SpamAssassin rules

All 1,293 rules of the current SpamAssassin ruleset with their default scores, and plain-English fixes for the 85 rules that most often hit legitimate email.

Test your email with SpamAssassin

Rules explained

Authentication (SPF, DKIM, DMARC)

Blocklists and allowlists

Content

Headers

HTML and MIME

Links

Sending server

All rules

Ruleset revision 1938714. Scores apply with network tests on and Bayes off.

RuleScoreDescription
ACCESSDB–Message would have been caught by accessdb
ACCT_PHISHING_MANY2.999Phishing for account information
ACT_NOW_CAPS0.1Talks about 'acting now' with capitals
AC_BR_BONANZA0.001Too many newlines in a row... spammy template
AC_DIV_BONANZA0.001Too many divs in a row... spammy template
AC_FROM_MANY_DOTS2.5Multiple periods in From user name
AC_HTML_NONSENSE_TAGS1Many consecutive multi-letter HTML tags, likely nonsense/spam
AC_POST_EXTRAS1Suspicious URL
AC_SPAMMY_URI_PATTERNS11link combos match highly spammy template
AC_SPAMMY_URI_PATTERNS101link combos match highly spammy template
AC_SPAMMY_URI_PATTERNS111link combos match highly spammy template
AC_SPAMMY_URI_PATTERNS121link combos match highly spammy template
AC_SPAMMY_URI_PATTERNS21link combos match highly spammy template
AC_SPAMMY_URI_PATTERNS31link combos match highly spammy template
AC_SPAMMY_URI_PATTERNS41link combos match highly spammy template
AC_SPAMMY_URI_PATTERNS81link combos match highly spammy template
AC_SPAMMY_URI_PATTERNS91link combos match highly spammy template
ADMAIL0.001"admail" and variants
ADMITS_SPAM1.999Admits this is an ad
ADULT_DATING_COMPANY20
ADVANCE_FEE_2_NEW_FORM1Advance Fee fraud and a form
ADVANCE_FEE_2_NEW_FRM_MNY1Advance Fee fraud form and lots of money
ADVANCE_FEE_2_NEW_MONEY1.999Advance Fee fraud and lots of money
ADVANCE_FEE_3_NEW2.296Appears to be advance fee fraud (Nigerian 419)
ADVANCE_FEE_3_NEW_FORM1Advance Fee fraud and a form
ADVANCE_FEE_3_NEW_FRM_MNY1Advance Fee fraud form and lots of money
ADVANCE_FEE_3_NEW_MONEY3.099Advance Fee fraud and lots of money
ADVANCE_FEE_4_NEW2.399Appears to be advance fee fraud (Nigerian 419)
ADVANCE_FEE_4_NEW_FORM1Advance Fee fraud and a form
ADVANCE_FEE_4_NEW_FRM_MNY1Advance Fee fraud form and lots of money
ADVANCE_FEE_4_NEW_MONEY0.009Advance Fee fraud and lots of money
ADVANCE_FEE_5_NEW2.499Appears to be advance fee fraud (Nigerian 419)
ADVANCE_FEE_5_NEW_FORM1Advance Fee fraud and a form
ADVANCE_FEE_5_NEW_FRM_MNY1Advance Fee fraud form and lots of money
ADVANCE_FEE_5_NEW_MONEY3Advance Fee fraud and lots of money
AD_PREFS0.25Advertising preferences
ALIBABA_IMG_NOT_RCVD_ALI1Alibaba hosted image but message not from Alibaba
ALL_TRUSTED-1Passed through trusted hosts only via SMTP
AMAZON_IMG_NOT_RCVD_AMZN2.499Amazon hosted image but message not from Amazon
ANY_BOUNCE_MESSAGE0.1Message is some kind of bounce message
APOSTROPHE_FROM0.786From address contains an apostrophe
APP_DEVELOPMENT_FREEM1App development pitch, freemail or CHN replyto
APP_DEVELOPMENT_NORDNS1App development pitch, no rDNS
ARC_INVALID0.1ARC signature exists, but is not valid
ARC_SIGNED0.001Message has a ARC signature
ARC_TRUSTED0.001Message has valid ARC chain from trusted sealer
ARC_VALID0.001Message has a valid ARC signature
AWL1Adjusted score from AWL reputation of From: address
AXB_XMAILER_MIMEOLE_OL_024C21.793Yet another X header trait
BAD_CREDIT0.1Eliminate Bad Credit
BAD_ENC_HEADER0.001Message has bad MIME encoding in the header
BANG_GUAR1Something is emphatically guaranteed
BANG_OPRAH–Talks about Oprah with an exclamation!
BANKING_LAWS2.004Talks about banking laws
BASE64_LENGTH_78_790.1
BASE64_LENGTH_79_INF2.019base64 encoded email part uses line length greater than 79 characters
BAYES_00–Bayes spam probability is 0 to 1%
BAYES_05–Bayes spam probability is 1 to 5%
BAYES_20–Bayes spam probability is 5 to 20%
BAYES_40–Bayes spam probability is 20 to 40%
BAYES_50–Bayes spam probability is 40 to 60%
BAYES_60–Bayes spam probability is 60 to 80%
BAYES_80–Bayes spam probability is 80 to 95%
BAYES_95–Bayes spam probability is 95 to 99%
BAYES_99–Bayes spam probability is 99 to 100%
BAYES_999–Bayes spam probability is 99.9 to 100%
BEBEE_IMG_NOT_RCVD_BB1Bebee hosted image but message not from Bebee
BIGNUM_EMAILS_FREEM1.962Lots of email addresses/leads, free email account
BIGNUM_EMAILS_MANY2.999Lots of email addresses/leads, over and over
BILLION_DOLLARS1.451Talks about lots of money
BILL_16181Mentions proposed US law supposedly permitting spamming
BITCOIN_BOMB1BitCoin + bomb
BITCOIN_DEADLINE1.935BitCoin with a deadline
BITCOIN_DIRECT3.499Bitcoin + direct-to-MX
BITCOIN_EXTORT_013.535Extortion spam, pay via BitCoin
BITCOIN_EXTORT_021Extortion spam, pay via BitCoin
BITCOIN_IMGUR1Bitcoin + hosted image
BITCOIN_MALF_HTML1.554Bitcoin + malformed HTML
BITCOIN_MALWARE1BitCoin + malware bragging
BITCOIN_OBFU_SUBJ1Bitcoin + obfuscated subject
BITCOIN_ONAN2.519BitCoin + [censored]
BITCOIN_PAY_ME1Pay me via BitCoin
BITCOIN_SPAM_011BitCoin spam pattern 01
BITCOIN_SPAM_021.525BitCoin spam pattern 02
BITCOIN_SPAM_031.973BitCoin spam pattern 03
BITCOIN_SPAM_041BitCoin spam pattern 04
BITCOIN_SPAM_050.001BitCoin spam pattern 05
BITCOIN_SPAM_061BitCoin spam pattern 06
BITCOIN_SPAM_071.168BitCoin spam pattern 07
BITCOIN_SPAM_081BitCoin spam pattern 08
BITCOIN_SPAM_091BitCoin spam pattern 09
BITCOIN_SPAM_101BitCoin spam pattern 10
BITCOIN_SPAM_111BitCoin spam pattern 11
BITCOIN_SPAM_121BitCoin spam pattern 12
BITCOIN_SPF_ONLYALL1Bitcoin from a domain specifically set to pass +all SPF
BITCOIN_TOEQFM1.982Bitcoin + To same as From
BITCOIN_VISTA1.674Bitcoin + old MSFT msgid format
BITCOIN_WFH_011Work-from-Home + bitcoin
BITCOIN_XPRIO0.334Bitcoin + priority
BITCOIN_YOUR_INFO2.75BitCoin with your personal info
BLANK_LINES_80_90–Message body has 80-90% blank lines
BODY_8BITS1.5Body includes 8 consecutive 8-bit characters
BODY_ENHANCEMENT1.611Information on growing body parts
BODY_ENHANCEMENT20.1Information on getting larger body parts
BODY_URI_ONLY0.001Message body is only a URI in one line of text or for an image
BOGUS_MIME_VERSION1Mime version header is bogus
BOGUS_MSM_HDRS1Apparently bogus Microsoft email headers
BOMB_FREEM1Bomb + freemail
BOMB_MONEY1Bomb + money: bomb threat?
BOUNCE_MESSAGE0.1MTA bounce message
BTC_ORG1Bitcoin wallet ID + unusual header
BULK_RE_SUSP_NTLD1Precedence bulk and RE: from a suspicious TLD
CANT_SEE_AD1You really want to see our spam.
CHALLENGE_RESPONSE0.1Challenge-Response message for mail you sent
CHARSET_FARAWAY3.2Character set indicates a foreign language
CHARSET_FARAWAY_HEADER3.2A foreign language charset used in headers
CN_B2B_SPAMMER1Chinese company introducing itself
CN_PHISH_JP_011Apparent Chinese phishing of Japanese target
CN_PHISH_JP_021JP "password" + .cn URL - possible Chinese phishing
CN_PHISH_JP_041.971JP "payment" + .cn URL - possible Chinese phishing
CN_PHISH_JP_061JP "mastercard" + .cn URL - possible Chinese phishing
CN_PHISH_JP_071JP "update payment information" + .cn URL - possible Chinese phishing
COMMENT_GIBBERISH1Nonsense in long HTML comment
COMPENSATION0.001"Compensation"
CONFIRMED_FORGED–Received headers are forged
CONTENT_AFTER_HTML0.646More content after HTML close tag + other spam signs
CONTENT_AFTER_HTML_WEAK1More content after HTML close tag
CORRUPT_FROM_LINE_IN_HDRS–Informational: message is corrupt, with a From line in its headers
CRBOUNCE_MESSAGE0.1Challenge-Response bounce message
CTE_8BIT_MISMATCH0.112Header says 7bits but body disagrees
CTYPE_001C_A–
CTYPE_001C_B0.001
CTYPE_8SPACE_GIF–Stock spam image part 'Content-Type' found (8 spc)
CUM_SHOT–Possible porn - Cum Shot
CURR_PRICE0.001
DATE_IN_FUTURE_03_062.426Date: is 3 to 6 hours after Received: date
DATE_IN_FUTURE_06_120.001Date: is 6 to 12 hours after Received: date
DATE_IN_FUTURE_12_242.489Date: is 12 to 24 hours after Received: date
DATE_IN_FUTURE_24_481.248Date: is 24 to 48 hours after Received: date
DATE_IN_FUTURE_48_960.813Date: is 48 to 96 hours after Received: date
DATE_IN_FUTURE_96_Q3.702Date: is 4 days to 4 months after Received: date
DATE_IN_FUTURE_96_XX–Date: is 96 hours or more after Received: date
DATE_IN_PAST_03_061.076Date: is 3 to 6 hours before Received: date
DATE_IN_PAST_06_121.103Date: is 6 to 12 hours before Received: date
DATE_IN_PAST_12_240.804Date: is 12 to 24 hours before Received: date
DATE_IN_PAST_24_480.485Date: is 24 to 48 hours before Received: date
DATE_IN_PAST_48_961Date: is 48 to 96 hours before Received: date
DATE_IN_PAST_96_XX2.07Date: is 96 hours or more before Received: date
DATE_SPAMWARE_Y2K–Date header uses unusual Y2K formatting
DAY_I_EARNED1Work-at-home spam
DCC_CHECK1.1Detected as bulk mail by DCC (dcc-servers.net)
DCC_REPUT_00_12-0.8DCC reputation between 0 and 12 % (mostly ham)
DCC_REPUT_13_19-0.1DCC reputation between 13 and 19 %
DCC_REPUT_70_890.1DCC reputation between 70 and 89 %
DCC_REPUT_90_940.4DCC reputation between 90 and 94 %
DCC_REPUT_95_980.7DCC reputation between 95 and 98 % (mostly spam)
DCC_REPUT_99_1001.2DCC reputation between 99 % or higher (spam)
DC_GIF_UNO_LARGO1.323Message contains a single large gif image
DC_IMAGE_SPAM_HTML0.1Possible Image-only spam
DC_IMAGE_SPAM_TEXT0.1Possible Image-only spam with little text
DC_PNG_UNO_LARGO0.001Message contains a single large png image
DEAR_BENEFICIARY2.699Dear Beneficiary:
DEAR_FRIEND2.604Dear Friend? That's not very dear!
DEAR_SOMETHING1.731Contains 'Dear (something)'
DEAR_WINNER3.099Spam with generic salutation of "dear winner"
DIET_1–Lose Weight Spam
DIGEST_MULTIPLE0.001Message hits more than one network digest check
DKIMDOMAIN_IN_DWL-3.5
DKIMDOMAIN_IN_DWL_UNKNOWN-0.01
DKIMWL_BL2.798DKIMwl.org - Blocked sender
DKIMWL_BLOCKED0.001ADMINISTRATOR NOTICE: The query to DKIMWL.org was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists\#dnsbl-block for more information.
DKIMWL_WL_HIGH-0.331DKIMwl.org - High trust sender
DKIMWL_WL_MED-0.001DKIMwl.org - Medium trust sender
DKIMWL_WL_MEDHI-1DKIMwl.org - Medium-high trust sender
DKIM_ADSP_ALL1.1No valid author signature, domain signs all mail
DKIM_ADSP_CUSTOM_HIGH0.001No valid author signature, adsp_override is CUSTOM_HIGH
DKIM_ADSP_CUSTOM_LOW0.001No valid author signature, adsp_override is CUSTOM_LOW
DKIM_ADSP_CUSTOM_MED0.001No valid author signature, adsp_override is CUSTOM_MED
DKIM_ADSP_DISCARD1.8No valid author signature, domain signs all mail and suggests discarding the rest
DKIM_ADSP_NXDOMAIN0.8No valid author signature and domain not in DNS
DKIM_INVALID0.1DKIM or DK signature exists, but is not valid
DKIM_POLICY_SIGNALL–
DKIM_POLICY_SIGNSOME–
DKIM_POLICY_TESTING–
DKIM_SIGNED0.1Message has a DKIM or DK signature, not necessarily valid
