1|Accepting credit cards|ACCEPT_CREDIT_CARDS|0.399 2|Message would have been caught by accessdb|ACCESSDB|1 3|Talks about 'acting now' with capitals|ACT_NOW_CAPS|0.093 4|From Address contains FREE|ADDR_FREE|1.832 5|Uses an address with lots of numbers at a big ISP |ADDR_NUMS_AT_BIGSITE|0.081 6|To: address appears in Subject|ADDRESS_IN_SUBJECT|1.804 7|Spam is 100% natural?!|ALL_NATURAL|1.061 8|Did not pass through any untrusted hosts|ALL_TRUSTED|-11.387 9|Alta en buscadores hispanos.|ALTA_BUSCADORES_ES|1 10|Possible porn - Amateur Porn|AMATEUR_PORN|1.744 11|Amazing Stuff|AMAZING_STUFF|0.102 12|Includes a link for AOL users to click|AOL_USERS_LINK|0.109 13|As seen on national TV!|AS_SEEN_ON|0.02 14|From: address is in the auto white-list|AWL|1 15|Eliminate Bad Credit|BAD_CREDIT|0 16|Talks about exercise with an exclamation!|BANG_EXERCISE|1.442 17|Something is emphatically guaranteed|BANG_GUAR|0 18|Talks about more with an exclamation!|BANG_MORE|0 19|Talks about Oprah with an exclamation!|BANG_OPRAH|1.975 20|Talks about quotes with an exclamation!|BANG_QUOTE|1.964 21|Avoiding bankruptcy|BANKRUPTCY|0.489 22|Includes a link to a likely spammer domain|BARGAIN_URL|1.833 23|Bayesian spam probability is 0 to 1%|BAYES_00|-2.599 24|Bayesian spam probability is 1 to 5%|BAYES_05|-0.413 25|Bayesian spam probability is 5 to 20%|BAYES_20|-1.951 26|Bayesian spam probability is 20 to 40%|BAYES_40|-1.096 27|Bayesian spam probability is 40 to 60%|BAYES_50|0.001 28|Bayesian spam probability is 60 to 80%|BAYES_60|0.372 29|Bayesian spam probability is 80 to 95%|BAYES_80|2.087 30|Bayesian spam probability is 95 to 99%|BAYES_95|2.063 31|Bayesian spam probability is 99 to 100%|BAYES_99|1.886 32|Be your own boss|BE_BOSS|1.648 33|Have you been turned down?|BEEN_TURNED_DOWN|1.89 34|Possible porn - Best Largest Most Porn |BEST_PORN|0 35|Possible mention of bill 1618 (anti-spam bill)|BILL_1618|1.895 36|Talks about lots of money|BILLION_DOLLARS|0.134 37|Contains an URL in the BIZ top-level domain|BIZ_TLD|2.288 38|Message body has 70-80% blank lines|BLANK_LINES_70_80|1.515 39|Message body has 80-90% blank lines|BLANK_LINES_80_90|0 40|Message body has 90-100% blank lines|BLANK_LINES_90_100|1.996 41|Body includes 8 consecutive 8-bit characters|BODY_8BITS|1.5 42|Information on growing body parts|BODY_ENHANCEMENT|0 43|Information on getting larger body parts|BODY_ENHANCEMENT2|0 44|Buy Direct|BUY_DIRECT|1.663 45|Claims 'cannot be considered spam'|CANNOT_BE_SPAM|1.769 46|Talks about free mobile phones|CELL_PHONE_FREE|0.922 47|Talks about cell-phone signal improvement|CELL_PHONE_IMPROVE|1.031 48|Character set indicates a foreign language|CHARSET_FARAWAY|3.2 49|A foreign language charset used in headers|CHARSET_FARAWAY_HEADER|3.2 50|Involves 'china.com'|CHINA_HEADER|2.386 51|Asks you to click below (in capital letters)|CLICK_BELOW_CAPS|0.112 52|Haga click aqui.|CLICK_ES|1 53|Click to be removed|CLICK_TO_REMOVE_1|0.791 54|Las direcciones fueron obtenidas de internet.|COLECTOR_DE_MAILS_ES|1 55|Compete for your business|COMPETE|2.05 56|No such thing as a free lunch (2)|COMPLETELY_FREE|0.026 57|Confidentiality on all orders|CONFIDENTIAL_ORDER|1.266 58|Congratulations - you've been scammed?|CONGRATULATIONS|0.272 59|Consolidate debt credit or bills |CONSOLIDATE_DEBT|0.245 60|Pago contra reembolso.|CONTRA_REEMBOLSO_ES|1 61|Common pyramid scheme phrase (1)|COPY_ACCURATELY|0 62|Credit Card Offers|CREDIT_CARD|0.31 63|Possible porn - Cum Shot|CUM_SHOT|0 64|Date: is 3 to 6 hours after Received: date|DATE_IN_FUTURE_03_06|0.847 65|Date: is 6 to 12 hours after Received: date|DATE_IN_FUTURE_06_12|1.3 66|Date: is 12 to 24 hours after Received: date|DATE_IN_FUTURE_12_24|3.031 67|Date: is 24 to 48 hours after Received: date|DATE_IN_FUTURE_24_48|2.314 68|Date: is 48 to 96 hours after Received: date|DATE_IN_FUTURE_48_96|2.689 69|Date: is 96 hours or more after Received: date|DATE_IN_FUTURE_96_XX|1.962 70|Date: is 3 to 6 hours before Received: date|DATE_IN_PAST_03_06|0 71|Date: is 6 to 12 hours before Received: date|DATE_IN_PAST_06_12|0 72|Date: is 12 to 24 hours before Received: date|DATE_IN_PAST_12_24|0.703 73|Date: is 24 to 48 hours before Received: date|DATE_IN_PAST_24_48|0.089 74|Date: is 48 to 96 hours before Received: date|DATE_IN_PAST_48_96|0 75|Date: is 96 hours or more before Received: date|DATE_IN_PAST_96_XX|1.36 76|Date header uses unusual Y2K formatting|DATE_SPAMWARE_Y2K|3.911 77|Listed in DCC (http://rhyolite.com/anti-spam/dcc/)|DCC_CHECK|2.169 78|Dear Friend? That's not very dear!