So what is
with all of this amateurish phishing spam that has been sliding right past SpamAssassin like shit through a goose for the past few months? Has someone recently discovered a new technique for finding open relays that will SPF-sign anything?
Received: from mail.vividdreamqb.name (milestone.clevervistakb.com [170.130.167.11])
From: Dicks Rewards Team
Subject: Final notice: YETI Beach Lounge Wagon unlocked by your gear score
Message-ID: X-Request-ID: d36d3311-8a4b-4ac9-91b0-4afeee106923
Feedback-ID: jhkmk:vividdreamqb.name:mail
X-Spam-Report: * 0.0 HTML_MESSAGE BODY: HTML included in message
* 0.4 KHOP_HELO_FCRDNS Relay HELO differs from its IP's reverse DNS
I can't even tell who has been popped here. "clevervistakb.com" and "vividdreamqb.name" have the same IPs but different registrars (maybe that's a TLD thing?) It's also not clear to me which of those domains sender_access matches on.
I have, however, come to the conclusion that that there are simply too many web sites.
Previously, previously, previously, previously, previously, previously, previously, previously, previously, previously.