DKIM_VALID-0.1Message has at least one valid DKIM or DK signature
DKIM_VALID_AU-0.1Message has a valid DKIM or DK signature from author's domain
DKIM_VALID_EF-0.1Message has a valid DKIM or DK signature from envelope-from domain
DKIM_VERIFIED–
DMARC_MISSING0.001Missing DMARC policy
DMARC_NONE0.898DMARC none policy
DMARC_PASS-0.001DMARC pass policy
DMARC_PERMERROR2.139DMARC permanent error
DMARC_QUAR1.198DMARC quarantine policy
DMARC_REJECT1.797DMARC reject policy
DMARC_TEMPERROR0.001DMARC temporary error
DOS_ANAL_SPAM_MAILER–X-mailer pattern common to anal porn site spam
DOS_BODY_HIGH_NO_MID3.999High bit body and no message ID header
DOS_FIX_MY_URI–Looks like a "fix my obfu'd URI please" spam
DOS_HIGH_BAT_TO_MX–The Bat! Direct to MX with High Bits
DOS_LET_GO_JOB–Let go from their job and now makes lots of dough!
DOS_OE_TO_MX3.086Delivered direct to MX with OE headers
DOS_OE_TO_MX_IMAGE1.886Direct to MX with OE headers and an image
DOS_OUTLOOK_TO_MX1.449Delivered direct to MX with Outlook headers
DOS_RCVD_IP_TWICE_C2.06Received from the same IP twice in a row (only one external relay; empty or IP helo)
DOS_STOCK_BAT0.001Probable pump and dump stock spam
DOS_STOCK_BAT2–
DOS_URI_ASTERISK–Found an asterisk in a URI
DOS_YOUR_PLACE–Russian dating spam
DOTGOV_IMAGE1.gov URI + hosted image
DRUGS_ANXIETY0.1Refers to an anxiety control drug
DRUGS_ANXIETY_EREC–Refers to both an erectile and an anxiety drug
DRUGS_ANXIETY_OBFU–Obfuscated reference to an anxiety control drug
DRUGS_DIET0.757Refers to a diet drug
DRUGS_DIET_OBFU–Obfuscated reference to a diet drug
DRUGS_ERECTILE2.221Refers to an erectile drug
DRUGS_ERECTILE_OBFU1.309Obfuscated reference to an erectile drug
DRUGS_HDIA–Subject mentions "hoodia"
DRUGS_MANYKINDS1.473Refers to at least four kinds of drugs
DRUGS_MUSCLE2.499Refers to a muscle relaxant
DRUGS_SLEEP_EREC–Refers to both an erectile and a sleep aid drug
DRUGS_SMEAR12.051Two or more drugs crammed together into one word
DRUGS_STOCK_MIMEOLE1.681
DRUG_DOSAGE–Talks about price per dose
DRUG_ED_CAPS1.023Mentions an E.D. drug
DRUG_ED_GENERIC–Mentions Generic Viagra
DRUG_ED_ONLINE1.152Fast Viagra Delivery
DRUG_ED_SILD0.001Talks about an E.D. drug using its chemical name
DSN_NO_MIMEVERSION1.999Return-Path <> and no MIME-Version: header
DX_TEXT_021"change your message stat"
DX_TEXT_031"XXX Media Group"
DYNAMIC_IMGUR3.222dynamic IP + hosted image
DYN_RDNS_AND_INLINE_IMAGE1.344Contains image, and was sent by dynamic rDNS
DYN_RDNS_SHORT_HELO_HTML0.001Sent by dynamic rDNS, short HELO, and HTML
DYN_RDNS_SHORT_HELO_IMAGE2.516Short HELO string, dynamic rDNS, inline image
EBAY_IMG_NOT_RCVD_EBAY1E-bay hosted image but message not from E-bay
EMAIL_ROT13–Body contains a ROT13-encoded email address
EMPTY_MESSAGE2.344Message appears to have no textual parts
EMRCP1"Excess Maximum Return Capital Profit" scam
EM_ROLEX1.309Message puts emphasis on the watch manufacturer
ENCRYPTED_MESSAGE-0.999Message is encrypted, not likely to be spam
END_FUTURE_EMAILS0.146Spammy unsubscribe
ENGLISH_UCE_SUBJECT1.542Subject contains an English UCE tag
ENVFROM_GOOG_TRIX1From suspicious Google subdomain
ENV_AND_HDR_SPF_MATCH-0.5Env and Hdr From used in default SPF WL Match
EXCUSE_241Claims you wanted this ad
EXCUSE_41.687Claims you can be removed from the list
EXCUSE_REMOVE2.992Talks about how to be removed from mailings
FACEBOOK_IMG_NOT_RCVD_FB1Facebook hosted image but message not from Facebook
FAKE_OUTBLAZE_RCVD–Received header contains faked 'mr.outblaze.com'
FAKE_REPLY_C0.001
FBI_MONEY1The FBI wants to give you lots of money?
FBI_SPOOF1Claims to be FBI, but not from FBI domain
FILL_THIS_FORM0.001Fill in a form with personal information
FILL_THIS_FORM_FRAUD_PHISH0.396
FILL_THIS_FORM_LOAN2.237
FILL_THIS_FORM_LONG2Fill in a form with personal information
FIN_FREE0.1Freedom of a financial nature
FONT_INVIS_DIRECT1Invisible text + direct-to-MX
FONT_INVIS_DOTGOV1Invisible text + .gov URI
FONT_INVIS_HTML_NOHTML2.999Invisible text + malformed HTML
FONT_INVIS_LONG_LINE1Invisible text + long lines
FONT_INVIS_MSGID2.499Invisible text + suspicious message ID
FONT_INVIS_NORDNS1.225Invisible text + no rDNS
FONT_INVIS_POSTEXTRAS1Invisible text + suspicious URI
FORGED_GMAIL_RCVD1'From' gmail.com does not match 'Received' headers
FORGED_HOTMAIL_RCVD21.187hotmail.com 'From' address, but no 'Received:'
FORGED_IMS_HTML–IMS can't send HTML message only
FORGED_IMS_TAGS–IMS mailers can't send HTML in this format
FORGED_MSGID_AOL–Message-ID is forged, (aol.com)
FORGED_MSGID_EXCITE1.899Message-ID is forged, (excite.com)
FORGED_MSGID_HOTMAIL–Message-ID is forged, (hotmail.com)
FORGED_MSGID_MSN–Message-ID is forged, (msn.com)
FORGED_MSGID_YAHOO0.1Message-ID is forged, (yahoo.com)
FORGED_MUA_EUDORA2.51Forged mail pretending to be from Eudora
FORGED_MUA_IMS2.399Forged mail pretending to be from IMS
FORGED_MUA_MOZILLA1.596Forged mail pretending to be from Mozilla
FORGED_MUA_OIMO2.599Forged mail pretending to be from MS Outlook IMO
FORGED_MUA_OUTLOOK2.785Forged mail pretending to be from MS Outlook
FORGED_MUA_THEBAT_BOUN3.22Mail pretending to be from The Bat! (boundary)
FORGED_MUA_THEBAT_CS–Mail pretending to be from The Bat! (charset)
FORGED_OUTLOOK_HTML0.001Outlook can't send HTML message only
FORGED_OUTLOOK_TAGS0.565Outlook can't send HTML in this format
FORGED_QUALCOMM_TAGS–QUALCOMM mailers can't send HTML in this format
FORGED_TELESP_RCVD2.499Contains forged hostname for a DSL IP in Brazil
FORGED_THEBAT_HTML–The Bat! can't send HTML message only
FORGED_YAHOO_RCVD1.022'From' yahoo.com does not match 'Received' headers
FORM_FRAUD0.383Fill a form and a fraud phrase
FORM_FRAUD_31Fill a form and several fraud phrases
FORM_FRAUD_50.001Fill a form and many fraud phrases
FORWARD_LOOKING–Stock Disclaimer Statement
FOUND_YOU1I found you...
FRAGMENTED_MESSAGE–Partial message
FREEMAIL_ENVFROM_END_DIGIT0.25Envelope-from freemail username ends in digit
FREEMAIL_FORGED_FROMDOMAIN0.0012nd level domains in From and EnvelopeFrom freemail headers are different
FREEMAIL_FORGED_REPLYTO2.503Freemail in Reply-To, but not From
FREEMAIL_FROM0.001Sender email is commonly abused enduser mail provider
FREEMAIL_REPLY1From and body contain different freemails
FREEMAIL_REPLYTO1Reply-To/From or Reply-To/body contain different freemails
FREEMAIL_REPLYTO_END_DIGIT0.25Reply-To freemail username ends in digit
FREEMAIL_WFH_011Work-from-Home + freemail
FREEM_FRNUM_UNICD_EMPTY1Numeric freemail From address, unicode From name and Subject, empty body
FREE_PORN–Possible porn - Free Porn
FREE_QUOTE_INSTANT2.699Free express or no-obligation quote
FRNAME_IN_MSG_XPRIO_NO_SUB1From name in message + X-Priority + short or no subject
FROMSPACE1Idiosyncratic "From" header format
FROM_ADDR_WS2.999Malformed From address
FROM_BANK_NOAUTH1From Bank domain but no SPF or DKIM
FROM_BLANK_NAME2.099From: contains empty name
FROM_DOMAIN_NOVOWEL0.5From: domain has series of non-vowel letters
FROM_EXCESS_BASE640.001From: base64 encoded unnecessarily
FROM_FMBLA_NDBLOCKED0.001ADMINISTRATOR NOTICE: The query to fresh.fmb.la was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists\#dnsbl-block for more information.
FROM_FMBLA_NEWDOM1.499From domain was registered in last 7 days
FROM_FMBLA_NEWDOM140.999From domain was registered in last 7-14 days
FROM_FMBLA_NEWDOM280.799From domain was registered in last 14-28 days
FROM_GOV_DKIM_AU-1From Government address and DKIM signed
FROM_GOV_REPLYTO_FREEMAIL1From Government domain but ReplyTo is FREEMAIL
FROM_GOV_SPOOF0.999From Government domain but matches SPOOFED
FROM_ILLEGAL_CHARS2.059From: has too many raw illegal characters
FROM_IN_TO_AND_SUBJ1From address is in To and Subject
FROM_LOCAL_DIGITS0.001From: localpart has long digit sequence
FROM_LOCAL_HEX0.331From: localpart has long hexadecimal sequence
FROM_LOCAL_NOVOWEL0.5From: localpart has series of non-vowel letters
FROM_LONG_DOM1Absurdly long From domain name
FROM_LONG_DOM_MINFP1Absurdly long From domain name, suspicious relays
FROM_MISSPACED0.544From: missing whitespace
FROM_MISSP_EH_MATCH1.999From misspaced, matches envelope
FROM_MISSP_FREEMAIL1.931From misspaced + freemail provider
FROM_MISSP_MSFT1.252From misspaced + supposed Microsoft tool
FROM_MISSP_REPLYTO2.401From misspaced, has Reply-To
FROM_MISSP_SPF_FAIL1.893
FROM_MISSP_USER1.485From misspaced, from "User"
FROM_MISSP_XPRIO1.69Misspaced FROM + X-Priority
FROM_MULTI_NORDNS3.11Multiple From addresses + no rDNS
FROM_NEWDOM_BTC1Newdomain with Bitcoin ID
FROM_NO_USER2.599From: has no local-part before @ sign
FROM_NTLD_LINKBAIT1From abused NTLD with little more than a URI
FROM_NTLD_REPLY_FREEMAIL0.004From abused NTLD and Reply-To is FREEMAIL
FROM_NUMBERO_NEWDOMAIN1Fingerprint and new domain
FROM_OFFERS1From address is "at something-offers"
FROM_PAYPAL_SPOOF0.738From PayPal domain but matches SPOOFED
FROM_STARTS_WITH_NUMS0.553From: starts with several numbers
FROM_SUSPICIOUS_NTLD0.499From abused NTLD
FROM_SUSPICIOUS_NTLD_FP1.999From abused NTLD
FROM_UNBAL12.699From with unbalanced angle brackets, '>' missing
FROM_WSP_LEAD3.099Leading whitespace after '<' in From header field
FROM_WSP_TRAIL2.9Trailing whitespace before '>' in From header field
FSL_BULK_SIG0.001Bulk signature with no Unsubscribe
FSL_CTYPE_WIN12510.328Content-Type only seen in 419 spam
FSL_FAKE_HOTMAIL_RVCD1.816
FSL_HELO_BARE_IP_11.426
FSL_HELO_BARE_IP_22.104
FSL_HELO_DEVICE0.1
FSL_HELO_NON_FQDN_10.001
FSL_HELO_SETUP–
FSL_INTERIA_ABUSE2.664
FSL_NEW_HELO_USER0.001Spam's using Helo and User
FUZZY_AFFORDABLE–Attempt to obfuscate words in spam
FUZZY_AMAZON1Obfuscated "amazon"
FUZZY_ANDROID1Obfuscated "android"
FUZZY_APPLE2.299Obfuscated "apple"
FUZZY_BILLION–Attempt to obfuscate words in spam
FUZZY_BITCOIN1.321Obfuscated "Bitcoin"
FUZZY_BROWSER1Obfuscated "browser"
FUZZY_BTC_WALLET1Heavily obfuscated "bitcoin wallet"
FUZZY_CLICK_HERE1Obfuscated "click here"
FUZZY_CPILL0.001Attempt to obfuscate words in spam
FUZZY_CREDIT1.413Attempt to obfuscate words in spam
FUZZY_DOLLARS1Obfuscated "dollar" or "dollars"
FUZZY_DR_OZ1Obfuscated Doctor Oz
FUZZY_FACEBOOK1Obfuscated "facebook"
FUZZY_GUARANTEE–Attempt to obfuscate words in spam
FUZZY_HARRIS1Obfuscated "Harris"
FUZZY_IMPORTANT1Obfuscated "important"
FUZZY_MALICIOUS1Obfuscated "malicious"
FUZZY_MEDICATION–Attempt to obfuscate words in spam
FUZZY_MERIDIA–Obfuscation of the word "meridia"
FUZZY_MICROSOFT1Obfuscated "microsoft"
FUZZY_MILLION0.1Attempt to obfuscate words in spam
FUZZY_MONERO1Obfuscated "Monero"
FUZZY_MONEY–Attempt to obfuscate words in spam
FUZZY_MORTGAGE–Attempt to obfuscate words in spam
FUZZY_NORTON1Obfuscated "norton"
FUZZY_OBLIGATION–Attempt to obfuscate words in spam