|DEAR_FRIEND|0.07 79|Contains 'Dear (something)'|DEAR_SOMETHING|1.578 80|Deep discount medications|DEEP_DISC_MEDS|2.626 81|Para dejar de fumar|DEJAR_DE_FUMAR_ES|1 82|Lose Weight Spam|DIET_1|0 83|Describes weight loss|DIET_2|0.316 84|Describes body fat loss|DIET_3|2.073 85|Attempts to disguise porn words|DISGUISE_PORN|0.03 86|From: sender listed in dnsbl.ahbl.org|DNS_FROM_AHBL_RHSBL|0.295 87|Envelope sender in abuse.rfc-ignorant.org|DNS_FROM_RFC_ABUSE|0 88|Envelope sender in bogusmx.rfc-ignorant.org|DNS_FROM_RFC_BOGUSMX|2.63 89|Envelope sender in dsn.rfc-ignorant.org|DNS_FROM_RFC_DSN|1 90|Envelope sender in postmaster.rfc-ignorant.org|DNS_FROM_RFC_POST|1.614 91|Envelope sender in whois.rfc-ignorant.org|DNS_FROM_RFC_WHOIS|0.296 92|Do it Today|DO_IT_TODAY|0 93|Domain name containing a '4u' variant|DOMAIN_4U2|1.588 94|Message body mentions many internet domains|DOMAIN_RATIO|3.176 95|Talks about price per dose|DRUG_DOSAGE|0.862 96|Mentions an E.D. drug|DRUG_ED_CAPS|0.185 97|Viagra and other drugs|DRUG_ED_COMBO|1.636 98|Mentions Generic Viagra|DRUG_ED_GENERIC|1.128 99|Fast Viagra Delivery|DRUG_ED_ONLINE|2.3 100|Talks about an E.D. drug using its chemical name|DRUG_ED_SILD|1.666 101|Two or more drugs crammed together into one word|DRUGS_SMEAR1|2.351 102|Contains 'earn (dollar) something per week'|EARN_PER_WEEK|1.896 103|Potential Earnings|EARNINGS|1.675 104|Body contains a ROT13-encoded email address|EMAIL_ROT13|3.105 105|Subject contains an English UCE tag|ENGLISH_UCE_SUBJECT|0.11 106|HTML contains needlessly encoded characters|ENTITY_DEC_ALPHANUM|2.716 107|IMPERATIVOS/EXCLAMACIONES EN MAYUSCULAS.|EXCLAMACION_ES|1 108|Gives a lame excuse about why spam was sent|EXCUSE_1|0.132 109|'if you do not wish to receive any more'|EXCUSE_10|0.024 110|Nobody's perfect|EXCUSE_12|0.197 111|Claims you opted-in or registered|EXCUSE_19|0 112|Claims you have provided permission|EXCUSE_23|2.4 113|Claims you wanted this ad|EXCUSE_24|2.08 114|Claims you can be removed from the list|EXCUSE_3|0.116 115|Claims you can be removed from the list|EXCUSE_4|1.119 116|Claims you can be removed from the list|EXCUSE_6|1.696 117|Claims you can be removed from the list|EXCUSE_7|0.018 118|Claims not to be spam in Spanish|EXCUSE_ES_01|1 119|Someone fell free to send you a message in Spanish|EXCUSE_ES_02|1 120|Someone requested an spammer to spam you in Spanish|EXCUSE_ES_03|1 121|El correo como alternativa comercial|EXCUSE_ES_05|1 122|Mensaje enviado por error|EXCUSE_ES_06|1 123|No se puede considerar spam|EXCUSE_ES_07|1 124|Talks about how to be removed from mailings|EXCUSE_REMOVE|0.31 125|Offers Extra Cash|EXTRA_CASH|0.447 126|Header has extraneous Content-type:...type= entry|EXTRA_MPART_TYPE|0 127|Host HELO did not match rDNS: email.com|FAKE_HELO_EMAIL_COM|1.537 128|Host HELO did not match rDNS: eudoramail.com|FAKE_HELO_EUDORAMAIL|0 129|Host HELO did not match rDNS: excite.com|FAKE_HELO_EXCITE|2.074 130|Host HELO did not match rDNS: lycos.com|FAKE_HELO_LYCOS|0.988 131|Host HELO did not match rDNS: mail.com|FAKE_HELO_MAIL_COM|0 132|Relay HELO'd with suspicious hostname (mail.com)|FAKE_HELO_MAIL_COM_DOM|2.108 133|Host HELO did not match rDNS: msn.com|FAKE_HELO_MSN|2.645 134|Host HELO did not match rDNS: yahoo.ca|FAKE_HELO_YAHOO_CA|1.116 135|Received header contains faked 'mr.outblaze.com'|FAKE_OUTBLAZE_RCVD|3.1 136|Faked To 'Undisclosed-Recipients'|FAKED_UNDISC_RECIPS|1.602 137|Freedom of a financial nature|FIN_FREE|0.788 138|Received forged contains fake AOL relays |FORGED_AOL_RCVD|0 139|Forged eudoramail.com 'Received:' header found|FORGED_EUDORAMAIL_RCVD|0.29 140|Forged 'by gw05' 'Received:' header found|FORGED_GW05_RCVD|1.697 141|Forged hotmail.com 'Received:' header found|FORGED_HOTMAIL_RCVD|2.536 142|hotmail.com 'From' address but no 'Received:' |FORGED_HOTMAIL_RCVD2|1.177 143|'From' juno.com does not match 'Received' headers|FORGED_JUNO_RCVD|0.792 144|Received: contains a forged HELO|FORGED_RCVD_HELO|0 145|Contains forged hostname for a DSL IP in Brazil|FORGED_TELESP_RCVD|1.532 146|'From' yahoo.com does not match 'Received' headers|FORGED_YAHOO_RCVD|2.7 147|Stock Disclaimer Statement|FORWARD_LOOKING|2.2 148|Contains 'free access' with capitals|FREE_ACCESS|0 149|Free Membership|FREE_MEMBERSHIP|0.873 150|Possible porn - Free Porn|FREE_PORN|0 151|Free Preview|FREE_PREVIEW|1.851 152|Free express or no-obligation quote|FREE_QUOTE_INSTANT|0.001 153|Contains 'free sample' with capitals|FREE_SAMPLE|0.941 154|From and