Some example headers...
A Good Email from a friend, score 3.3 :
CODE
Return-path: <mXXXXX@XXXX.com>
Envelope-to: penn@XXXX.net
Delivery-date: Wed, 10 Nov 2004 12:41:28 +0000
Received: from XXXXX by server25.fastbighost.com with local-bsmtp (Exim 4.42)
id 1CRXXXXXXXWW-AL
for penn@XXXX.net; Wed, 10 Nov 2004 12:41:27 +0000
Received: from [64.XX.XX.XX] (helo=wproxy.XXXXX.com)
by server25.fastbighost.com with esmtp (Exim 4.42)
id 1CRrXXXXXXn-RL
for penn@XXXX.net; Wed, 10 Nov 2004 12:41:24 +0000
Received: by wproxy.XXXX.com with SMTP id 65sXXXXX3wri
for <penn@XXXX.net>; Wed, 10 Nov 2004 04:43:20 -0800 (PST)
Received: by 10.XX.XX.XX with SMTP id c7XXXXX577wra;
Wed, 10 Nov 2004 04:43:19 -0800 (PST)
Received: by 10.XX.XX.XX with HTTP; Wed, 10 Nov 2004 04:43:19 -0800 (PST)
Message-ID: <ed73XXXXXXXXXXXXXba9b9c1@mail.XXXXX.com>
Date: Wed, 10 Nov 2004 07:43:19 -0500
From: MXXXX FXXXX <mXXXXX@XXXX.com>
Reply-To: MXXXX FXXXX <mXXXX@XXXX.com>
To: "penn@XXXX.net" <penn@XXXX.net>
Subject: Re: For Wifi Keychain
In-Reply-To: <000d01XXXXXX890$3301a8c0@XXXXXX>
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
References: <XXXXXX23460@XXXXX.com>
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on
server25.fastbighost.com
X-Spam-Level: ***
X-Spam-Status: No, score=3.3 required=10.0 tests=AWL,RCVD_BY_IP,
TO_ADDRESS_EQ_REAL,URIBL_WS_SURBL autolearn=no version=3.0.1
Random Spam Email, score 86!!!:
CODE
Return-path: <Looneyaitp@euroseek.net>
Envelope-to: penn@XXXX.net
Delivery-date: Tue, 09 Nov 2004 14:12:40 +0000
Received: from XXXX by server25.fastbighost.com with local-bsmtp (Exim 4.42)
id 1CRWjd-00058D-7R
for penn@XXXX.net; Tue, 09 Nov 2004 14:12:39 +0000
Received: from [24.10.9.109] (helo=c-24-10-9-109.client.comcast.net)
by server25.fastbighost.com with smtp (Exim 4.42)
id 1CRWjX-00056a-DL
for penn@XXXX.net; Tue, 09 Nov 2004 14:12:36 +0000
Received: from 238.187.28.134 by 24.10.9.109; Tue, 09 Nov 2004 19:14:01 +0500
Message-ID: <XMWOKQTRLDFKPBMWKBPH@thedoctorspostoffice.com>
From: "Michel Montes" <Looneyaitp@euroseek.net>
Reply-To: "Michel Montes" <Looneyaitp@euroseek.net>
To: penn@XXXX.net
Subject: *****SPAM SCORE: 86.4***** Don't miss this! Live and Work in the USA!
Date: Tue, 09 Nov 2004 19:13:01 +0500
X-Mailer: QUALCOMM Windows Eudora Version 5.1
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="--1-018794432-8521696775=:72682"
X-Priority: 5
X-MSMail-Priority: Low
X-Spam-Prev-Subject: Don't miss this! Live and Work in the USA!
X-Spam-Flag: YES
X-Spam-Checker-Version: SpamAssassin 3.0.1 (2004-10-22) on
server25.fastbighost.com
X-Spam-Level: **************************************************
X-Spam-Status: Yes, score=86.4 required=10.0 tests=FORGED_MUA_EUDORA,
FORGED_QUALCOMM_TAGS,HELO_DYNAMIC_IPADDR,HTML_40_50,
HTML_IMAGE_ONLY_04,HTML_MESSAGE,HTML_MIME_NO_HTML_TAG,
HTML_SHORT_CENTER,LONGWORDS,MANY_EXCLAMATIONS,MIME_HTML_ONLY,
MIME_HTML_ONLY_MULTI,MISSING_MIMEOLE,MPART_ALT_DIFF,MSGID_SPAM_CAPS,
RCVD_BY_IP,RCVD_DOUBLE_IP_SPAM,RCVD_IN_BL_SPAMCOP_NET,RCVD_IN_DSBL,
RCVD_IN_NJABL_DUL,RCVD_IN_SORBS_DUL,RCVD_IN_XBL,URIBL_OB_SURBL,
URIBL_SBL,URIBL_SC_SURBL,URIBL_WS_SURBL autolearn=spam version=3.0.1
X-Spam-Report:
* 2.8 HELO_DYNAMIC_IPADDR Relay HELO'd using suspicious hostname (IP addr 1)
* 3.2 MSGID_SPAM_CAPS Spam tool Message-Id: (caps variant)
* 0.0 RCVD_BY_IP Received by mail server with no name
* 4.0 HTML_40_50 BODY: Message is 40% to 50% HTML
* 0.5 HTML_MESSAGE BODY: HTML included in message
* 1.5 MPART_ALT_DIFF BODY: HTML and text parts are different
* 1.2 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
* 9.0 HTML_IMAGE_ONLY_04 BODY: HTML: images with 0-400 bytes of words
* 10 RCVD_IN_SORBS_DUL RBL: SORBS: sent directly from dynamic IP address
* [24.10.9.109 listed in dnsbl.sorbs.net]
* 10 RCVD_IN_DSBL RBL: Received via a relay in list.dsbl.org
* [<http://dsbl.org/listing?ip=24.10.9.109>]
* 10 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
* [Blocked - see <http://www.spamcop.net/bl.shtml?24.10.9.109>]
* 10 RCVD_IN_XBL RBL: Received via a relay in Spamhaus XBL
* [24.10.9.109 listed in sbl-xbl.spamhaus.org]
* 10 RCVD_IN_NJABL_DUL RBL: NJABL: dialup sender did non-local SMTP
* [24.10.9.109 listed in combined.njabl.org]
* 0.6 URIBL_SBL Contains an URL listed in the SBL blocklist
* [URIs: usa-vista.com]
* 0.5 URIBL_WS_SURBL Contains an URL listed in the WS SURBL blocklist
* [URIs: usa-vista.com]
* 2.0 URIBL_OB_SURBL Contains an URL listed in the OB SURBL blocklist
* [URIs: usa-vista.com]
* 3.9 URIBL_SC_SURBL Contains an URL listed in the SC SURBL blocklist
* [URIs: usa-vista.com]
* 0.4 HTML_SHORT_CENTER HTML is very short with CENTER tag
* 4.1 RCVD_DOUBLE_IP_SPAM Bulk email fingerprint (double IP) found
* 0.1 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag
* 0.2 FORGED_QUALCOMM_TAGS QUALCOMM mailers can't send HTML in this format
* 0.0 MIME_HTML_ONLY_MULTI Multipart message only has text/html MIME parts
* 0.0 MISSING_MIMEOLE Message has X-MSMail-Priority, but no X-MimeOLE
* 2.3 LONGWORDS Long string of long words
* 0.0 MANY_EXCLAMATIONS Subject has many exclamations
* 0.1 FORGED_MUA_EUDORA Forged mail pretending to be from Eudora