FUZZY_OFFERS–Attempt to obfuscate words in spam
FUZZY_OVERSTOCK1Obfuscated "overstock"
FUZZY_PAYPAL1Obfuscated "paypal"
FUZZY_PHARMACY3.299Attempt to obfuscate words in spam
FUZZY_PHENT1.647Attempt to obfuscate words in spam
FUZZY_PORN1Obfuscated "Pornography" or "Pornographic"
FUZZY_PRESCRIPT–Attempt to obfuscate words in spam
FUZZY_PRICES0.72Attempt to obfuscate words in spam
FUZZY_PRIVACY1Obfuscated "privacy"
FUZZY_PROMOTION1Obfuscated "promotion"
FUZZY_REFINANCE–Attempt to obfuscate words in spam
FUZZY_REMOVE–Attempt to obfuscate words in spam
FUZZY_SAVINGS1Obfuscated "savings"
FUZZY_SECURITY2.299Obfuscated "security"
FUZZY_SOFTWARE–Attempt to obfuscate words in spam
FUZZY_THOUSANDS–Attempt to obfuscate words in spam
FUZZY_TRUSTWALLET1Obfuscated "Trust Wallet", probable phishing
FUZZY_UNINSTALL1Obfuscated "uninstall"
FUZZY_UNSUBSCRIBE1Obfuscated "unsubscribe"
FUZZY_VIOXX–Attempt to obfuscate words in spam
FUZZY_VLIUM–Attempt to obfuscate words in spam
FUZZY_VPILL0.494Attempt to obfuscate words in spam
FUZZY_WALLET1Obfuscated "Wallet"
FUZZY_WELLSFARGO1Obfuscated "Wells Fargo"
FUZZY_XPILL0.1Attempt to obfuscate words in spam
GAPPY_SALES_LEADS_FREEM1Obfuscated marketing text, freemail or CHN replyto
GAPPY_SUBJECT0.1Subject: contains G.a.p.p.y-T.e.x.t
GB_BITCOIN_CP0.528Localized Bitcoin scam
GB_CUSTOM_HTM_URI0.012Custom html uri
GB_FAKE_LISTUNSUB1.499Fake List-Unsubscribe header
GB_FAKE_RF_SHORT1Fake reply or forward with url shortener
GB_FORGED_MUA_POSTFIX1Forged Postfix mua headers
GB_FREEMAIL_DISPTO0.499Disposition-Notification-To/From or Disposition-Notification-To/body contain different freemails
GB_FREEMAIL_DISPTO_NOTFREEM0.499Disposition-Notification-To/From contain different freemails but mailfrom is not a freemail
GB_FROM_METAMASK1Metamask spam
GB_GOOGLE_OBFUR0.75Obfuscate url through Google redirect
GB_HASHBL_BTC0.96Message contains BTC address found on BTCBL
GEO_QUERY_STRING–
GMD_PDF_EMPTY_BODY0.25Attached PDF with empty message body
GMD_PDF_ENCRYPTED0.6Attached PDF is encrypted
GMD_PDF_HORIZ0.25Contains pdf 100-240 (high) x 450-800 (wide)
GMD_PDF_SQUARE0.5Contains pdf 180-360 (high) x 180-360 (wide)
GMD_PDF_VERT0.9Contains pdf 450-800 (high) x 100-240 (wide)
GMD_PRODUCER_EASYPDF0.25PDF producer was BCL easyPDF
GMD_PRODUCER_GPL0.25PDF producer was GPL Ghostscript
GMD_PRODUCER_POWERPDF0.25PDF producer was PowerPDF
GOOGLE_DOCS_PHISH1Possible phishing via a Google Docs form
GOOGLE_DOCS_PHISH_MANY1Phishing via a Google Docs form
GOOGLE_DOC_SUSP1Suspicious use of Google Docs
GOOGLE_DRIVE_REPLY_BAD_NTLD1From Google Drive and Reply-To is from a suspicious TLD
GOOG_MALWARE_DNLD1File download via Google - Malware?
GOOG_REDIR_DOCUSIGN1Indirect docusign link, probable phishing
GOOG_REDIR_FRAUD1Google redirect to obscure spamvertised website + fraud keywords
GOOG_REDIR_HTML_ONLY1.499Google redirect to obscure spamvertised website + HTML only
GOOG_REDIR_NORDNS1.499Google redirect to obscure spamvertised website + no rDNS
GOOG_REDIR_NOTRDNS1.146Google redirect to obscure spamvertised website + HELO is not rDNS
GOOG_REDIR_SHORT1Google redirect to obscure spamvertised website + short message
GOOG_REDIR_STATICRDNS1Google redirect to obscure spamvertised website + static rDNS
GOOG_STO_EMAIL_PHISH2.999Possible phishing with google hosted content URI having email address
GOOG_STO_HTML_PHISH1Possible phishing with google content hosting to avoid URIBL
GOOG_STO_HTML_PHISH_MANY1Phishing with google content hosting to avoid URIBL
GOOG_STO_IMG_HTML1Apparently using google content hosting to avoid URIBL
GOOG_STO_IMG_NOHTML1Apparently using google content hosting to avoid URIBL
GOOG_STO_NOIMG_HTML2.999Apparently using google content hosting to avoid URIBL
GTUBE1000Generic Test for Unsolicited Bulk Email
GUARANTEED_100_PERCENT2.699One hundred percent guaranteed
HAS_X_NO_RELAY1Has spammy header
HAS_X_OUTGOING_SPAM_STAT1Has header claiming outbound spam scan - why trust the results?
HDRS_LCASE0.043Odd capitalization of message header
HDRS_MISSP1Misspaced headers
HDR_ORDER_FTSDMCXX_001C–Header order similar to spam (FTSDMCXX/MID variant)
HDR_ORDER_FTSDMCXX_BAT–Header order similar to spam (FTSDMCXX/boundary variant)
HDR_ORDER_FTSDMCXX_DIRECT1.886Header order similar to spam (FTSDMCXX/boundary variant) + direct-to-MX
HDR_ORDER_FTSDMCXX_NORDNS2.539Header order similar to spam (FTSDMCXX/boundary variant) + no rDNS
HEADER_COUNT_CTYPE–Multiple Content-Type headers found
HEADER_COUNT_SUBJECT–Multiple Subject headers found
HEADER_FROM_DIFFERENT_DOMAINS0.249From and EnvelopeFrom 2nd level mail domains are different
HEADER_SPAM2.499Bulk email fingerprint (header-based) found
HEAD_ILLEGAL_CHARS–Headers have too many raw illegal characters
HEAD_LONG–Message headers are very long
HELO_DYNAMIC_CHELLO_NL1.918Relay HELO'd using suspicious hostname (Chello.nl)
HELO_DYNAMIC_DHCP0.841Relay HELO'd using suspicious hostname (DHCP)
HELO_DYNAMIC_DIALIN3.233Relay HELO'd using suspicious hostname (T-Dialin)
HELO_DYNAMIC_HCC2.514Relay HELO'd using suspicious hostname (HCC)
HELO_DYNAMIC_HEXIP0.511Relay HELO'd using suspicious hostname (Hex IP)
HELO_DYNAMIC_HOME_NL1.53Relay HELO'd using suspicious hostname (Home.nl)
HELO_DYNAMIC_IPADDR3.243Relay HELO'd using suspicious hostname (IP addr 1)
HELO_DYNAMIC_IPADDR23.888Relay HELO'd using suspicious hostname (IP addr 2)
HELO_DYNAMIC_ROGERS–Relay HELO'd using suspicious hostname (Rogers)
HELO_DYNAMIC_SPLIT_IP2.893Relay HELO'd using suspicious hostname (Split IP)
HELO_FRIEND–
HELO_LH_HOME2.023
HELO_LH_LD–
HELO_LOCALHOST3.603
HELO_MISC_IP0.25Looking for more Dynamic IP Relays
HELO_NO_DOMAIN1.941Relay reports its domain incorrectly
HELO_OEM2.899
HELO_STATIC_HOST-0.001Relay HELO'd using static hostname
HEXHASH_WORD1Multiple instances of word + hexadecimal hash
HIDE_WIN_STATUS0.001Javascript to hide URLs in browser
HIGH_CODEPAGE_URI–
HK_CTE_RAW1
HK_NAME_DRUGS0.001From name contains drugs
HK_NAME_MR_MRS0.999
HK_RANDOM_ENVFROM0.742Envelope sender username looks random
HK_RANDOM_FROM1From username looks random
HK_RANDOM_REPLYTO0.999Reply-To username looks random
HK_RCVD_IP_MULTICAST1
HK_SCAM0.001
HOSTED_IMG_DIRECT_MX3.499Image hosted at large ecomm, CDN or hosting site, message direct-to-mx
HOSTED_IMG_DQ_UNSUB1Image hosted at large ecomm, CDN or hosting site, IP addr unsub link
HOSTED_IMG_FREEM1Image hosted at large ecomm, CDN or hosting site or redirected, freemail from or reply-to
HOSTED_IMG_MULTI1Multiple images hosted at different large ecomm, CDN or hosting sites, free image sites, or redirected
HOSTED_IMG_MULTI_PUB_012.999Multiple hosted images at public site
HREF_EMPTY_NORDNS1.478Empty href + no rDNS
HREF_EMPTY_PHPMAIL1Empty href + PHP Mailer
HREF_EMPTY_XANTIABUSE1Empty href + X-AntiAbuse
HREF_EMPTY_XAUTHED1Empty href + X-Authenticated-Sender
HTML_BADTAG_40_50–HTML message is 40% to 50% bad tags
HTML_BADTAG_50_60–HTML message is 50% to 60% bad tags
HTML_BADTAG_60_70–HTML message is 60% to 70% bad tags
HTML_BADTAG_90_100–HTML message is 90% to 100% bad tags
HTML_CHARSET_FARAWAY0.5A foreign language charset used in HTML markup
HTML_COMMENT_SAVED_URL0.357HTML message is a saved web page
HTML_COMMENT_SHORT–HTML comment is very short
HTML_EMBEDS0.001HTML with embedded plugin object
HTML_ENTITY_ASCII1Obfuscated ASCII
HTML_ENTITY_ASCII_TINY1Obfuscated ASCII + tiny fonts
HTML_EXTRA_CLOSE0.001HTML contains far too many close tags
HTML_FONT_FACE_BAD0.001HTML font face is not a word
HTML_FONT_LOW_CONTRAST0.001HTML font color similar or identical to background
HTML_FONT_SIZE_HUGE0.001HTML font size is huge
HTML_FONT_SIZE_LARGE0.001HTML font size is large
HTML_FONT_TINY_NORDNS1.999Font too small to read, no rDNS
HTML_FORMACTION_MAILTO–HTML includes a form which sends mail
HTML_IFRAME_SRC–Message has HTML IFRAME tag with SRC URI
HTML_IMAGE_ONLY_040.342HTML: images with 0-400 bytes of words
HTML_IMAGE_ONLY_081.781HTML: images with 400-800 bytes of words
HTML_IMAGE_ONLY_121.629HTML: images with 800-1200 bytes of words
HTML_IMAGE_ONLY_161.048HTML: images with 1200-1600 bytes of words
HTML_IMAGE_ONLY_200.7HTML: images with 1600-2000 bytes of words
HTML_IMAGE_ONLY_241.282HTML: images with 2000-2400 bytes of words
HTML_IMAGE_ONLY_280.726HTML: images with 2400-2800 bytes of words
HTML_IMAGE_ONLY_320.001HTML: images with 2800-3200 bytes of words
HTML_IMAGE_RATIO_020.001HTML has a low ratio of text to image area
HTML_IMAGE_RATIO_040.001HTML has a low ratio of text to image area
HTML_IMAGE_RATIO_060.001HTML has a low ratio of text to image area
HTML_IMAGE_RATIO_080.001HTML has a low ratio of text to image area
HTML_MESSAGE0.001HTML included in message
HTML_MIME_NO_HTML_TAG0.635HTML-only message, but there is no HTML tag
HTML_MISSING_CTYPE–Message is HTML without HTML Content-Type
HTML_NONELEMENT_30_400.00130% to 40% of HTML elements are non-standard
HTML_NONELEMENT_40_50–40% to 50% of HTML elements are non-standard
HTML_NONELEMENT_60_70–60% to 70% of HTML elements are non-standard
HTML_NONELEMENT_80_90–80% to 90% of HTML elements are non-standard
HTML_OBFUSCATE_05_100.001Message is 5% to 10% HTML obfuscation
HTML_OBFUSCATE_10_201.162Message is 10% to 20% HTML obfuscation
HTML_OBFUSCATE_20_302.441Message is 20% to 30% HTML obfuscation
HTML_OBFUSCATE_30_40–Message is 30% to 40% HTML obfuscation
HTML_OBFUSCATE_50_60–Message is 50% to 60% HTML obfuscation
HTML_OBFUSCATE_70_80–Message is 70% to 80% HTML obfuscation
HTML_OBFUSCATE_90_1002Message is 90% to 100% HTML obfuscation
HTML_OFF_PAGE1HTML element rendered well off the displayed page
HTML_SHORT_CENTER3.421HTML is very short with CENTER tag
HTML_SHRT_CMNT_OBFU_MANY1Obfuscation with many short HTML comments
HTML_SINGLET_MANY1Many single-letter HTML format blocks
HTML_TAG_BALANCE_BODY0.1HTML has unbalanced "body" tags
HTML_TAG_BALANCE_CENTER3.899Malformatted HTML
HTML_TAG_BALANCE_HEAD–HTML has unbalanced "head" tags
HTML_TAG_EXIST_BGSOUND–HTML has "bgsound" tag
HTML_TEXT_INVISIBLE_FONT0.001HTML hidden text - word obfuscation?
HTML_TEXT_INVISIBLE_STYLE1HTML hidden text + other spam signs
HTML_TITLE_SUBJ_DIFF2.171
HTTPS_HTTP_MISMATCH0.1
HTTPS_IP_MISMATCH–IP to HTTPS link found in HTML
HTTP_77–Contains an URL-encoded hostname (HTTP77)
HTTP_ESCAPED_HOST0.1Uses %-escapes inside a URL's hostname
HTTP_EXCESSIVE_ESCAPES0.001Completely unnecessary %-escapes inside a URL
IMG_DIRECT_TO_MX3.399
IMG_ONLY_FM_DOM_INFO1HTML image-only message from .info domain
IMPOTENCE2.144Impotence cure
INVALID_DATE0.432Invalid Date: header (not RFC 2822)
INVALID_DATE_TZ_ABSURD0.632Invalid Date: header (timezone does not exist)
INVALID_MSGID1.167Message-Id is not valid, according to RFC 2822
INVALID_TZ_CST–Invalid date in header (wrong CST timezone)