To are the same but not exactly |FROM_AND_TO_SAME|0 155|From: ends in numbers|FROM_ENDS_IN_NUMS|0 156|From: contains numbers mixed in with letters|FROM_HAS_MIXED_NUMS|0 157|From: contains numbers mixed in with letters|FROM_HAS_MIXED_NUMS3|1.614 158|From contains too many raw illegal characters|FROM_ILLEGAL_CHARS|0.008 159|From address has no lower-case characters|FROM_NO_LOWER|0.377 160|From: has no local-part before @ sign|FROM_NO_USER|0.983 161|Message is from domain that never sends email|FROM_NONSENDING_DOMAIN|0 162|From address is webmail but starts with a number |FROM_NUM_AT_WEBMAIL|1.617 163|From address is 'at something-offers'|FROM_OFFERS|1.491 164|From: starts with nums|FROM_STARTS_WITH_NUMS|0.3 165|From webmail service and address ends in numbers|FROM_WEBMAIL_END_NUMS6|0 166|Frontpage used to create the message|FRONTPAGE|2.08 167|Offers a full refund|FULL_REFUND|1.272 168|Pueden ser ganadores.|GANADORES_ES_01|1 169|Ha sido ganador.|GANADORES_ES_02|1 170|Subject: contains G.a.p.p.y-T.e.x.t|GAPPY_SUBJECT|1.343 171|Get Paid|GET_PAID|0.862 172|NOS CHILLAN PARA DECIR QUE ES GRATIS|GRATIS_ES|1.4 173|Generic Test for Unsolicited Bulk Email|GTUBE|1000 174|One hundred percent guaranteed|GUARANTEED_100_PERCENT|0 175|Guaranteed Stuff|GUARANTEED_STUFF|0 176|Has Habeas warrant mark and on Infringer List|HABEAS_INFRINGER|16 177|Has Habeas warrant mark and on User List|HABEAS_USER|-8 178|Cures Baldness|HAIR_LOSS|1.738 179|Possible porn - Hardcore Porn|HARDCORE_PORN|0.684 180|Contains valid Hashcash token (20 bits)|HASHCASH_20|-0.5 181|Contains valid Hashcash token (21 bits)|HASHCASH_21|-0.7 182|Contains valid Hashcash token (22 bits)|HASHCASH_22|-1 183|Contains valid Hashcash token (23 bits)|HASHCASH_23|-2 184|Contains valid Hashcash token (24 bits)|HASHCASH_24|-3 185|Contains valid Hashcash token (25 bits)|HASHCASH_25|-4 186|Hashcash token already spent in another mail|HASHCASH_2SPEND|0.1 187|Contains valid Hashcash token (>25 bits)|HASHCASH_HIGH|-5 188|Headers are in order found in spam (MTSRIX)|HDR_ORDER_MTSRIX|1.057 189|Headers are in order found in spam (TRIMRS)|HDR_ORDER_TRIMRS|2.199 190|Header contains too many raw illegal characters|HEAD_ILLEGAL_CHARS|2.125 191|Message headers are very long|HEAD_LONG|2.5 192|Multiple Content-Type headers found|HEADER_COUNT_CTYPE|1.771 193|Relay HELO'd using suspicious hostname (Adelphia)|HELO_DYNAMIC_ADELPHIA|2.199 194|Relay HELO'd using suspicious hostname (ATTBI.com)|HELO_DYNAMIC_ATTBI|3.147 195|Relay HELO'd using suspicious hostname (Chello.nl)|HELO_DYNAMIC_CHELLO_NL|0.244 196|Relay HELO'd using suspicious hostname (Chello.no)|HELO_DYNAMIC_CHELLO_NO|1.57 197|Relay HELO'd using suspicious hostname (Comcast)|HELO_DYNAMIC_COMCAST|3.7 198|Relay HELO'd using suspicious hostname (DHCP)|HELO_DYNAMIC_DHCP|1.248 199|Relay HELO'd using suspicious hostname (T-Dialin)|HELO_DYNAMIC_DIALIN|1.755 200|Relay HELO'd using suspicious hostname (HCC)|HELO_DYNAMIC_HCC|3.741 201|Relay HELO'd using suspicious hostname (Hex IP)|HELO_DYNAMIC_HEXIP|1.522 202|Relay HELO'd using suspicious hostname (Home.nl)|HELO_DYNAMIC_HOME_NL|1.878 203|Relay HELO'd using suspicious hostname (IP addr 1)|HELO_DYNAMIC_IPADDR|4.4 204|Relay HELO'd using suspicious hostname (IP addr 2)|HELO_DYNAMIC_IPADDR2|3.496 205|Relay HELO'd using suspicious hostname (NTL)|HELO_DYNAMIC_NTL|1.732 206|Relay HELO'd using suspicious hostname (OptOnline)|HELO_DYNAMIC_OOL|3.182 207|Relay HELO'd using suspicious hostname (Rogers)|HELO_DYNAMIC_ROGERS|2.094 208|Relay HELO'd using suspicious hostname (RR 2)|HELO_DYNAMIC_RR2|2.2 209|Relay HELO'd using suspicious hostname (Split IP)|HELO_DYNAMIC_SPLIT_IP|0.775 210|Relay HELO'd using suspicious hostname (Telia)|HELO_DYNAMIC_TELIA|1.515 211|Relay HELO'd using suspicious hostname (Veloxzone)|HELO_DYNAMIC_VELOX|2.003 212|Relay HELO'd using suspicious hostname (VTR)|HELO_DYNAMIC_VTR|1.96 213|Relay HELO'd using suspicious hostname (YahooBB)|HELO_DYNAMIC_YAHOOBB|3 214|Talks about Hidden Charges|HIDDEN_CHARGES|0 215|Javascript to hide URLs in browser|HIDE_WIN_STATUS|0.063 216|Possible porn - Hot Nasty Wild Young |HOT_NASTY|0.088 217|Message is 0% to 10% HTML|HTML_00_10|1.068 218|Message is 10% to 20% HTML|HTML_10_20|0.246 219|Message is 20% to 30% HTML|HTML_20_30|0.226 220|Message is 30% to 40% HTML|HTML_30_40|0.021 221|Message is 40% to 50% HTML|HTML_40_50|0.035 222|Message is 50% to 60% HTML|HTML_50_60|0.087 223|Message is 60% to 70% HTML|HTML_60_70|0 224|Message is 70% to 80% HTML|HTML_70_80|0 