[SAtalk] Conflicting scores in SA/MailScanner

Julian Field mailscanner at ecs.soton.ac.uk
Mon Jun 30 10:28:27 IST 2003

At 22:51 29/06/2003, you wrote:
>At 09:53 27/06/03 -0400, Matt Kettler wrote:
>>At 11:27 AM 6/27/03 +1200, Simon Byrnand wrote:
>>>Shouldn't it be possible to simply check for the presence of
>>>spamassassin markup before calling it a second time ??
>>No, because that's easily abused by spammers.. all they have to do is add
>>a spamassassin markup to the header that says "not spam" and they bypass
>>your SA processing entirely.
>So add a site specific header to show the message has been scanned....
>they're unlikely to be able to forge that :)

Never rely on anything in the headers at all. The whole lot are trivial to