INVALID_TZ_EST–Invalid date in header (wrong EST timezone)
INVESTMENT_ADVICE0.1Message mentions investment advice
JAPANESE_UCE_BODY–Body contains Japanese UCE tag
JAPANESE_UCE_SUBJECT–Subject contains a Japanese UCE tag
JH_SPAMMY_HEADERS1Has unusual message header(s) seen primarily in spam
JH_SPAMMY_PATTERN011Unusual pattern seen in spam campaign
JH_SPAMMY_PATTERN021Unusual pattern seen in spam campaign
JM_I_FEEL_LUCKY–
JM_RCVD_QMAILV1–
JM_TORA_XM–
JOIN_MILLIONS0.1Join Millions of Americans
JS_FROMCHARCODE–Document is built from a Javascript charcode array
KB_DATE_CONTAINS_TAB3.799
KB_FAKED_THE_BAT3.441
KB_RATWARE_BOUNDARY–
KB_RATWARE_MSGID2.987
KB_RATWARE_OUTLOOK_08–
KB_RATWARE_OUTLOOK_12–
KB_RATWARE_OUTLOOK_16–
KB_RATWARE_OUTLOOK_MID4.4
KHOP_FAKE_EBAY1Sender falsely claims to be from eBay
KHOP_HELO_FCRDNS0.4Relay HELO differs from its IP's reverse DNS
KOREAN_UCE_SUBJECT–Subject: contains Korean unsolicited email tag
LINKEDIN_IMG_NOT_RCVD_LNKN1Linkedin hosted image but message not from Linkedin
LIST_PRTL_PUMPDUMP1Incomplete List-* headers and stock pump-and-dump
LIST_PRTL_SAME_USER1Incomplete List-* headers and from+to user the same
LIVEFILESTORE0.1
LIVE_PORN–Possible porn - Live Porn
LOCALPART_IN_SUBJECT0.73Local part of To: address appears in Subject
LONGWORDS1Long string of long words
LONG_HEX_URI1Very long purely hexadecimal URI
LONG_IMG_URI0.626Image URI with very long path component - web bug?
LONG_INVISIBLE_TEXT0.644Long block of hidden text - bayes poison?
LONG_TERM_PRICE0.001
LOOPHOLE_1–A loop hole in the banking laws?
LOTS_OF_MONEY0.001Huge... sums of money
LOTTERY_11.488
LOTTERY_PH_0044700.1
LOW_PRICE0.1Lowest Price
LUCRATIVE0.642Make lots of money!
L_SPAM_TOOL_130.485
MAILING_LIST_MULTI1Multiple indicators imply a widely-seen list manager
MALE_ENHANCE3.099Message talks about enhancing men
MALF_HTML_B641Malformatted base64-encoded HTML content
MALWARE_NORDNS1Malware bragging + no rDNS
MALWARE_PASSWORD1Malware bragging + "password"
MALW_ATTACH3.5Attachment filename suspicious, probable malware exploit
MANY_HDRS_LCASE0.1Odd capitalization of multiple message headers
MANY_SPAN_IN_TEXT1Many <SPAN> tags embedded within text
MARKETING_PARTNERS0.235Claims you registered with a partner
MAY_BE_FORGED3.099Relay IP's reverse DNS does not resolve to IP
MC_MSFT_LISTMGR1Mailchimp campaign uses Microsoft brand as list-manage subdomain
MICROSOFT_EXECUTABLE0.1Message includes Microsoft executable program
MID_DEGREES–
MILLION_HUNDRED2.499Million "One to Nine" Hundred
MILLION_USD1.999Talks about millions of dollars
MIMEOLE_DIRECT_TO_MX1.999MIMEOLE + direct-to-MX
MIMEPART_LIMIT_EXCEEDED0.001Message has too many MIME parts
MIME_BAD_ISO_CHARSET–MIME character set is an unknown ISO charset
MIME_BASE64_TEXT0.001Message text disguised using base64 encoding
MIME_BOUND_DD_DIGITS0.349Spam tool pattern in MIME boundary
MIME_BOUND_DIGITS_150.1Spam tool pattern in MIME boundary
MIME_BOUND_EQ_REL–
MIME_BOUND_MANY_HEX–Spam tool pattern in MIME boundary
MIME_CHARSET_FARAWAY2.45MIME character set indicates foreign language
MIME_HEADER_CTYPE_ONLY0.1'Content-Type' found without required MIME headers
MIME_HTML_MOSTLY0.1Multipart message mostly text/html MIME
MIME_HTML_ONLY0.1Message only has text/html MIME parts
MIME_HTML_ONLY_MULTI0.001Multipart message only has text/html MIME parts
MIME_NO_TEXT0.001No (properly identified) text body parts
MIME_PHP_NO_TEXT2.799No text body parts, X-Mailer: PHP
MIME_QP_LONG_LINE0.001Quoted-printable line longer than 76 chars
MIME_SUSPECT_NAME0.1MIME filename does not match content
MISSING_DATE1.396Missing Date: header
MISSING_FROM1Missing From: header
MISSING_HB_SEP–Missing blank line between message header and body
MISSING_HEADERS1.207Missing To: header
MISSING_MID0.14Missing Message-Id: header
MISSING_MIMEOLE1.843Message has X-MSMail-Priority, but no X-MimeOLE
MISSING_MIME_HB_SEP0.001Missing blank line between MIME header and body
MISSING_SUBJECT1.767Missing Subject: header
MIXED_AREA_CASE1Has area tag in mixed case
MIXED_CENTER_CASE1Has center tag in mixed case
MIXED_ES0.108Too many es are not es
MIXED_FONT_CASE1Has font tag in mixed case
MIXED_HREF_CASE2Has href in mixed case
MIXED_IMG_CASE1Has img tag in mixed case
MONERO_DEADLINE1Monero cryptocurrency with a deadline
MONERO_EXTORT_011Extortion spam, pay via Monero cryptocurrency
MONERO_MALWARE1Monero cryptocurrency + malware bragging
MONERO_PAY_ME1Pay me via Monero cryptocurrency
MONEY_BACK1Money back guarantee
MONEY_FRAUD_32.699Lots of money and several fraud phrases
MONEY_FRAUD_52.497Lots of money and many fraud phrases
MONEY_FRAUD_80.001Lots of money and very many fraud phrases
MONEY_FREEMAIL_REPTO0.838Lots of money from someone using free email?
MONEY_FROM_410.989Lots of money from Africa
MONEY_FROM_MISSP0.001Lots of money and misspaced From
MORE_SEX2.765Talks about a bigger drive for sex
MPART_ALT_DIFF0.724HTML and text parts are different
MPART_ALT_DIFF_COUNT1.483HTML and text parts are different
MSGID_DOLLARS_RANDOM–
MSGID_DOLLARS_URI_IMG1Suspicious Message-ID and image
MSGID_FROM_MTA_HEADER0.001Message-Id was added by a relay
MSGID_HDR_MALF1Has invalid message ID header
MSGID_MULTIPLE_AT1Message-ID contains multiple '@' characters
MSGID_OUTLOOK_INVALID3.899Message-Id is fake (in Outlook Express format)
MSGID_RANDY2.599Message-Id has pattern used in spam
MSGID_SHORT0.337Message-ID is unusually short
MSGID_SPAM_CAPS1.997Spam tool Message-Id: (caps variant)
MSGID_SPAM_LETTERS–Spam tool Message-Id: (letters variant)
MSGID_YAHOO_CAPS1.413Message-ID has ALLCAPS@yahoo.com
MSM_PRIO_REPTO2.079MSMail priority header + Reply-to + short subject
MSOE_MID_WRONG_CASE3.373
MULTIPART_ALT_NON_TEXT–
MULTI_FORGED–Received headers indicate multiple forgeries
MXG_EMAIL_FRAG0.1URI with email in fragment
MXG_SPOOFED_DOCUSIGN0.1Docusign spoofing
NAME_EMAIL_DIFF0.821Sender NAME is an unrelated email address
NEWEGG_IMG_NOT_RCVD_NEGG1Newegg hosted image but message not from Newegg
NEW_PRODUCTS1.249
NICE_REPLY_A-0.001Looks like a legit reply (A)
NML_ADSP_CUSTOM_HIGH2.6ADSP custom_high hit, and not from a mailing list
NML_ADSP_CUSTOM_LOW0.7ADSP custom_low hit, and not from a mailing list
NML_ADSP_CUSTOM_MED1.2ADSP custom_med hit, and not from a mailing list
NONEXISTENT_CHARSET–Character set doesn't exist
NORDNS_LOW_CONTRAST2.499No rDNS + hidden text
NORMAL_HTTP_TO_IP0.001URI host has a public dotted-decimal IPv4 address
NOT_ADVISOR–Not registered investment advisor
NOT_SPAM1I'm not spam! Really! I'm not, I'm not, I'm not!
NO_DNS_FOR_FROM0.379Envelope sender has no MX or A DNS records
NO_FM_NAME_IP_HOSTN1.515No From name + hostname using IP address
NO_HEADERS_MESSAGE0.001Message appears to be missing most RFC-822 headers
NO_MEDICAL1.254No Medical Exams
NO_PRESCRIPTION1.102No prescription needed
NO_RDNS_DOTCOM_HELO0.433Host HELO'd as a big ISP, but had no rDNS
NO_RECEIVED-0.001Informational: message has no Received headers
NO_RELAYS-0.001Informational: message was not relayed via SMTP
NSL_RCVD_FROM_USER0.001Received from User
NSL_RCVD_HELO_USER0.864Received from HELO User
NULL_IN_BODY0.498Message has NUL (ASCII 0) byte in message
NUMBERONLY_BITCOIN_EXP0.001Domain ends in a large number and very short body with link
NUMERIC_HTTP_ADDR0.001Uses a numeric IP address in URL
OBFUSCATING_COMMENT–HTML comments which obfuscate text
OBFU_BITCOIN2.999Obfuscated BitCoin references
OBFU_HTML_ATTACH1.687HTML attachment with non-text MIME type
OBFU_JVSCR_ESC1Injects content using obfuscated javascript
OBFU_TEXT_ATTACH–Text attachment with non-text MIME type
OBFU_UNSUB_UL1Obfuscated unsubscribe text
OBSCURED_EMAIL–Message seems to contain rot13ed address
ODD_FREEM_REPTO2.243Has unusual reply-to header
ONE_TIME1.175One Time Rip Off
ONLINE_PHARMACY2.371Online Pharmacy
OOOBOUNCE_MESSAGE0.1Out Of Office bounce message
PART_CID_STOCK0.001Has a spammy image attachment (by Content-ID)
PART_CID_STOCK_LESS0.036Has a spammy image attachment (by Content-ID, more specific)
PAYPAL_PHISH_071Paypal mail passed through both paypal and MSFT infrastructure; high fraud probability
PDS_BAD_THREAD_QP_640.999Bad thread header - short QP
PDS_BTC_ID0.5FP reduced Bitcoin ID
PDS_BTC_MSGID0.809Bitcoin ID with T_MSGID_NOFQDN2
PDS_DBL_URL_TNB_RUNON1.999Double-url and To no arrows, from runon
PDS_FRNOM_TODOM_DBL_URL1.499From Name to domain, double URL
PDS_FRNOM_TODOM_NAKED_TO0.13Naked to From name equals to Domain
PDS_FROM_2_EMAILS1.597From header has multiple different addresses
PDS_FROM_NAME_TO_DOMAIN1.696From:name looks like To:domain
PDS_HELO_SPF_FAIL1High profile HELO that fails SPF
PDS_NAKED_TO_NUMERO1.999Naked-to, numberonly domain
PDS_NO_FULL_NAME_SPOOFED_URL0.749HTML message short, T_SPOOFED_URL and T_KHOP_NO_FULL_NAME
PDS_RDNS_DYNAMIC_FP0.01RDNS_DYNAMIC with FP steps
PERCENT_RANDOM2.837Message has a random macro in it
PHISH_ATTACH3.5Attachment filename suspicious, probable phishing
PHISH_AZURE_CLOUDAPP3.5Link to known phishing web application
PHISH_FBASEAPP1Probable phishing via hosted web app
PHONE_983_NOVEL1Body contains phone number in unassigned NANP area code 983
PHP_NOVER_MUA1Mail from PHP with no version number
PHP_ORIG_SCRIPT0.746Sent by bot & other signs
PHP_SCRIPT2.499Sent by PHP script
PHP_SCRIPT_MUA1Sent by PHP script, no version number
PLING_QUERY0.1Subject has exclamation mark and question mark
POSSIBLE_AMAZON_PHISH_031Amazon Prime phishing via Google Draw
POSSIBLE_APPLE_PHISH_021Claims to be from apple but not processed by any apple MTA
POSSIBLE_EBAY_PHISH_021Claims to be from ebay but not processed by any ebay MTA
POSSIBLE_GMAIL_PHISHER3.694Apparent phishing email sent from a gmail account
POSSIBLE_PAYPAL_PHISH_011Claims to be from paypal but has non-paypal from email address
POSSIBLE_PAYPAL_PHISH_021Claims to be from paypal but not processed by any paypal MTA
PP_MIME_FAKE_ASCII_TEXT0.238MIME text/plain claims to be ASCII but isn't
PP_TOO_MUCH_UNICODE020.5Is text/plain but has many unicode escapes
PP_TOO_MUCH_UNICODE051Is text/plain but has many unicode escapes
PREST_NON_ACCREDITED–'Prestigious Non-Accredited Universities'
PREVENT_NONDELIVERY–Message has Prevent-NonDelivery-Report header
PRICES_ARE_AFFORDABLE0.851Message says that prices aren't too expensive
PUMPDUMP1Pump-and-dump stock scam phrase
PUMPDUMP_MULTI1Pump-and-dump stock scam phrases
PUMPDUMP_TIP1Pump-and-dump stock tip
PYZOR_CHECK1.985Listed in Pyzor (https://pyzor.readthedocs.io/en/latest/)
RAND_HEADER_LIST_SPOOF1Random gibberish message header(s) + pretending to be a mailing list
RAND_HEADER_MANY1Multiple random gibberish message headers
RAND_MKTG_HEADER1Has partially-randomized marketing/tracking header(s)
RATWARE_EFROM0.1Bulk email fingerprint (envfrom) found