225|Message is 80% to 90% HTML|HTML_80_90|0.146 226|Message is 90% to 100% HTML|HTML_90_100|0.022 227|HTML has many bad attributes in tags|HTML_ATTR_BAD|2.354 228|HTML appears to have random attributes in tags|HTML_ATTR_UNIQUE|0 229|HTML tags used to obfuscate words|HTML_BACKHAIR_2|0 230|HTML tags used to obfuscate words|HTML_BACKHAIR_4|0.058 231|HTML tags used to obfuscate words|HTML_BACKHAIR_8|0.727 232|HTML message is 0% to 10% bad tags|HTML_BADTAG_00_10|0 233|HTML message is 10% to 20% bad tags|HTML_BADTAG_10_20|0 234|HTML message is 20% to 30% bad tags|HTML_BADTAG_20_30|0 235|HTML message is 30% to 40% bad tags|HTML_BADTAG_30_40|0 236|HTML message is 40% to 50% bad tags|HTML_BADTAG_40_50|0.01 237|HTML message is 50% to 60% bad tags|HTML_BADTAG_50_60|0.153 238|HTML message is 60% to 70% bad tags|HTML_BADTAG_60_70|1.356 239|HTML message is 70% to 80% bad tags|HTML_BADTAG_70_80|2.28 240|HTML message is 80% to 90% bad tags|HTML_BADTAG_80_90|1.911 241|HTML message is 90% to 100% bad tags|HTML_BADTAG_90_100|2.804 242|HTML message is a saved web page|HTML_COMMENT_SAVED_URL|0.146 243|HTML comment is very short|HTML_COMMENT_SHORT|0 244|HTML conversion tool used by spam|HTML_CONVERTED|1.605 245|HTML with embedded plugin object|HTML_EMBEDS|0.207 246|HTML contains unsafe auto-executing code|HTML_EVENT_UNSAFE|0.515 247|HTML tag for a big font size|HTML_FONT_BIG|0.142 248|HTML font face is not a word|HTML_FONT_FACE_BAD|0.037 249|HTML font face has excess capital characters|HTML_FONT_FACE_CAPS|0.247 250|HTML font color is same as background|HTML_FONT_INVISIBLE|0.036 251|HTML font color similar to background|HTML_FONT_LOW_CONTRAST|0.788 252|HTML font size is huge|HTML_FONT_SIZE_HUGE|2.594 253|HTML font size is large|HTML_FONT_SIZE_LARGE|0.153 254|HTML font size is negative|HTML_FONT_SIZE_NONE|0.033 255|HTML font size is tiny|HTML_FONT_SIZE_TINY|0.533 256|HTML tag for a tiny font size|HTML_FONT_TINY|0.964 257|HTML includes a form which sends mail|HTML_FORMACTION_MAILTO|2.353 258|HTML: images with 0-400 bytes of words|HTML_IMAGE_ONLY_04|3.304 259|HTML: images with 400-800 bytes of words|HTML_IMAGE_ONLY_08|3.036 260|HTML: images with 800-1200 bytes of words|HTML_IMAGE_ONLY_12|2.942 261|HTML: images with 1200-1600 bytes of words|HTML_IMAGE_ONLY_16|1.047 262|HTML: images with 1600-2000 bytes of words|HTML_IMAGE_ONLY_20|0.446 263|HTML: images with 2000-2400 bytes of words|HTML_IMAGE_ONLY_24|0.502 264|HTML has a low ratio of text to image area|HTML_IMAGE_RATIO_02|0.018 265|HTML has a low ratio of text to image area|HTML_IMAGE_RATIO_04|0.105 266|HTML has a low ratio of text to image area|HTML_IMAGE_RATIO_06|0.131 267|HTML has a low ratio of text to image area|HTML_IMAGE_RATIO_08|0.032 268|HTML link text says 'push here' or similar|HTML_LINK_PUSH_HERE|0.873 269|HTML included in message|HTML_MESSAGE|0.001 270|0% to 10% of HTML elements are non-standard|HTML_NONELEMENT_00_10|0.001 271|10% to 20% of HTML elements are non-standard|HTML_NONELEMENT_10_20|0 272|20% to 30% of HTML elements are non-standard|HTML_NONELEMENT_20_30|0 273|30% to 40% of HTML elements are non-standard|HTML_NONELEMENT_30_40|0 274|40% to 50% of HTML elements are non-standard|HTML_NONELEMENT_40_50|0 275|50% to 60% of HTML elements are non-standard|HTML_NONELEMENT_50_60|1 276|60% to 70% of HTML elements are non-standard|HTML_NONELEMENT_60_70|0.001 277|70% to 80% of HTML elements are non-standard|HTML_NONELEMENT_70_80|0 278|80% to 90% of HTML elements are non-standard|HTML_NONELEMENT_80_90|0 279|90% to 100% of HTML elements are non-standard|HTML_NONELEMENT_90_100|2.963 280|Message is 5% to 10% HTML obfuscation|HTML_OBFUSCATE_05_10|0.257 281|Message is 10% to 20% HTML obfuscation|HTML_OBFUSCATE_10_20|0.865 282|Message is 20% to 30% HTML obfuscation|HTML_OBFUSCATE_20_30|0 283|Message is 30% to 40% HTML obfuscation|HTML_OBFUSCATE_30_40|3.445 284|Message is 40% to 50% HTML obfuscation|HTML_OBFUSCATE_40_50|3.089 285|Message is 50% to 60% HTML obfuscation|HTML_OBFUSCATE_50_60|3.325 286|Message is 60% to 70% HTML obfuscation|HTML_OBFUSCATE_60_70|2.805 287|Message is 70% to 80% HTML obfuscation|HTML_OBFUSCATE_70_80|2.689 288|Message is 80% to 90% HTML obfuscation|HTML_OBFUSCATE_80_90|1.939 289|Message is 90% to 100% HTML obfuscation|HTML_OBFUSCATE_90_100|1.775 290|HTML is extremely short|HTML_SHORT_LENGTH|0.389 291|HTML has very strong 'shouting' markup|HTML_SHOUTING3|0.019 292|HTML has very strong 'shouting' markup|HTML_SHOUTING4|0 293|HTML has very strong 