I've not made the upgrade yet. I'm on 2.64 (I'd not run 2.63 or older on a
production box. It has a malformed message DoS vulnerability).

However, I've been closely following the threads on this subject here, and
on sa-talk, and I've been studying the SA 3.0 rules, mass-checks, scores,
and code a bit.

Really, you hear a lot of people claiming that SA 3.0 catches more, and a
lot of people claiming it catches less.

The general summary I can conclude from talking to lots of happy and
unhappy upgraders is:

1) anyone upgrading from stock SA 2.6x sees an improvement.

2) Anyone who already has surbl, antidrug, and all the other add-ons that
are now built into SA 3.0 see much less improvement. The mass-check tested
scores are much less aggressive than those assigned by many rule-writers,
some of whom still don't quite understand some of the detailed subtleties
of how SA scoring works (I'm talking scoreset balance issues, overlapping
rules with paired-firing, the real impacts of 'FPs are 100 times worse than
FNs" concept in the score assignment, etc)

3) anyone with a NATed mailserver, or other mailserver configuration where
your externally accessible MX appears to be a reserved IP, must set
trusted_networks manually. Otherwise major FN problems ensue from
ALL_TRUSTED misfiring. The trusted_networks problem is not new to 3.0, it's
been around since 2.50, but it's impact is much more severe in 3.0 than
earlier versions. (in 2.6x and 2.5x it mostly caused dialup rbls to