RATWARE_EGROUPS1.258Bulk email fingerprint (eGroups) found
RATWARE_HASH_DASH–Contains a hashbuster in Send-Safe format
RATWARE_MOZ_MALFORMED–Bulk email fingerprint (Mozilla malformed) found
RATWARE_MPOP_WEBMAIL1.338Bulk email fingerprint (mPOP Web-Mail)
RATWARE_MS_HASH1Bulk email fingerprint (msgid ms hash) found
RATWARE_NAME_ID0.309Bulk email fingerprint (msgid from) found
RATWARE_NO_RDNS2.529Suspicious MsgID and MIME boundary + no rDNS
RATWARE_OE_MALFORMED–X-Mailer has malformed Outlook Express version
RATWARE_OUTLOOK_NONAME1Bulk email fingerprint (Outlook no name) found
RATWARE_RCVD_AT–Bulk email fingerprint (Received @) found
RATWARE_RCVD_PF–Bulk email fingerprint (Received PF) found
RATWARE_ZERO_TZ2.535Bulk email fingerprint (+0000) found
RAZOR2_CF_RANGE_51_1002.43Razor2 gives confidence level above 50%
RAZOR2_CHECK1.729Listed in Razor2 (http://razor.sf.net/)
RCVD_AM_PM–Received headers forged (AM/PM)
RCVD_BAD_ID–Received header contains id field with bad characters
RCVD_DBL_DQ1Malformatted message header
RCVD_DOTEDU_SHORT1Via .edu MTA + short message
RCVD_DOTEDU_SUSP_URI1Via .edu MTA + suspicious URI
RCVD_DOUBLE_IP_LOOSE0.96Received: by and from look like IP addresses
RCVD_DOUBLE_IP_SPAM2.777Bulk email fingerprint (double IP) found
RCVD_FAKE_HELO_DOTCOM2.389Received contains a faked HELO hostname
RCVD_FORGED_WROTE–Forged 'Received' header found ('wrote:' spam)
RCVD_FORGED_WROTE2–
RCVD_HELO_IP_MISMATCH1.186Received: HELO and IP do not match, but should
RCVD_ILLEGAL_IP1.3Received: contains illegal IP address
RCVD_IN_BL_SPAMCOP_NET1.246Received via a relay in bl.spamcop.net
RCVD_IN_DNSWL_BLOCKED0.001ADMINISTRATOR NOTICE: The query to DNSWL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists\#DnsBlocklists-dnsbl-block for more information.
RCVD_IN_DNSWL_HI-5Sender listed at https://www.dnswl.org/, high trust
RCVD_IN_DNSWL_LOW-0.7Sender listed at https://www.dnswl.org/, low trust
RCVD_IN_DNSWL_MED-2.3Sender listed at https://www.dnswl.org/, medium trust
RCVD_IN_DNSWL_NONE-0.0001Sender listed at https://www.dnswl.org/, no trust
RCVD_IN_IADB_COURT1IADB: Court-ordered email
RCVD_IN_IADB_DK-0.223IADB: Sender publishes Domain Keys record
RCVD_IN_IADB_DMARC0.001IADB: Sender has DMARC record
RCVD_IN_IADB_DOPTIN-4IADB: All mailing list mail is confirmed opt-in
RCVD_IN_IADB_DOPTIN_GT50–IADB: Confirmed opt-in used more than 50% of the time
RCVD_IN_IADB_DOPTIN_LT50-0.001IADB: Confirmed opt-in used less than 50% of the time
RCVD_IN_IADB_ECARD1IADB: ecard, e-invitation, or similar e-correspondence service
RCVD_IN_IADB_EDDB–
RCVD_IN_IADB_EPIA–
RCVD_IN_IADB_ESP-0.001IADB: Email Service Provider (ESP)
RCVD_IN_IADB_GOODMAIL–
RCVD_IN_IADB_LEG_BNPROFIT1IADB: email sent on behalf of a non-profit organization
RCVD_IN_IADB_LEG_MAND1IADB: Legally mandated email
RCVD_IN_IADB_LEG_NPROFIT1IADB: email sent from a non-profit organization
RCVD_IN_IADB_LISTED-0.38Participates in the IADB system
RCVD_IN_IADB_LOOSE–IADB: Adds relationship addrs w/out opt-in
RCVD_IN_IADB_MI_CPEAR–IADB: Complies with Michigan's CPEAR law
RCVD_IN_IADB_MI_CPR_30–
RCVD_IN_IADB_MI_CPR_MAT0.001
RCVD_IN_IADB_ML_DOPTIN-6IADB: Mailing list email only, confirmed opt-in
RCVD_IN_IADB_NOCONTROL–IADB: Has absolutely no mailing controls in place
RCVD_IN_IADB_OOO–IADB: One-to-one/transactional email only
RCVD_IN_IADB_OPTIN-2.057IADB: All mailing list mail is opt-in
RCVD_IN_IADB_OPTIN_GT50-1.208IADB: Opt-in used more than 50% of the time
RCVD_IN_IADB_OPTIN_LT50–IADB: Opt-in used less than 50% of the time
RCVD_IN_IADB_OPTOUTONLY–IADB: Scrapes addresses, pure opt-out only
RCVD_IN_IADB_RDNS-0.167IADB: Sender has reverse DNS record
RCVD_IN_IADB_SENDERID-0.001IADB: Sender publishes Sender ID record
RCVD_IN_IADB_SOCIAL1IADB: social networking service email
RCVD_IN_IADB_SPF-0.001IADB: Sender publishes SPF record
RCVD_IN_IADB_TRACK1IADB: email with open and read tracking services
RCVD_IN_IADB_UNVERIFIED_1–IADB: Accepts unverified sign-ups
RCVD_IN_IADB_UNVERIFIED_2–IADB: Accepts unverified sign-ups, gives chance to opt out
RCVD_IN_IADB_URG1IADB: time-critical urgent or emergency communications
RCVD_IN_IADB_UT_CPEAR–IADB: Complies with Utah's CPEAR law
RCVD_IN_IADB_UT_CPR_30–
RCVD_IN_IADB_UT_CPR_MAT0.001
RCVD_IN_IADB_VOUCHED-2.2ISIPP IADB lists as vouched-for sender
RCVD_IN_MAPS_DUL–Relay in DUL, http://www.mail-abuse.com/enduserinfo_dul.html
RCVD_IN_MAPS_NML–Relay in NML, http://www.mail-abuse.com/enduserinfo_nml.html
RCVD_IN_MAPS_OPS–Relay in OPS, http://www.mail-abuse.com/enduserinfo_ops.html
RCVD_IN_MAPS_RBL–Relay in RBL, http://www.mail-abuse.com/enduserinfo_rbl.html
RCVD_IN_MAPS_RSS–Relay in RSS, http://www.mail-abuse.com/enduserinfo_rss.html
RCVD_IN_MSPIKE_BL0.001Mailspike blocklisted
RCVD_IN_MSPIKE_H20.001Average reputation (+2)
RCVD_IN_MSPIKE_H30.001Good reputation (+3)
RCVD_IN_MSPIKE_H40.001Very Good reputation (+4)
RCVD_IN_MSPIKE_H50.001Excellent reputation (+5)
RCVD_IN_MSPIKE_L20.001Suspicious reputation (-2)
RCVD_IN_MSPIKE_L30.001Low reputation (-3)
RCVD_IN_MSPIKE_L40.001Bad reputation (-4)
RCVD_IN_MSPIKE_L50.001Very bad reputation (-5)
RCVD_IN_MSPIKE_WL0.001Mailspike good senders
RCVD_IN_MSPIKE_ZBI0.001
RCVD_IN_PBL3.558Received via a relay in Spamhaus PBL
RCVD_IN_PSBL2.7Received via a relay in PSBL
RCVD_IN_SBL2.596Received via a relay in Spamhaus SBL
RCVD_IN_SBL_CSS3.558Received via a relay in Spamhaus SBL-CSS
RCVD_IN_VALIDITY_CERTIFIED–Sender in Validity Certification - Contact certification@validity.com
RCVD_IN_VALIDITY_CERTIFIED_BLOCKED–ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information.
RCVD_IN_VALIDITY_RPBL–Relay in Validity RPBL, https://senderscore.org/blocklistlookup/
RCVD_IN_VALIDITY_RPBL_BLOCKED–ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information.
RCVD_IN_VALIDITY_SAFE–Sender in Validity Safe - Contact certification@validity.com
RCVD_IN_VALIDITY_SAFE_BLOCKED–ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information.
RCVD_IN_XBL0.724Received via a relay in Spamhaus XBL
RCVD_IN_ZEN_BLOCKED0.001ADMINISTRATOR NOTICE: The query to zen.spamhaus.org was blocked. See https://www.spamhaus.org/returnc/vol/
RCVD_IN_ZEN_BLOCKED_OPENDNS0.001ADMINISTRATOR NOTICE: The query to zen.spamhaus.org was blocked due to usage of an open resolver. See https://www.spamhaus.org/returnc/pub/
RCVD_MAIL_COM–Forged Received header (contains post.com or mail.com)
RCVD_NUMERIC_HELO0.865
RDNS_DYNAMIC0.363Delivered to internal network by host with dynamic-looking rDNS
RDNS_LOCALHOST0.969Sender's public rDNS is "localhost"
RDNS_NONE1.274Delivered to internal network by a host with no rDNS
RDNS_NUM_TLD_ATCHNX1Relay rDNS has numeric TLD + suspicious attachment
RDNS_NUM_TLD_XM1Relay rDNS has numeric TLD + suspicious headers
REDIR_URL_CHAINED0.01Message has redirected URL chained to other redirectors
REDIR_URL_LOOP0.01Message has redirected URL that loops back to itself
REDIR_URL_MAXCHAIN0.01Message has redirected URL that causes too many redirections
REFINANCE_NOW–Home refinancing
REFINANCE_YOUR_HOME–Home refinancing
REPLICA_WATCH3.164Message talks about a replica watch
REPLYTO_WITHOUT_TO_CC1.946
REPTO_419_FRAUD1Reply-To is known advance fee fraud collector mailbox
REPTO_419_FRAUD_AOL1Reply-To is known advance fee fraud collector mailbox
REPTO_419_FRAUD_AOL_LOOSE1Ends-in-digits Reply-To is similar to known advance fee fraud collector mailbox
REPTO_419_FRAUD_CNS1Reply-To is known advance fee fraud collector mailbox
REPTO_419_FRAUD_GM0.001Reply-To is known advance fee fraud collector mailbox
REPTO_419_FRAUD_GM_LOOSE1Ends-in-digits Reply-To is similar to known advance fee fraud collector mailbox
REPTO_419_FRAUD_HM1Reply-To is known advance fee fraud collector mailbox
REPTO_419_FRAUD_HM_LOOSE1Ends-in-digits Reply-To is similar to known advance fee fraud collector mailbox
REPTO_419_FRAUD_OL1.819Reply-To is known advance fee fraud collector mailbox
REPTO_419_FRAUD_PM1Reply-To is known advance fee fraud collector mailbox
REPTO_419_FRAUD_QQ1Reply-To is known advance fee fraud collector mailbox
REPTO_419_FRAUD_YH1Reply-To is known advance fee fraud collector mailbox
REPTO_419_FRAUD_YH_LOOSE1Ends-in-digits Reply-To is similar to known advance fee fraud collector mailbox
REPTO_419_FRAUD_YJ1Reply-To is known advance fee fraud collector mailbox
REPTO_419_FRAUD_YN1Reply-To is known advance fee fraud collector mailbox
REPTO_INFONUMSCOM1
REPTO_QUOTE_AOL–AOL doesn't do quoting like this
REPTO_QUOTE_IMS–IMS doesn't do quoting like this
REPTO_QUOTE_MSN–MSN doesn't do quoting like this
REPTO_QUOTE_QUALCOMM–Qualcomm/Eudora doesn't do quoting like this
REPTO_QUOTE_YAHOO0.49Yahoo! doesn't do quoting like this
RISK_FREE2.327No risk!
RP_MATCHES_RCVD-0.001
RUDE_HTML–Spammer message says you need an HTML mailer
SB_GIF_AND_NO_URIS2.199
SCC_CANSPAM_12.282Interesting compliance language
SCC_CANSPAM_21.335Interesting compliance language
SCC_ISEMM_LID_11Fingerprint of a particular spammer using an old spamware
SCC_ISEMM_LID_1B1Genericized spammer fingerprint
SCC_SPECIAL_GUID1Unique in a similar way
SENDGRID_REDIR0.001
SENDGRID_REDIR_PHISH1Redirect URI via Sendgrid + phishing signs
SEO_SUSP_NTLD1SEO offer from suspicious TLD
SHOPIFY_IMG_NOT_RCVD_SFY1Shopify hosted image but message not from Shopify
SHORTCIRCUIT–Not all rules were run, due to a shortcircuited rule
SHORTENER_SHORT_IMG2.499Short HTML + image + URL shortener
SHORT_HELO_AND_INLINE_IMAGE0.1Short HELO string, with inline image
SHORT_IMG_SUSP_NTLD1.019Short HTML + image + suspicious TLD
SHORT_TERM_PRICE0.001
SHY_OBFU_EXPIRE1Obfuscation, probable phishing
SHY_OBFU_PASSWORD1Obfuscation, probable phishing
SORTED_RECIPS2.474Recipient list is sorted by address
SPAMMY_XMAILER0.862X-Mailer string is common in spam and not in ham
SPF_FAIL0.919SPF: sender does not match SPF record (fail)
SPF_HELO_FAIL0.001SPF: HELO does not match SPF record (fail)
SPF_HELO_NEUTRAL0.001SPF: HELO does not match SPF record (neutral)
SPF_HELO_NONE0.001SPF: HELO does not publish an SPF Record
SPF_HELO_PASS-0.001SPF: HELO matches SPF record
SPF_HELO_SOFTFAIL0.896SPF: HELO does not match SPF record (softfail)
SPF_NEUTRAL0.652SPF: sender does not match SPF record (neutral)
SPF_NONE0.001SPF: sender does not publish an SPF Record
SPF_PASS-0.001SPF: sender matches SPF record
SPF_SOFTFAIL0.972SPF: sender does not match SPF record (softfail)
SPOOFED_FREEMAIL0.747
SPOOFED_FREEMAIL_NO_RDNS1.1From SPOOFED_FREEMAIL and no rDNS
SPOOFED_FREEM_REPTO1.489Forged freemail sender with freemail reply-to
SPOOFED_FREEM_REPTO_CHN1Forged freemail sender with Chinese freemail reply-to
SPOOFED_FREEM_REPTO_RUS1Forged freemail sender with Russian freemail reply-to