'shouting' markup|HTML_SHOUTING5|0.019 294|HTML has very strong 'shouting' markup|HTML_SHOUTING6|0 295|HTML has very strong 'shouting' markup|HTML_SHOUTING7|0.646 296|HTML has unbalanced 'body' tags|HTML_TAG_BALANCE_BODY|0 297|HTML has unbalanced 'head' tags|HTML_TAG_BALANCE_HEAD|0 298|HTML has 'marquee' tag|HTML_TAG_EXIST_MARQUEE|2.034 299|HTML has 'tbody' tag|HTML_TAG_EXIST_TBODY|0.114 300|HTML contains text after BODY close tag|HTML_TEXT_AFTER_BODY|0.061 301|HTML contains text after HTML close tag|HTML_TEXT_AFTER_HTML|0.031 302|HTML title contains no text|HTML_TITLE_EMPTY|0.004 303|HTML title contains 'Untitled'|HTML_TITLE_UNTITLED|0 304|Image tag intended to identify you|HTML_WEB_BUGS|0.035 305|Contains an URL-encoded hostname (HTTP77)|HTTP_77|1.981 306|Uses control sequences inside a URL hostname|HTTP_CTRL_CHARS_HOST|1.9 307|Uses %-escapes inside a URL's hostname|HTTP_ESCAPED_HOST|0.477 308|Completely unnecessary %-escapes inside a URL|HTTP_EXCESSIVE_ESCAPES|0.151 309|Impotence cure|IMPOTENCE|0.094 310|Contains an URL in the INFO top-level domain|INFO_TLD|0 311|Informacion y reserva|INFORMACION_RESERVA_ES|1 312|Requires Initial Investment|INITIAL_INVEST|1.23 313|Nos animan a contestar si estamos interesados|INTERESADO_ES|1 314|Invalid Date: header (not RFC 2822)|INVALID_DATE|0.236 315|Invalid Date: header (timezone does not exist)|INVALID_DATE_TZ_ABSURD|0.96 316|Invalid date in header (wrong CST timezone)|INVALID_TZ_CST|2.873 317|Invalid date in header (wrong EST timezone)|INVALID_TZ_EST|3.582 318|Invalid date in header (wrong GMT/UTC timezone)|INVALID_TZ_GMT|0.198 319|Invaluable marketing information|INVALUABLE_MARKETING|0 320|Dotted-decimal IP address followed by CGI|IP_LINK_PLUS|0.232 321|Claims to be Legal|ITS_LEGAL|0.264 322|Subject contains a Japanese UCE tag|JAPANESE_UCE_SUBJECT|1.8 323|Contains 'My wife Jody' testimonial|JODY|0 324|Join Millions of Americans|JOIN_MILLIONS|0.448 325|Subject: contains Korean unsolicited email tag|KOREAN_UCE_SUBJECT|3.081 326|No existe legislaci?n en Chile contra el SPAM|LEY_CHILE_ES_01|1 327|Clama cumplir con la legislaci?n chilena|LEY_CHILE_ES_02|1 328|Dice cumplir con la ley|LEY_ORGANICA_ES|2 329|Possible porn - Live Porn|LIVE_PORN|0 330|Thousands or millions of pictures movies etc. |LOTS_OF_STUFF|0 331|Lowest Price|LOW_PRICE|0 332|Contains mail-in order form|MAIL_IN_ORDER_FORM|0 333|mailto URI includes removal text|MAILTO_SUBJ_REMOVE|0.542 334|Includes a 'remove' email address|MAILTO_TO_REMOVE|0.116 335|Includes a link to a likely spammer email|MAILTO_TO_SPAM_ADDR|0 336|Claims you registered with a partner|MARKETING_PARTNERS|1.401 337|Mas informacion.|MAS_INFORMACION_ES|1 338|Meet Singles|MEET_SINGLES|1.172 339|SEC-mandated penny-stock warning|MICRO_CAP_WARNING|1.828 340|Get a million email addresses|MILLION_EMAIL|0 341|Talks about millions of dollars|MILLION_USD|2.796 342|Extra blank lines in base64 encoding|MIME_BASE64_BLANKS|1.469 343|base64 attachment does not have a file name|MIME_BASE64_NO_NAME|0 344|Message text disguised using base64 encoding|MIME_BASE64_TEXT|0.298 345|Spam tool pattern in MIME boundary|MIME_BOUND_DD_DIGITS|4.139 346|Spam tool pattern in MIME boundary|MIME_BOUND_DIGITS_15|3.4 347|Spam tool pattern in MIME boundary|MIME_BOUND_DIGITS_7|0.893 348|Spam tool pattern in MIME boundary|MIME_BOUND_MANY_HEX|2.7 349|Spam tool pattern in MIME boundary (rfkindy)|MIME_BOUND_RKFINDY|2.671 350|Multipart message mostly text/html MIME|MIME_HTML_MOSTLY|1.023 351|Message only has text/html MIME parts|MIME_HTML_ONLY|0.177 352|MIME section missing boundary|MIME_MISSING_BOUNDARY|0 353|Quoted-printable line longer than 76 chars|MIME_QP_LONG_LINE|0.039 354|MIME filename does not match content|MIME_SUSPECT_NAME|0.1 355|Missing Date: header|MISSING_DATE|0 356|Missing To: header|MISSING_HEADERS|0.119 357|Multi Level Marketing mentioned|ML_MARKETING|0 358|Money back guarantee|MONEY_BACK|0.095 359|Talks about a bigger drive for sex|MORE_SEX|2.422 360|Information on mortgages|MORTGAGE_BEST|0.144 361|Looks like mortgage pitch|MORTGAGE_PITCH|0 362|Information on mortgage rates|MORTGAGE_RATES|0.202 363|HTML and text parts are different|MPART_ALT_DIFF|0.066 364|Message-Id was added by a hotmail.com relay|MSGID_FROM_MTA_HOTMAIL|2.144 365|Message-Id for external message added locally|MSGID_FROM_MTA_ID|1.723 366|Message-Id has no hostname|MSGID_NO_HOST|0.14 367|Message-Id is fake (in Outlook Express format)|MSGID_OUTLOOK_INVALID|2.7 368|Spam tool Message-Id: (99x9xx99 