diff --git a/rules/regexp/headers.lua b/rules/regexp/headers.lua index ff16fd886a..f9d613a14e 100644 --- a/rules/regexp/headers.lua +++ b/rules/regexp/headers.lua @@ -993,3 +993,18 @@ reconf['FORGED_X_MAILER'] = { score = 4.0, group = 'headers', } + +-- X-Mailer headers like: 'Internet Mail Service (5.5.2650.21)' are being +-- forged by spammers, but MS Exachange 5.5 is still being used (in 2020) on +-- some mail servers. Example of genuene headers (DC-EXMPL is a hostname which +-- can be a FQDN): +-- Received: by DC-EXMPL with Internet Mail Service (5.5.2656.59) +-- id ; Tue, 8 Dec 2020 07:10:54 -0600 +-- Message-ID: +-- X-Mailer: Internet Mail Service (5.5.2656.59) +reconf['FORGED_IMS'] = { + description = 'Forged X-Mailer: Internet Mail Service', + re = [[X-Mailer=/^Internet Mail Service \(5\./{header} & !Received=/^by \S+ with Internet Mail Service \(5\./{header}]] + score = 3.0, + group = 'headers', +}