SPOOF_COM2COM0.001URI contains ".com" in middle and end
SPOOF_COM2OTH0.001URI contains ".com" in middle
SPOOF_GMAIL_MID0.001From Gmail but it doesn't seem to be...
SPOOF_NET2COM–URI contains ".net" or ".org", then ".com"
STATIC_XPRIO_OLE1.16Static RDNS + X-Priority + MIMEOLE
STOCK_ALERT–Offers a alert about a stock
STOCK_IMG_CTYPE0.005Stock spam image part, with distinctive Content-Type header
STOCK_IMG_HDR_FROM0.001Stock spam image part, with distinctive From line
STOCK_IMG_HTML0.028Stock spam image part, with distinctive HTML
STOCK_IMG_OUTLOOK0.702Stock spam image part, with Outlook-like features
STOCK_PRICES–
STOCK_TIP1Stock tips
STOX_AND_PRICE–
STOX_REPLY_TYPE0.212
STOX_REPLY_TYPE_WITHOUT_QUOTES1.86
STRONG_BUY–Tells you about a strong buy
SUBJECT_DIET1.563Subject talks about losing pounds
SUBJECT_DRUG_GAP_C0.989Subject contains a gappy version of 'cialis'
SUBJECT_DRUG_GAP_L2.304Subject contains a gappy version of 'levitra'
SUBJECT_DRUG_GAP_S–Subject contains a gappy version of 'soma'
SUBJECT_DRUG_GAP_X–Subject contains a gappy version of 'xanax'
SUBJECT_FUZZY_CHEAP1.831Attempt to obfuscate words in Subject:
SUBJECT_FUZZY_MEDS–Attempt to obfuscate words in Subject:
SUBJECT_FUZZY_PENIS–Attempt to obfuscate words in Subject:
SUBJECT_FUZZY_TION–Attempt to obfuscate words in Subject:
SUBJECT_FUZZY_VPILL–Attempt to obfuscate words in Subject:
SUBJECT_IN_BLACKLIST100DEPRECATED: See SUBJECT_IN_BLOCKLIST
SUBJECT_IN_BLOCKLIST0.01Subject: contains string in the user's block-list
SUBJECT_IN_WELCOMELIST-0.01Subject: contains string in the user's welcome-list
SUBJECT_IN_WHITELIST-100DEPRECATED: See SUBJECT_IN_WELCOMELIST
SUBJECT_NEEDS_ENCODING0.1Subject includes non-encoded illegal characters
SUBJECT_SEXUAL–Subject indicates sexually-explicit content
SUBJ_ALL_CAPS0.5Subject is all capitals
SUBJ_AS_SEEN3.099Subject contains "As Seen"
SUBJ_BRKN_WORDNUMS1Subject contains odd word breaks and numbers
SUBJ_BUY1.498Subject line starts with Buy or Buying
SUBJ_DOLLARS0.1Subject starts with dollar amount
SUBJ_ILLEGAL_CHARS1.105Subject: has too many raw illegal characters
SUBJ_UNNEEDED_HTML1Unneeded HTML formatting in Subject:
SUBJ_YOUR_FAMILY2.999Subject contains "Your Family"
SURBL_BLOCKED0.001ADMINISTRATOR NOTICE: The query to SURBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists\#dnsbl-block for more information.
SUSPICIOUS_RECIPS2.497Similar addresses in recipient list
SYSADMIN1Supposedly from your IT department
TAGSTAT_IMG_NOT_RCVD_TGST1Tagstat hosted image but message not from Tagstat
TARINGANET_IMG_NOT_RCVD_TN1media.taringa.net hosted image but message not from taringa.net
TBIRD_SUSP_MIME_BDRY2.4Unlikely Thunderbird MIME boundary
TELEGRAM_MESSAGE1Sent a Telegram message, probable phishing exfil
TEQF_USR_IMAGE1To and from user nearly same + image
TEQF_USR_MSGID_HEX1To and from user nearly same + unusual message ID
TEQF_USR_MSGID_MALF1To and from user nearly same + malformed message ID
TEQF_USR_POLITE0.963To and from user nearly same + polite greeting
THEBAT_UNREG1.843
THIS_AD2.699"This ad" and variants
THIS_IS_ADV_SUSP_NTLD1This is an advertisement from a suspicious TLD
TONLINE_FAKE_DKIM1t-online.de doesn't do DKIM
TO_EQ_FM_DIRECT_MX0.001To == From and direct-to-MX
TO_EQ_FM_DOM_HTML_IMG2.499To domain == From domain and HTML image link
TO_EQ_FM_DOM_HTML_ONLY0.001To domain == From domain and HTML only
TO_EQ_FM_DOM_SPF_FAIL0.001To domain == From domain and external SPF failed
TO_EQ_FM_HTML_DIRECT0.001To == From and HTML only, direct-to-MX
TO_EQ_FM_HTML_ONLY0.001To == From and HTML only
TO_EQ_FM_SPF_FAIL0.001To == From and external SPF failed
TO_IN_SUBJ0.099To address is in Subject
TO_MALFORMED0.1To: has a malformed address
TO_NAME_SUBJ_NO_RDNS2.999Recipient username in subject + no rDNS
TO_NO_BRKTS_DYNIP3.999To: lacks brackets and dynamic rDNS
TO_NO_BRKTS_FROM_MSSP2.499Multiple header formatting problems
TO_NO_BRKTS_HTML_IMG0.001To: lacks brackets and HTML and one image
TO_NO_BRKTS_HTML_ONLY1.999To: lacks brackets and HTML only
TO_NO_BRKTS_MSFT2.499To: lacks brackets and supposed Microsoft tool
TO_NO_BRKTS_NORDNS_HTML1.999To: lacks brackets and no rDNS and HTML only
TO_NO_BRKTS_PCNT2.499To: lacks brackets + percentage
TO_TOO_MANY_WFH_011Work-from-Home + many recipients
TRACKER_ID0.1Incorporates a tracking ID number
TT_MSGID_TRUNC0.023Scora: Message-Id ends after left-bracket + digits
TT_OBSCURED_VALIUM–Scora: obscured "VALIUM" in subject
TT_OBSCURED_VIAGRA–Scora: obscured "VIAGRA" in subject
TVD_ACT_193–Message refers to an act passed in the 1930s
TVD_APPROVED1Body states that the recipient has been approved
TVD_DEAR_HOMEOWNER–Spam with generic salutation of "dear homeowner"
TVD_EB_PHISH–
TVD_ENVFROM_APOST–Envelope From contains single-quote
TVD_FINGER_020.001
TVD_FLOAT_GENERAL–Message uses CSS float style
TVD_FROM_10.999From address appears to be a throwaway domain
TVD_FUZZY_DEGREE–Obfuscation of the word "degree"
TVD_FUZZY_FINANCE–Obfuscation of the word "finance"
TVD_FUZZY_FIXED_RATE–Obfuscation of the phrase "fixed rate"
TVD_FUZZY_MICROCAP–Obfuscation of the word "micro-cap"
TVD_FUZZY_PHARMACEUTICAL–Obfuscation of the word "pharmaceutical"
TVD_FUZZY_SYMBOL–Obfuscation of the word "symbol"
TVD_FW_GRAPHIC_NAME_LONG0.648Long image attachment name
TVD_FW_GRAPHIC_NAME_MID0.001Medium sized image attachment name
TVD_INCREASE_SIZE0.601Advertising for penis enlargement
TVD_PH_BODY_ACCOUNTS_PRE0.001The body matches phrases such as "accounts suspended", "account credited", "account verification"
TVD_PH_REC0.1Message includes a phrase commonly used in phishing mails
TVD_PH_SEC0.1Message includes a phrase commonly used in phishing mails
TVD_PP_PHISH–
TVD_QUAL_MEDS2.397The body matches phrases such as "quality meds" or "quality medication"
TVD_RATWARE_CB–Content-Type header that is commonly indicative of ratware
TVD_RATWARE_CB_2–Content-Type header that is commonly indicative of ratware
TVD_RATWARE_MSGID_02–Ratware with a Message-ID header that is entirely lower-case
TVD_RCVD_IP0.001Message was received from an IP address
TVD_RCVD_IP40.001Message was received from an IPv4 address
TVD_SECTION–References to specific legal codes
TVD_SILLY_URI_OBFU–URI obfuscation that can fool a URIBL or a uri rule
TVD_SPACED_SUBJECT_WORD3–Entire subject is "UPPERlowerUPPER" with no whitespace
TVD_SPACE_ENCODED2.499Space ratio & encoded subject
TVD_SPACE_RATIO0.001
TVD_SPACE_RATIO_MINFP0.001Space ratio (vertical text obfuscation?)
TVD_STOCK1–Spam related to stock trading
TVD_SUBJ_ACC_NUM0.1Subject has spammy looking monetary reference
TVD_SUBJ_FINGER_03–Entire subject is enclosed in asterisks "* like so *"
TVD_SUBJ_OWE–Subject line states that the recipieint is in debt
TVD_SUBJ_WIPE_DEBT2.291Spam advertising a way to eliminate debt
TVD_VISIT_PHARMA1.196Body mentions online pharmacy
TVD_VIS_HIDDEN–Invisible textarea HTML tags
TW_GIBBERISH_MANY1Lots of gibberish text to spoof pattern matching filters
TXREP1Score normalizing based on sender's reputation
T_ACH_CANCELLED_EXE0.01"ACH cancelled" probable malware
T_ANY_PILL_PRICE0.01Prices for pills
T_CDISP_SZ_MANY–Suspicious MIME header
T_CTE_BAS640.01Malformated Content-Type-Encoding
T_CTYPE_NULL0.01Malformed Content-Type header
T_DATE_IN_FUTURE_Q_PLUS0.01Date: is over 4 months after Received: date
T_DOC_ATTACH_NO_EXT0.01Document attachment with suspicious name
T_DOS_OUTLOOK_TO_MX_IMAGE0.01Direct to MX with Outlook headers and an image
T_DOS_ZIP_HARDCORE–hardcore.zip file attached; quite certainly a virus
T_DRUGS_ERECTILE_SHORT_SHORTNER0.01Short erectile drugs advert with T_URL_SHORTENER
T_FILL_THIS_FORM_FRAUD_PHISH0.01Answer suspicious question(s)
T_FILL_THIS_FORM_LOAN0.01Answer loan question(s)
T_FILL_THIS_FORM_SHORT0.01Fill in a short form with personal information
T_FKO_CAL_RAND_START0.01Calendar invite with random start time
T_FORGED_TBIRD_IMG_SIZE0.01Likely forged Thunderbird image spam
T_FREEMAIL_DOC_PDF0.01MS document or PDF attachment, from freemail
T_FREEMAIL_DOC_PDF_BCC0.01MS document or PDF attachment, from freemail, all recipients hidden
T_FREEMAIL_RVW_ATTCH0.01Please review attached document, from freemail
T_FROMNAME_EQUALS_TO0.01From:name matches To:
T_FROMNAME_SPOOFED_EMAIL0.01From:name looks like a spoofed email
T_FROM_MULTI_SHORT_IMG0.01Multiple From addresses + short message with image
T_FUZZY_OPTOUT0.01Obfuscated opt-out text
T_FUZZY_TELEGRAM0.01Obfuscated "telegram"
T_FUZZY_TRUMP0.01Obfuscated "Trump"
T_GB_FROMNAME_SPOOFED_EMAIL_IP0.01From:name looks like a spoofed email from a spoofed ip
T_GB_STORAGE_GOOGLE_EMAIL0.01Google storage cloud abuse
T_GB_WEBFORM0.01Webform with url shortener
T_GB_YOUTUBE_EMAIL0.01Youtube attribution links abuse
T_HTML_ATTACH0.01HTML attachment to bypass scanning?
T_ISO_ATTACH0.01ISO attachment - possible malware delivery
T_KAM_HTML_FONT_INVALID0.01Test for Invalidly Named or Formatted Colors in HTML
T_LARGE_PCT_AFTER_MANY0.01Many large percentages after...
T_LOTTO_AGENT0.01Claims Agent
T_LOTTO_AGENT_FM0.01Claims Agent
T_LOTTO_AGENT_RPLY0.01Claims Agent
T_LOTTO_URI0.01Claims Department URL
T_MANY_PILL_PRICE0.01Prices for many pills
T_MIME_MALF0.01Malformed MIME: headers in body
T_MONEY_PERCENT0.01X% of a lot of money for you
T_MXG_BING_REDIR_SUSP–Suspicious Bing redirect
T_MXG_LOWER_HDR_SPAM0.01Lower case header spam
T_OBFU_ATTACH_MISSP0.01Obfuscated attachment type and misspaced From
T_OBFU_DOC_ATTACH–MS Document attachment with generic MIME type
T_OBFU_GIF_ATTACH–GIF attachment with generic MIME type
T_OBFU_HTML_ATT_MALW0.01HTML attachment with incorrect MIME type - possible malware
T_OBFU_JPG_ATTACH–JPG attachment with generic MIME type
T_OBFU_PDF_ATTACH–PDF attachment with generic MIME type
T_OFFER_ONLY_AMERICA0.01Offer only available to US
T_PDS_BTC_AHACKER0.01Bitcoin Hacker
T_PDS_BTC_HACKER0.01Bitcoin Hacker
T_PDS_BTC_NTLD0.01Bitcoin suspect NTLD
T_PDS_EMPTYSUBJ_URISHRT0.01Empty subject with little more than URI shortener
T_PDS_FREEMAIL_REPLYTO_URISHRT0.01Freemail replyto with URI shortener
T_PDS_FROM_2_EMAILS_SHRTNER0.01From 2 emails short email with little more than a URI shortener
T_PDS_LTC_AHACKER0.01Litecoin Hacker
T_PDS_LTC_HACKER0.01Litecoin Hacker
T_PDS_OTHER_BAD_TLD0.01Untrustworthy TLDs
T_PDS_PRO_TLD0.01.pro TLD
T_PDS_SHORTFWD_URISHRT0.01Threaded email with URI shortener
T_PDS_SHORTFWD_URISHRT_FP0.01Apparently a short fwd/re with URI shortener
T_PDS_SHORTFWD_URISHRT_QP0.01Apparently a short fwd/re with URI shortener
T_PDS_SHORT_SPOOFED_URL0.01HTML message short and T_SPOOFED_URL (S_U_FP)
T_PDS_TINYSUBJ_URISHRT0.01Short subject with URL shortener
T_PDS_TO_EQ_FROM_NAME0.01From: name same as To: address
T_PDS_URISHRT_LOCALPART_SUBJ0.01Localpart of To in subject
