email fingerprint (X-Message-Info) found |
| X_PRIORITY_CC | – | Cc: after X-Priority: (bulk email fingerprint) |
| YAHOO_DRS_REDIR | – | Has Yahoo Redirect URI |
| YAHOO_RD_REDIR | – | Has Yahoo Redirect URI |
| ZW_OBFU_FROMTOSUBJ | 1 | Obfuscated text + from in to and subject |
Rules and scores: Apache SpamAssassin, Apache License 2.0.
Frequently asked questions
What is a good SpamAssassin score?
Lower is better. Messages scoring 5.0 or more are treated as spam by default. Aim for a score below 2; legitimate, well-authenticated email often scores 0 or below.
Why do some rules have a negative score?
Negative scores mark signs of legitimate mail, such as a valid DKIM signature from your own domain or a listing on the DNSWL allowlist. They lower the total score.
What do T_ rules mean?
Rules starting with T_ are in testing. They get a tiny score (0.01) until their accuracy is measured, so they barely affect the result.
How do I see which rules my email triggers?
Send it to a test address in the email spam checker. It runs SpamAssassin and lists every rule with an explanation and a fix.
Email validation API
Clean lists, fewer bounces
Bounces hurt your sender reputation as much as spammy content. Validate addresses before you send, in your sign-up form or in bulk.
Read the docs100 free validations every month. No credit card required.
GET https://api.emailvalidation.io/v1/info?email=support@emailvalidation.io
{
"email": "support@emailvalidation.io",
"domain": "emailvalidation.io",
"format_valid": true,
"mx_found": true,
"smtp_check": true,
"disposable": false,
"role": true,
"free": false,
"score": 0.64,
"state": "deliverable",
"reason": "valid_mailbox"
}Free email tools
Email validator
Does this mailbox exist?
Email spam checker
Will your email land in spam?
Bulk email validator
Clean a list of up to 50 addresses.
Email syntax checker
Is the address written correctly?
Disposable email checker
Is this a throwaway address?
MX record lookup
Which servers receive mail for a domain?
SPF record checker
Is the SPF record valid?
DMARC record checker
Is the domain protected against spoofing?
DKIM record checker
Is the DKIM key published?
Email server settingsSMTP, IMAP and POP3 for 119 providers.
Disposable email domains9,100+ temporary email domains.