Bug 6441 - [review] FORGED_HOTMAIL_RCVD2 triggered by message from Hotmail to Yahoogroup
Summary: [review] FORGED_HOTMAIL_RCVD2 triggered by message from Hotmail to Yahoogroup
Status: RESOLVED WONTFIX
Alias: None
Product: Spamassassin
Classification: Unclassified
Component: Rules (show other bugs)
Version: unspecified
Hardware: PC Linux
: P2 normal
Target Milestone: 3.4.0
Assignee: SpamAssassin Developer Mailing List
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2010-06-01 04:35 UTC by Christophe
Modified: 2013-01-20 17:11 UTC (History)
1 user (show)



Attachment Type Modified Status Actions Submitter/CLA Status

Note You need to log in before you can comment on or make changes to this bug.
Description Christophe 2010-06-01 04:35:31 UTC
Hi,

messages from Hotmail to Yahoo Group seem to trigger FORGED_HOTMAIL_RCVD2.


Received: from wally.hr3.wk3.org (localhost.localdomain [127.0.0.1])
	by wally.hr3.wk3.org (Postfix) with ESMTP id 6BF0916C41D5
	for <****@wk3.org>; Mon, 31 May 2010 23:58:47 +0200 (CEST)
X-Spam-Checker-Version: SpamAssassin 3.2.5 (2008-06-10) on wally.hr3.wk3.org
X-Spam-Level: ***
X-Spam-Status: No, score=3.3 required=7.0 tests=DKIM_SIGNED,DKIM_VERIFIED,
	FORGED_HOTMAIL_RCVD2,HTML_MESSAGE,RCVD_IN_BL_SPAMCOP_NET autolearn=no
	version=3.2.5
Received: from n49a.bullet.mail.sp1.yahoo.com (n49a.bullet.mail.sp1.yahoo.com [66.163.168.143])
	by wally.hr3.wk3.org (Postfix) with SMTP
	for <****@wk3.org>; Mon, 31 May 2010 23:58:47 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoogroups.de; s=kilo; t=1275343125; bh=YxCtowIHnVBnc6tla4jyynuPA9p2UM/cXxhlushULao=; h=Received:Received:X-Yahoo-Newman-Id:X-Sender:X-Apparently-To:X-Received:X-Received:X-Received:X-Received:X-Received:To:Message-ID:User-Agent:X-Mailer:X-Originating-IP:X-Yahoo-Post-IP:From:X-Yahoo-Profile:Sender:MIME-Version:Mailing-List:Delivered-To:List-Id:Precedence:List-Unsubscribe:Date:Subject:X-Yahoo-Newman-Property:Content-Type; b=YrsPK+Ue/zpa4diHzsPcJt/NBuRy6/OsytW8ieraiqb97+L/2qtKSrokX/0chU5yB4DEI4EutTB/L5lO7AwdKEnOOmSR1B22kXUPtvO9QvmRoHHkXleA8evRoDGL8Aaj
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=kilo; d=yahoogroups.de;
	b=u1vB0SRBzjAhCX0PsV5ESNwF3DR5DLbzk7kzEWQCdLmmFZVv7imrX+u32L5UZ2jF0Xw9BvBWEanwZKWusKzeXYzikPD6QBnlH0u9APWBGR9gsgTNKxC+esJmkncIFVda;
Received: from [69.147.65.173] by n49.bullet.mail.sp1.yahoo.com with NNFMP; 31 May 2010 21:58:45 -0000
Received: from [98.137.34.39] by t15.bullet.mail.sp1.yahoo.com with NNFMP; 31 May 2010 21:58:45 -0000
X-Yahoo-Newman-Id: 12454063-m7239
X-Sender: ****@hotmail.com
X-Apparently-To: freecycle-berlin@yahoogroups.de
X-Received: (qmail 32857 invoked from network); 31 May 2010 21:58:42 -0000
X-Received: from unknown (66.196.94.106)
  by m3.grp.sp2.yahoo.com with QMQP; 31 May 2010 21:58:42 -0000
X-Received: from unknown (HELO n45b.bullet.mail.sp1.yahoo.com) (66.163.168.159)
  by mta2.grp.re1.yahoo.com with SMTP; 31 May 2010 21:58:42 -0000
X-Received: from [69.147.65.171] by n45.bullet.mail.sp1.yahoo.com with NNFMP; 31 May 2010 21:58:41 -0000
X-Received: from [98.137.34.36] by t13.bullet.mail.sp1.yahoo.com with NNFMP; 31 May 2010 21:58:41 -0000
To: freecycle-berlin@yahoogroups.de
Message-ID: <hu1beg+ftm9@eGroups.com>
User-Agent: eGroups-EW/0.82
X-Mailer: Yahoo Groups Message Poster
X-Originating-IP: 66.163.168.****
X-Yahoo-Post-IP: 77.186.104.****
From: "****" <****@hotmail.com>
X-Yahoo-Profile: ****
Sender: freecycle-berlin@yahoogroups.de
MIME-Version: 1.0
Mailing-List: list freecycle-berlin@yahoogroups.de; contact freecycle-berlin-owner@yahoogroups.de
Delivered-To: mailing list freecycle-berlin@yahoogroups.de
List-Id: <freecycle-berlin.yahoogroups.de>
Precedence: bulk
List-Unsubscribe: <mailto:freecycle-berlin-unsubscribe@yahoogroups.de>
Date: Mon, 31 May 2010 21:58:40 -0000
Subject: [Freecycle Berlin] ****
X-Yahoo-Newman-Property: groups-email-ff-m
Content-Type: multipart/alternative;
 boundary="2fFtsHDd4jqemAJq1C4QZ5gz04PstZAYBbsuXWz"