T_PHOTO_EDITING_DIRECT0.01Image editing service, direct to MX
T_PHOTO_EDITING_FREEM0.01Image editing service, freemail or CHN replyto
T_REMOTE_IMAGE0.01Message contains an external image
T_SCC_BOGUS_CTE_10.01Bogus Content-Transfer-Encoding header
T_SCC_CTMPP0.01Uncommon Content-Type
T_SENT_TO_EMAIL_ADDR0.01Email was sent to email address
T_SHARE_50_500.01Share the money 50/50
T_SHORT_SHORTNER0.01Short body with little more than a link to a shortener
T_SPF_HELO_PERMERROR0.01SPF: test of HELO record failed (permerror)
T_SPF_HELO_TEMPERROR0.01SPF: test of HELO record failed (temperror)
T_SPF_PERMERROR0.01SPF: test of record failed (permerror)
T_SPF_TEMPERROR0.01SPF: test of record failed (temperror)
T_STY_INVIS_DIRECT0.01HTML hidden text + direct-to-MX
T_SUSPNTLD_EXPIRATION_EXTORT0.01Susp NTLD with an expiration notice and lotsa money
T_TONOM_EQ_TOLOC_SHRT_PSHRTNER0.01Short subject with potential shortener and To:name eq To:local
T_TONOM_EQ_TOLOC_SHRT_SHRTNER0.01Short email with shortener and To:name eq To:local
T_URI_GOOG_STO_SUBD_SPAMMY0.01Link to spammy content hosted by google storage
T_WON_MONEY_ATTACH0.01You won lots of money! See attachment.
T_WON_NBDY_ATTACH0.01You won lots of money! See attachment.
T_XPRIO_URL_SHORTNER0.01X-Priority header and short URL
T_ZW_OBFU_BITCOIN0.01Obfuscated text + bitcoin ID - possible extortion
T_ZW_OBFU_FREEM0.01Obfuscated text + freemail
UC_GIBBERISH_OBFU1Multiple instances of "word VERYLONGGIBBERISH word"
UNCLAIMED_MONEY2.699People just leave money laying around
UNCLOSED_BRACKET1.329Headers contain an unclosed bracket
UNDISC_FREEM3Undisclosed recipients + freemail reply-to
UNDISC_MONEY2.999Undisclosed recipients + money/fraud signs
UNICODE_OBFU_ASC2.499Obfuscating text with unicode
UNICODE_OBFU_ZW0.001Obfuscating text with hidden characters
UNICODE_OBFU_ZW_MANY0.001Heavily obfuscating text with hidden characters
UNICODE_RTL_OBFU1Word obfuscation using Unicode right-to-left markers
UNPARSEABLE_RELAY0.001Informational: message has unparseable relay lines
UNRESOLVED_TEMPLATE0.716Headers contain an unresolved template
UNSUB_GOOG_FORM1Unsubscribe via Google Docs form
UNWANTED_LANGUAGE_BODY2.8Message written in an undesired language
UPPERCASE_50_750.791message body is 50-75% uppercase
UPPERCASE_75_1001.189message body is 75-100% uppercase
UPPERCASE_URI2.749Link protocol has unexpected mixed case
URG_BIZ0.941Contains urgent matter
URIBL_ABUSE_SURBL1.948Contains an URL listed in the ABUSE SURBL blocklist
URIBL_BLACK1.7Contains an URL listed in the URIBL blacklist
URIBL_BLOCKED0.001ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists\#dnsbl-block for more information.
URIBL_CR_SURBL1.263Contains an URL listed in the CR SURBL blocklist
URIBL_CSS0.1Contains an URL's NS IP listed in the Spamhaus CSS blocklist
URIBL_CSS_A0.1Contains URL's A record listed in the Spamhaus CSS blocklist
URIBL_CT_SURBL1.699Contains an URL listed in the CT SURBL blocklist
URIBL_DBL_ABUSE_BOTCC2.5Contains an abused botnet C&C URL listed in the Spamhaus DBL blocklist
URIBL_DBL_ABUSE_MALW2.5Contains an abused malware URL listed in the Spamhaus DBL blocklist
URIBL_DBL_ABUSE_PHISH2.5Contains an abused phishing URL listed in the Spamhaus DBL blocklist
URIBL_DBL_ABUSE_REDIR0.001Contains an abused redirector URL listed in the Spamhaus DBL blocklist
URIBL_DBL_ABUSE_SPAM2Contains an abused spamvertized URL listed in the Spamhaus DBL blocklist
URIBL_DBL_BLOCKED0.001ADMINISTRATOR NOTICE: The query to dbl.spamhaus.org was blocked. See https://www.spamhaus.org/returnc/vol/
URIBL_DBL_BLOCKED_OPENDNS0.001ADMINISTRATOR NOTICE: The query to dbl.spamhaus.org was blocked due to usage of an open resolver. See https://www.spamhaus.org/returnc/pub/
URIBL_DBL_BOTNETCC2.5Contains a botned C&C URL listed in the Spamhaus DBL blocklist
URIBL_DBL_ERROR0.001Error: queried the Spamhaus DBL blocklist for an IP
URIBL_DBL_MALWARE2.5Contains a malware URL listed in the Spamhaus DBL blocklist
URIBL_DBL_PHISH2.5Contains a Phishing URL listed in the Spamhaus DBL blocklist
URIBL_DBL_SPAM2.5Contains a spam URL listed in the Spamhaus DBL blocklist
URIBL_DM_SURBL0.001Contains an URL listed in the DM SURBL blocklist
URIBL_GREY1.084Contains an URL listed in the URIBL greylist
URIBL_MULTI_SURBL_HEADERS1Domain found in surbl multi for from or reply-to
URIBL_MW_SURBL1.263Contains a URL listed in the MW SURBL blocklist
URIBL_PH_SURBL0.001Contains an URL listed in the PH SURBL blocklist
URIBL_RED0.001Contains an URL listed in the URIBL redlist
URIBL_RHS_DOB0.276Contains an URI of a new domain (Day Old Bread)
URIBL_SBL0.644Contains an URL's NS IP listed in the Spamhaus SBL blocklist
URIBL_SBL_A0.1Contains URL's A record listed in the Spamhaus SBL blocklist
URIBL_ZEN_BLOCKED0.001ADMINISTRATOR NOTICE: The query to zen.spamhaus.org was blocked. See https://www.spamhaus.org/returnc/vol/
URIBL_ZEN_BLOCKED_OPENDNS0.001ADMINISTRATOR NOTICE: The query to zen.spamhaus.org was blocked due to usage of an open resolver. See https://www.spamhaus.org/returnc/pub/
URI_ADOBESPARK1
URI_AZURE_CLOUDAPP1Link to hosted azure web application, possible phishing
URI_CLOUDFLAREIPFS1References Interplanetary File System PtP content via CloudFlare, likely phishing
URI_DASHGOVEDU1Suspicious domain name
URI_DATA1"data:" URI - possible malware or phish
URI_DOTCN_LOGIN1Login page in .cn subdomain - possible Chinese phishing
URI_DOTCN_SPOOF2.997.CN TLD for non-.CN visible URL - likely Chinese phishing
URI_DOTEDU1Has .edu URI
URI_DOTEDU_ENTITY1Via .edu MTA + suspicious HTML content
URI_DOTTY_HEX1Suspicious URI format
URI_DQ_UNSUB1IP-address unsubscribe URI
URI_DWEBIPFS2.192References Interplanetary File System PtP content via dweb.link, likely phishing
URI_EXCESS_SLASHES2.499Too many slashes in URI, possible attempt to bypass spam filtering
URI_FIREBASEAPP2.999Link to hosted firebase web application, possible phishing
URI_GLITCHME1References glitch.me content, possible phishing
URI_GOOGDRAWPREVIEW_MINFP3Link to image at Google Docs, probable phishing
URI_GOOGLE_PROXY2.099Accessing a blacklisted URI or obscuring source of phish via Google proxy?
URI_GOOG_STO_SPAMMY1Link to spammy content hosted by google storage
URI_HEX0.1URI hostname has long hexadecimal sequence
URI_HEX_IP1URI with hex-encoded IP-address host
URI_HOST_IN_BLACKLIST100DEPRECATED: See URI_HOST_IN_BLOCKLIST
URI_HOST_IN_BLOCKLIST0.01Host or Domain is listed in the user's URI block-list
URI_HOST_IN_WELCOMELIST-0.01Host or Domain is listed in the user's URI welcome-list
URI_HOST_IN_WHITELIST-100DEPRECATED: See URI_HOST_IN_WELCOMELIST
URI_IMG_CWINDOWSNET0.734Non-MSFT image hosted by Microsoft Azure infra, possible phishing
URI_IMG_WP_REDIR1Image via WordPress "accelerator" proxy
URI_IPFS1.782References Interplanetary File System PtP content, probable phishing
URI_IPFSIO3.192References Interplanetary File System PtP content via ipfs.io, likely phishing
URI_LONG_REPEAT1Long identical host+domain
URI_MALWARE_SCMS1Link to malware exploit download (.SettingContent-ms file)
URI_NOVOWEL0.5URI hostname has long non-vowel sequence
URI_NO_WWW_BIZ_CGI1CGI in .biz TLD other than third-level "www"
URI_NO_WWW_INFO_CGI1CGI in .info TLD other than third-level "www"
URI_ONLY_MSGID_MALF1URI only + malformed message ID
URI_OPTOUT_3LD1Opt-out URI, suspicious hostname
URI_OPTOUT_USME1Opt-out URI, unusual TLD
URI_PHISH2.499Phishing using web form
URI_PHP_REDIR1PHP redirect to different URL (link obfuscation)
URI_REPLIT_DEV3replit.dev URL, probably phishing
URI_TRUNCATED0.001Message contained a URI which was truncated
URI_TRY_3LD0.744"Try it" URI, suspicious hostname
URI_TRY_USME1"Try it" URI, unusual TLD
URI_UNSUBSCRIBE–URI contains suspicious unsubscribe link
URI_WPADMIN1.512WordPress login/admin URI, possible phishing
URI_WP_DIRINDEX1URI for compromised WordPress site, possible malware
URI_WP_HACKED2.486URI for compromised WordPress site, possible malware
URI_WP_HACKED_21.851URI for compromised WordPress site, possible malware
URL_SHORTENER_CHAINED0.01Message contains shortened URL chained to other shorteners
URL_SHORTENER_DISABLED2Message contains shortened URL that has been disabled due to abuse
USB_DRIVES1Trying to sell custom USB flash drives
USER_IN_ALL_SPAM_TO-100User is listed in 'all_spam_to'
USER_IN_BLACKLIST100DEPRECATED: See USER_IN_BLOCKLIST
USER_IN_BLACKLIST_TO10DEPRECATED: See USER_IN_BLOCKLIST_TO
USER_IN_BLOCKLIST0.01From: user is listed in the block-list
USER_IN_BLOCKLIST_TO0.01User is listed in 'blocklist_to'
USER_IN_DEF_DKIM_WL-7.5From: address is in the default DKIM welcome-list
USER_IN_DEF_SPF_WL-7.5From: address is in the default SPF welcome-list
USER_IN_DEF_WELCOMELIST-0.01From: user is listed in the default welcome-list
USER_IN_DEF_WHITELIST-15DEPRECATED: See USER_IN_DEF_WELCOMELIST
USER_IN_DKIM_WELCOMELIST-0.01From: address is in the user's DKIM welcomelist
USER_IN_DKIM_WHITELIST-100DEPRECATED: See USER_IN_DKIM_WELCOMELIST
USER_IN_MORE_SPAM_TO-20User is listed in 'more_spam_to'
USER_IN_SPF_WELCOMELIST-0.01From: address is in the user's SPF welcomelist
USER_IN_SPF_WHITELIST-100DEPRECATED: See USER_IN_SPF_WELCOMELIST
USER_IN_WELCOMELIST-0.01User is listed in 'welcomelist_from'
USER_IN_WELCOMELIST_TO-0.01User is listed in 'welcomelist_to'
USER_IN_WHITELIST-100DEPRECATED: See USER_IN_WELCOMELIST
USER_IN_WHITELIST_TO-6DEPRECATED: See USER_IN_WELCOMELIST_TO
VBOUNCE_MESSAGE0.1Virus-scanner bounce message
VFY_ACCT_NORDNS1.705Verify your account to a poorly-configured MTA - probable phishing
VIA_GAP_GRA–Attempts to disguise the word 'viagra'
VISTA_COST1Old MSFT msgid format + "cost"
VISTA_TONOM_EQ_TOLOC1Old MSFT msgid format + To display name = username
VPS_NO_NTLD1vps[0-9] domain at a suspiscious TLD
WALMART_IMG_NOT_RCVD_WAL1Walmart hosted image but message not from Walmart
WEIRD_PORT0.001Uses non-standard port number for HTTP
WEIRD_QUOTING0.001Weird repeated double-quotation marks
WIKI_IMG2.499Image from wikipedia
WITH_LC_SMTP–Received line contains spam-sign (lowercase smtp)
WORD_INVIS1.933A hidden word
WORD_INVIS_MANY2.999Multiple individual hidden words
XM_DIGITS_ONLY1X-Mailer malformed
XM_LIGHT_HEAVY2.499Special edition of a MUA
XM_PHPMAILER_FORGED1Apparently forged header
XM_RANDOM2.499X-Mailer apparently random
XPRIO2.249Has X-Priority header
XPRIO_SHORT_SUBJ1Has X Priority header + short subject
XPRIO_VISTA1.589X-Priority + old MSFT msgid format
X_IP0.001Message has X-IP header
X_MAILER_CME_6543_MSN2.004
X_MESSAGE_INFO–Bulk email fingerprint (X-Message-Info) found
X_PRIORITY_CC–Cc: after X-Priority: (bulk email fingerprint)
YAHOO_DRS_REDIR–Has Yahoo Redirect URI
YAHOO_RD_REDIR–Has Yahoo Redirect URI
ZW_OBFU_FROMTOSUBJ1Obfuscated text + from in to and subject