variant)|MSGID_SPAM_99X9XX99|1.442 369|Spam tool Message-Id: (alpha-numeric variant)|MSGID_SPAM_ALPHA_NUM|3.228 370|Spam tool Message-Id: (caps variant)|MSGID_SPAM_CAPS|3.791 371|Spam tool Message-Id: (letters variant)|MSGID_SPAM_LETTERS|2.709 372|Spam tool Message-Id: (12-zeroes variant)|MSGID_SPAM_ZEROES|1.859 373|Message-ID has ALLCAPS@yahoo.com|MSGID_YAHOO_CAPS|3.8 374|List removal information|MULTI_REMOVAL_1WORD|0.802 375|Talks about a million North American dollars|NA_DOLLARS|2.611 376|Possible porn - Nasty Girls|NASTY_GIRLS|2.196 377|Subject is indicative of a Nigerian spam|NIGERIAN_SUBJECT1|0 378|Subject is indicative of a Nigerian spam|NIGERIAN_SUBJECT2|2.09 379|There is no catch|NO_CATCH|0 380|No such thing as a free lunch (3)|NO_COST|0 381|Without a credit check|NO_CREDIT_CHECK|0.037 382|You won't be 'disappointed'|NO_DISAPPOINTMENT|0.41 383|Envelope sender has no MX or A DNS records|NO_DNS_FOR_FROM|1.6 384|No Claim Forms|NO_FORMS|0.011 385|No nos env?an m?s spam... seguro que no.|NO_MAS_MAIL_1_ES|1 386|No recibir? este spam otra vez... seguro que no.|NO_MAS_MAIL_2_ES|1 387|No Medical Exams|NO_MEDICAL|0 388|There is no obligation|NO_OBLIGATION|0.83 389|No Purchase Necessary|NO_PURCHASE|0 390|Doesn't ask any questions|NO_QS_ASKED|0 391|Host HELO'd as a big ISP but had no rDNS |NO_RDNS_DOTCOM_HELO|0.016 392|From: does not include a real name|NO_REAL_NAME|0.007 393|Character set doesn't exist|NONEXISTENT_CHARSET|1.418 394|Non-secured Credit/Debt|NONSECURED_CREDIT|0 395|Uses a dotted-decimal IP address in URL|NORMAL_HTTP_TO_IP|0.028 396|Clama cumplir con la normativa SPAM|NORMATIVA_SPAM_ES|2 397|Not registered investment advisor|NOT_ADVISOR|2.7 398|Uses a numeric IP address in URL|NUMERIC_HTTP_ADDR|2.135 399|Message seems to contain rot13ed address|OBSCURED_EMAIL|3.132 400|Off Shore Scams|OFFSHORE_SCAM|0.144 401|One Time Rip Off|ONE_TIME|0.619 402|Online Pharmacy|ONLINE_PHARMACY|0 403|Talks about opting out (lowercase version)|OPTING_OUT|0.479 404|Talks about opting out (capitalized version)|OPTING_OUT_CAPS|0 405|Order a report from someone|ORDER_REPORT|0 406|Mentions their affiliate partners|OUR_AFFILIATE_PARTNERS|1.443 407|Possible porn - Pay Site|PAY_SITE|1.9 408|Para hacer su pedido.|PEDIDO_ES|1 409|Subject has exclamation mark and question mark|PLING_QUERY|0.368 410|Possible porn - various types of feline|PORN_15|2.168 411|Possible porn - nasty dirty little etc. |PORN_16|0.017 412|Possible porn - Celebrity Porn|PORN_CELEBRITY|0.038 413|URL uses words/phrases which indicate porn (misc)|PORN_URL_MISC|1.62 414|URL uses words/phrases which indicate porn (sex)|PORN_URL_SEX|0.011 415|URL uses words/phrases which indicate porn (slut)|PORN_URL_SLUT|0.094 416|Porno gratis.|PORNO_GRATIS_ES|1 417|Presentaci?n de un nuevo producto.|PRESENTAMOS_ES|1 418|'Prestigious Non-Accredited Universities'|PREST_NON_ACCREDITED|1.901 419|Promocion especial.|PROMOCION_ES|1 420|Listed in Pyzor (http://pyzor.sf.net/)|PYZOR_CHECK|3.451 421|Bulk email fingerprint (eGroups) found|RATWARE_EGROUPS|2.805 422|Bulk email fingerprint (Gecko faked) found|RATWARE_GECKO_BUILD|1.385 423|Bulk email fingerprint (hash 2) found|RATWARE_HASH_2|0.037 424|Bulk email fingerprint (hash 2 v2) found|RATWARE_HASH_2_V2|0.98 425|Contains a hashbuster in Send-Safe format|RATWARE_HASH_DASH|1.646 426|Bulk email fingerprint (jpfree) found|RATWARE_JPFREE|2.1 427|Bulk email fingerprint (Mozilla malformed) found|RATWARE_MOZ_MALFORMED|0.558 428|Bulk email fingerprint (netIP) found|RATWARE_NETIP|2.286 429|X-Mailer has malformed Outlook Express version|RATWARE_OE_MALFORMED|2.588 430|Bulk email fingerprint (Received @) found|RATWARE_RCVD_AT|3.415 431|Bulk email fingerprint ('esmtp' Received) found|RATWARE_RCVD_LC_ESMTP|2.083 432|Bulk email fingerprint (Received PF) found|RATWARE_RCVD_PF|3.867 433|Bulk email fingerprint (StormPost) found|RATWARE_STORM_URI|2.295 434|Razor2 gives confidence level above 50%|RAZOR2_CF_RANGE_51_100|0.056 435|Listed in Razor2 (http://razor.sf.net/)|RAZOR2_CHECK|1.511 436|Received headers forged (AM/PM)|RCVD_AM_PM|1.927 437|Bulk email fingerprint (bonus space) found|RCVD_BONUS_SPC_DATE|1.872 438|Received by mail server with no name|RCVD_BY_IP|0.067 439|Received contains a faked HELO hostname|RCVD_FAKE_HELO_DOTCOM|0.424 440|Received: HELO and IP do not match but should |RCVD_HELO_IP_MISMATCH|2.178 441|Received: contains illegal IP address|RCVD_ILLEGAL_IP|0.944 442|Received via a relay in bl.spamcop.net|RCVD_IN_BL_SPAMCOP_NET|1.216 443|Sender