# don't bother checking attachment bodies. this will greatly speed # up processing of large messages. /^[0-9a-z+\/=]{60,}\s*$/ OK # whitelist false-positive match for cialis /commercialis|provincialis|socialis|Catalys|alias|clear/ OK # whitelist multiple quoting levels /^\s*(?:[>|:_*#-]\s*){3,}/ OK /<\s*iframe\s+src\s*=(3D)?\s*"?cid:.*"?\s+height\s*=(3D)?\s*"?0"?\s+width\s*=(3D)?\s*"?0"?\s*>/ REJECT virus rejected. /<\s*embed\s+src\s*=(3D)?\s*"?cid:.*"?\s+style\s*=(3D)?\s*"?display:none"?\s*>/ REJECT virus rejected. /^(Content-(Disposition: (?:attachment|inline);|Type:).*|\s+)(file)?name\s*=\s*"?.*\.(ad[ep]|asd|ba[st]|c[ho]m|cmd|cpl|crt|dll|exe|hlp|hta|in[fs]|isp|jse?|lnk|md[be]|ms[cipt]|ocx|pcd|pif|reg|sc[rt]|sh[bs]|url|vb[esx]?|vxd|ws[cfh])"?\s*$/ REJECT executable file type rejected, please compress with zip and resend /^begin [0-9]{1,4} .*\.(ad[ep]|asd|ba[st]|c[ho]m|cmd|cpl|crt|dll|exe|hlp|hta|in[fs]|isp|jse?|lnk|md[be]|ms[cipt]|ocx|pcd|pif|reg|sc[rt]|sh[bs]|url|vb[esx]?|vxd|ws[cfh])$/ REJECT executable file type rejected, please compress with zip and resend # corrupt gifs. probably virus. filename always seems to be someword.[0-9].gif /^(Content-(Disposition: (?:attachment|inline);|Type:).*|\s+)(file)?name\s*=\s*"\w*\.[0-9]*\.gif"?\s*$/ REJECT virus rejected #PILLSdoc.uS # toner cartridges /1.888.288.9043|1.888.977.1577|1.888.248.4930/ REJECT # reject multiple html comments on a line /(?:]*>).*){4}/ REJECT # .EXE attachments /^TV[nopqr]....[AB]..A.A/i REJECT Email with EXE files attached denied /^M35[GHIJK].`..`..*````/i REJECT Email with EXE files attached denied # diploma spam /203-286-2187|44-207-681-2635|206-338-6061/ REJECT /U\s*.?N\s*.?I\s*.?V\s*.?E\s*.?R\s*.?S\s*.?I\s*.?T\s*.?Y\s*.?D\s*.?I\s*.?P\s*.?L\s*.?O\s*.?M\s*.?A/ REJECT /d\s*.?i\s*.?p\s*.?l\s*.?o\s*.?m\s*.?a(?:\s*.?s)?\s*.?a\s*.?v\s*.?a\s*.?i\s*.?l\s*.?a\s*.?b\s*.?l\s*.?e/ REJECT /GET YOUR UNIVERSITY DIPLOMA/ REJECT /U N IVERSI T Y|D I PL0 M A/ REJECT /Contact us NOW to receive your diploma/ REJECT /G.?e.?n.?u.?i.?n.?e.? .?C.?o.?l.?l.?e.?g.?e.? .?D.?e.?g.?r.?e.?e|No Study Required/ REJECT /Our University Enroll?ment department has been trying to contact you|you may be eligble for a degree|If you enroll? by the due date then your degree/ REJECT /Bachel0rs|D0ctorate|rec0rds|opp0rtunity|all0wing|c0llege/ REJECT # Business Seminars Australia /60\s+106\s+529\s+604|Business\s+Seminars\s+Australia|P\.?O\.?\s*Box\s+6099,?\s+East\s+Perth|ausremove\@china.com/ REJECT # a common almost-empty spam contains only a html image link /
(?:)?]*border=(?:0|"")>(?:)?<\/a>(?:)?<\/center>/ REJECT # embedded images /\bsrc\s*=(?:3D)?\s*"?cid:/ REJECT /\.(net|com|org|us|biz)\?rid=/ REJECT #/(?:Password\s*is\s*|Note: Use password|use the following password:|Password - |Archive password:|)/ REJECT /\bhref[a-z0-9]+href=/ REJECT /script\s+language\s*=(3D)?