Rules and scores: Apache SpamAssassin, Apache License 2.0.

Frequently asked questions

What is a good SpamAssassin score?

Lower is better. Messages scoring 5.0 or more are treated as spam by default. Aim for a score below 2; legitimate, well-authenticated email often scores 0 or below.

Why do some rules have a negative score?

Negative scores mark signs of legitimate mail, such as a valid DKIM signature from your own domain or a listing on the DNSWL allowlist. They lower the total score.

What do T_ rules mean?

Rules starting with T_ are in testing. They get a tiny score (0.01) until their accuracy is measured, so they barely affect the result.

How do I see which rules my email triggers?

Send it to a test address in the email spam checker. It runs SpamAssassin and lists every rule with an explanation and a fix.

Email validation API

Clean lists, fewer bounces

Bounces hurt your sender reputation as much as spammy content. Validate addresses before you send, in your sign-up form or in bulk.

Read the docs

100 free validations every month. No credit card required.

GET https://api.emailvalidation.io/v1/info?email=support@emailvalidation.io

{
  "email": "support@emailvalidation.io",
  "domain": "emailvalidation.io",
  "format_valid": true,
  "mx_found": true,
  "smtp_check": true,
  "disposable": false,
  "role": true,
  "free": false,
  "score": 0.64,
  "state": "deliverable",
  "reason": "valid_mailbox"
}

Free email tools

Start using our email validation software today!

Get 100 validations per month for free