is in Bonded Sender Program (other relay)|RCVD_IN_BSP_OTHER|-0.1 444|Sender is in Bonded Sender Program (trusted relay)|RCVD_IN_BSP_TRUSTED|-4.3 445|Received via a relay in list.dsbl.org|RCVD_IN_DSBL|3.805 446|Relay in DUL http://www.mail-abuse.org/dul/ |RCVD_IN_MAPS_DUL|1 447|Relay in NML http://www.mail-abuse.org/nml/ |RCVD_IN_MAPS_NML|1 448|Relay in RBL http://www.mail-abuse.org/rbl/ |RCVD_IN_MAPS_RBL|1 449|Relay in RSS http://www.mail-abuse.org/rss/ |RCVD_IN_MAPS_RSS|1 450|NJABL: sender is an open formmail|RCVD_IN_NJABL_CGI|1 451|NJABL: dialup sender did non-local SMTP|RCVD_IN_NJABL_DUL|0.088 452|NJABL: sent through multi-stage open relay|RCVD_IN_NJABL_MULTI|1 453|NJABL: sender is an open proxy|RCVD_IN_NJABL_PROXY|0.438 454|NJABL: sender is confirmed open relay|RCVD_IN_NJABL_RELAY|1.397 455|NJABL: sender is confirmed spam source|RCVD_IN_NJABL_SPAM|1.841 456|Sent via a relay in ipwhois.rfc-ignorant.org|RCVD_IN_RFC_IPWHOIS|1.664 457|Received via a relay in RSL|RCVD_IN_RSL|1.72 458|Received via a relay in Spamhaus SBL|RCVD_IN_SBL|0.107 459|SORBS: sender demands to never be tested|RCVD_IN_SORBS_BLOCK|1 460|SORBS: sent directly from dynamic IP address|RCVD_IN_SORBS_DUL|1.987 461|SORBS: sender is open HTTP proxy server|RCVD_IN_SORBS_HTTP|0.043 462|SORBS: sender is open proxy server|RCVD_IN_SORBS_MISC|0.338 463|SORBS: sender is open SMTP relay|RCVD_IN_SORBS_SMTP|2.493 464|SORBS: sender is open SOCKS proxy server|RCVD_IN_SORBS_SOCKS|2.054 465|SORBS: sender is a abuseable web server|RCVD_IN_SORBS_WEB|0.007 466|SORBS: sender is on a hijacked network|RCVD_IN_SORBS_ZOMBIE|0 467|Received via a relay in Spamhaus XBL|RCVD_IN_XBL|3.076 468|Received: contains an IP address used for HELO|RCVD_NUMERIC_HELO|1.248 469|Receive a special offer|RECEIVE_OFFER|0.793 470|Conviertete en Spammer.|REENVIA_ES|1 471|Home refinancing|REFINANCE_NOW|0.029 472|Home refinancing|REFINANCE_YOUR_HOME|0.34 473|Los regalos no existen salvo de nuestros amigos. |REGALO_ES|1 474|Claims you can be removed in Spanish|REMOVE_ES_01|1 475|Claims you can be removed in Spanish|REMOVE_ES_02|1 476|Claims you can be removed in Spanish|REMOVE_ES_03|1 477|Claims you can be removed in Spanish|REMOVE_ES_04|1 478|If you send an email you will be OptOut|REMOVE_ES_05|1 479|Claims you can opt-out|REMOVE_ES_06|1 480|Claims you can opt-out|REMOVE_ES_07|1 481|Claims you can opt-out|REMOVE_ES_08|1 482|URL of page called 'remove'|REMOVE_PAGE|0.191 483|Send real mail to be unsubscribed|REMOVE_POSTAL|1.9 484|Reply-To: is empty|REPLY_TO_EMPTY|1.643 485|Resistance to this spam is futile|RESISTANCE_IS_FUTILE|0 486|Reverses Aging|REVERSE_AGING|2.15 487|If only it were that easy|RICH|0 488|Risk free. Suuurreeee....|RISK_FREE|0.23 489|Received: says mail sent around the world (DNS)|ROUND_THE_WORLD|1.958 490|Received: says mail sent around the world (HELO)|ROUND_THE_WORLD_LOCAL|0.213 491|Mail guarantees satisfaction|SATIS_GUAR|0.081 492|Save big money|SAVE_THOUSANDS|0.031 493|Sender domain is new and very high volume|SB_NEW_BULK|1 494|Sender IP hosted at NSP has a volume spike|SB_NSP_VOLUME_SPIKE|1 495|Score with babes!|SEDUCTION|1.054 496|See for yourself|SEE_FOR_YOURSELF|0.044 497|They have selected you for something|SELECTED_YOU|1.897 498|Claims compliance with spam regulations|SENT_IN_COMPLIANCE|2 499|Serious Enquiries Only|SERIOUS_ONLY|1.748 500|Describes some sort of breakthrough|SOME_BREAKTHROUGH|1.61 501|Possible porn - Adult Web Sites|SOMETHING_FOR_ADULTS|0.006 502|Recipient list is sorted by address|SORTED_RECIPS|0.887 503|SPF: sender does not match SPF record (fail)|SPF_FAIL|0.875 504|SPF: HELO does not match SPF record (fail)|SPF_HELO_FAIL|0.001 505|SPF: HELO matches SPF record|SPF_HELO_PASS|-0.001 506|SPF: HELO does not match SPF record (softfail)|SPF_HELO_SOFTFAIL|3.14 507|SPF: sender matches SPF record|SPF_PASS|-0.001 508|SPF: sender does not match SPF record (softfail)|SPF_SOFTFAIL|0.5 509|Talks about 'starting now' with capitals|START_NOW_CAPS|0.857 510|Offers a alert about a stock|STOCK_ALERT|2.385 511|Offers a picked stock|STOCK_PICK|1.47 512|Tells you about a strong buy|STRONG_BUY|3.117 513|Subject starts with 'Free'|SUB_FREE_OFFER|0 514|Subject starts with 'Hello'|SUB_HELLO|0.007 515|Contains 'subject to credit approval'|SUBJ_2_CREDIT|0.076 516|Subject contains common spam sign (2 numbers)|SUBJ_2_NUM_PARENS|2.102 517|Subject is all capitals|SUBJ_ALL_CAPS|0.665 518|Subject contains 'As Seen'|SUBJ_AS_SEEN|0 519|Subject line starts with Buy or Buying|SUBJ_BUY|0 