\s*"?JScript.Encode"?/ REJECT /You may read more stories about the crash on visiting these websites:/ REJECT /because we are accepting your mort|Our office confirms you can get a|Approval process will take.*1 minute/ REJECT /Advertising (done )?by VD Markett?ing Ltd/ REJECT /R[0o]CKHARD.*[3E]R[3E]CT[il][o0]N/ REJECT /\bD.R.U.G.S\b/ REJECT /Get a capable html e-mailer/ REJECT # Cialis, hydrocodone, levitra, viagra, vicodin, etc /\b(C.?[:yit|1l].?[ãa\@4].?(?:[l1|].?){1,2}[:yitãa\@4|l1].?[s5]|L.?[e3].?V.?[:yit|1l].?T.?R.?[ãa\@4]|V.?[:yit|1l].?[ãa\@4e].?g.?r.?[ãa\@4]|V.?[:yit|1l].?C.?[O0].?D.?[:yit|1l].?N?|\bH.?[:yit|1l].?d.?r.?[o0].?c.?[o0].?d.?[o0].?n.?[e3]|T.?[ãa\@4].?d.?[ãa\@4].?[l1|].?[ãa\@4].?f.?[:yit|1l].?[l1|])/ REJECT # lines consisting only of at least 6 chars separated by spaces, with # any amount of optional leading or trailing white space # e.g. # V A L I U M # V h A f L l l v U j M b /^\s*(?:\S{1,2}\s+){4,}\S{0,2}\s*(?:\$\s*[0-9., ]{4,})?(?:=20|
)?\s*$/ REJECT /^<\s*DIV\s*>\s*[VXCAH]\s*<\s*FONT\s*color\s*=#(?:3d)?\s*"?FFFFFF"?/ REJECT # drug spams /(?:Cost|Price) in your (?:local )?(?:drugstore|medstore)/ REJECT /Herbal.V/ REJECT /cailis|ptabs/ REJECT /Prropecja|Levjttra|Ambbjen|CjALLjS|VALLjUM|VjAGGRA|Vjaagra|Vjjagra/ REJECT /CjALjj\.S|CjALj\.S|Cj\.\.aljs|CjAALj\.S/ REJECT /Sooftt\.abs|Softt\.\.abs|Sofftt\.abs|Sofft T\.abss|Softtt\.abs/ REJECT /^\s*(?:VA|XA|CI|AG|LIU|NA|ALI|RA)\s*$/ REJECT /
\s*(?:VA|XA|CI|AG|LIU|NA|ALI|RA)\s*<\/DIV>/ REJECT /^\s*(?:Som|Xana|CALIS|Proecia|Lvitra|Pxil|mbien|Merida|VIGRA|VAIUM)\s*$/ REJECT /\bp.e.n.i.s\b/ REJECT /Penls|phartmacy|Get your Viag|CIlck here and make sure/ REJECT /ejjaculation|peniis|penniss|monneyy|N-largement/ REJECT /M E D S|online drugs|eXclusive Generics|^Get ready in 15 minutes|go to the site/ REJECT /Increase.*Penis Width|Gain.*\d+\+.*Inches|Stop Premature Ejaculation|Rock Hard Erections/ REJECT /^(?:right|float|"?>\s*.\s*<\/span>\s*.\s*]/ REJECT # more bogus URLs /\/(?:signs|n|vk|mrg)\.asp/ REJECT /\/ph\/\?/ REJECT /^\s*(?: )*\s*\$(?:[0-9.]+)?
$/ REJECT # lots of spam URLs are http://051.spamdom.com/ or http://043. - dunno why. /http:\/\/(?:051|043)\./ REJECT # More misc. /L.?[0@].?[0@].?k.?i.?n.?g.?/ REJECT /Seminario|OBJETIVO|CONTENIDO|CONFERENCISTAS|Autoliquidacion/ REJECT /\b(?:Hey|Fwd?)[:,;]? *(?:cas|postmaster|webmaster|root|toni|claude|indigo)\b/ REJECT /copy.*address.*paste.*(?:w.?e.?b.*)?b.?r.?o.?w.?s.?e.?r:/ REJECT /swissecolife|EcoLife\s*Company|You must have a bank account/ REJECT /DC Brands International,? Inc/ REJECT /Endeavor Societies church addition Christian pledge/ REJECT /Subject: Re: \w{5} news/ REJECT /opt out of this campaign|Hoodia/ REJECT