dns: 5.2.3.updates.spamassassin.org => 895075, parsed as 895075
channel: current version is 895075, new version is 895075, skipping channel
Comment 1 Kevin A. McGrail 2011-10-29 05:22:27 UTC
The problem is that the mailing list software is removing the received headers from hotmail.

This likely breaks an RFC about modifying emails.

However, a key reason I've never seen this issue is because I implemented a rule based on this discussion some 5 years ago:

 http://lists.roaringpenguin.com/pipermail/mimedefang/2006-September/030885.html

I've written the original author for his permission to publish with SA but here's a current version.

#YAHOO GROUP EMAIL RULE BASED ON WORK FROM Jim McCullars - University of Alabama in Huntsville
header          __KAM_UAH_YAHOOGR_4 X-Mailer =~ /Yahoo Groups Message Poster/
ifplugin Mail::SpamAssassin::Plugin::DKIM
meta            KAM_UAH_YAHOOGROUP_SENDER __DOS_HAS_LIST_UNSUB && __ML2 && __DOS_HAS_MAILING_LIST && __KAM_UAH_YAHOOGR_4 && !FORGED_YAHOO_RCVD && DKIM_SIGNED && DKIM_VALID
else
meta            KAM_UAH_YAHOOGROUP_SENDER __DOS_HAS_LIST_UNSUB && __ML2 && __DOS_HAS_MAILING_LIST && __KAM_UAH_YAHOOGR_4 && !FORGED_YAHOO_RCVD
endif
score           KAM_UAH_YAHOOGROUP_SENDER -20.0
Comment 2 Mark Martinec 2011-10-29 23:14:52 UTC
>  && DKIM_SIGNED && DKIM_VALID

Btw, the '&& DKIM_SIGNED' is redundant.
It cannot be DKIM_VALID if it isn't signed.
Comment 3 Kevin A. McGrail 2013-01-20 17:11:30 UTC
(In reply to comment #2)
> >  && DKIM_SIGNED && DKIM_VALID
> 
> Btw, the '&& DKIM_SIGNED' is redundant.
> It cannot be DKIM_VALID if it isn't signed.

Good call.  Workaround below is likely the best solution.