520|Subject starts with dollar amount|SUBJ_DOLLARS|0.054 521|Subject contains 'For Only'|SUBJ_FOR_ONLY|0.044 522|Subject contains 'FREE' in CAPS|SUBJ_FREE_CAP|0 523|Subject GUARANTEED|SUBJ_GUARANTEED|0.452 524|Subject contains lots of white space|SUBJ_HAS_SPACES|1.175 525|Subject contains a unique ID|SUBJ_HAS_UNIQ_ID|1.339 526|Subject contains too many raw illegal characters|SUBJ_ILLEGAL_CHARS|2.854 527|Subject includes 'life insurance'|SUBJ_LIFE_INSURANCE|2.02 528|Subject contains 'Your Bills' or similar|SUBJ_YOUR_DEBT|1.261 529|Subject contains 'Your Family'|SUBJ_YOUR_FAMILY|0.011 530|Subject contains 'Your Own'|SUBJ_YOUR_OWN|0 531|Subject talks about losing pounds|SUBJECT_DIET|0.266 532|Subject contains a gappy version of 'cialis'|SUBJECT_DRUG_GAP_C|1.325 533|Subject contains a gappy version of 'levitra'|SUBJECT_DRUG_GAP_L|2.456 534|Subject contains a gappy version of 'phentermine'|SUBJECT_DRUG_GAP_P|1.425 535|Subject contains a gappy version of 'soma'|SUBJECT_DRUG_GAP_S|2.041 536|Subject contains a gappy version of 'valium'|SUBJECT_DRUG_GAP_VA|3.68 537|Subject contains a gappy version of 'viagra'|SUBJECT_DRUG_GAP_VIA|0.253 538|Subject contains a gappy version of 'vicodin'|SUBJECT_DRUG_GAP_VIC|2.868 539|Subject contains a gappy version of 'xanax'|SUBJECT_DRUG_GAP_X|2.512 540|Subject indicates sexually-explicit content|SUBJECT_SEXUAL|2.9 541|If you want to subscribe...|SUBSCRIBE_ES_01|1 542|Similar addresses in recipient list|SUSPICIOUS_RECIPS|1.915 543|Targeted Traffic / Email Addresses|TARGETED|0.48 544|Inmigraci?n legal (?) a los Estados Unidos|TARJETA_VERDE_ES|1 545|Contains URI to a document hosted at 'terra.es'|TERRA_ES|2.612 546|The best Rates|THE_BEST_RATE|0 547|To: repeats address as real name|TO_ADDRESS_EQ_REAL|0.026 548|To: is empty|TO_EMPTY|0.097 549|To: has a malformed address|TO_MALFORMED|2.187 550|To: has no local-part before @ sign|TO_NO_USER|0.128 551|To header contains 'recipient' marker|TO_RECIP_MARKER|1.539 552|Sent to a text file|TO_TXT|1.58 553|Incorporates a tracking ID number|TRACKER_ID|0.555 554|People just leave money laying around|UNCLAIMED_MONEY|1.584 555|Valid-looking To 'undisclosed-recipients'|UNDISC_RECIPS|1.302 556|Message body has many words used only once|UNIQUE_WORDS|2.273 557|University Diplomas|UNIVERSITY_DIPLOMAS|0 558|Headers contain an unresolved template|UNRESOLVED_TEMPLATE|2.866 559|Message written in an undesired language|UNWANTED_LANGUAGE_BODY|2.8 560|Contains urgent matter|URG_BIZ|1.808 561|Message has URI 4you|URI_4YOU|1.966 562|Contains a URI with an affiliate ID code|URI_AFFILIATE|2.052 563|Filename is just a '\#'; probably a JS trick|URI_IS_POUND|0 564|Message has link to company offers|URI_OFFERS|0.77 565|Message has HTTP redirector URI|URI_REDIRECTOR|0.011 566|Contains an URL listed in the AB SURBL blocklist|URIBL_AB_SURBL|0.417 567|Contains an URL listed in the OB SURBL blocklist|URIBL_OB_SURBL|3.213 568|Contains an URL listed in the PH SURBL blocklist|URIBL_PH_SURBL|2 569|Contains an URL listed in the SBL blocklist|URIBL_SBL|0.996 570|Contains an URL listed in the SC SURBL blocklist|URIBL_SC_SURBL|4.263 571|Contains an URL listed in the WS SURBL blocklist|URIBL_WS_SURBL|1.462 572|Mentions millions of (dollar) ((dollar) NN|NNN|NNN.NN) |US_DOLLARS_3|0.354 573|User is listed in 'all_spam_to'|USER_IN_ALL_SPAM_TO|-100 574|From: address is in the user's black-list|USER_IN_BLACKLIST|100 575|User is listed in 'blacklist_to'|USER_IN_BLACKLIST_TO|10 576|From: address is in the default white-list|USER_IN_DEF_WHITELIST|-15 577|User is listed in 'more_spam_to'|USER_IN_MORE_SPAM_TO|-20 578|From: address is in the user's white-list|USER_IN_WHITELIST|-100 579|User is listed in 'whitelist_to'|USER_IN_WHITELIST_TO|-6 580|URL contains username and (optional) password|USERPASS|0.268 581|Attempts to disguise the word 'viagra'|VIA_GAP_GRA|3.005 582|Claims to honor removal requests|WE_HONOR_ALL|2.029 583|Uses non-standard port number for HTTP|WEIRD_PORT|0.109 584|Weird repeated double-quotation marks|WEIRD_QUOTING|2 585|While you Sleep|WHILE_YOU_SLEEP|0 586|Why Pay More?|WHY_PAY_MORE|1.978 587|What are you waiting for|WHY_WAIT|0.764 588|Received line contains spam-sign (lowercase smtp)|WITH_LC_SMTP|2.2 589|Information on how to work at home (1)|WORK_AT_HOME|0.03 590|Removes Wrinkles|WRINKLES|2.091 591|X-Authentication-Warning header looks faked|X_AUTH_WARN_FAKED|3.105 592|Message has X-Library header|X_LIBRARY|2.755 593|Bulk email fingerprint (X-Message-Info) found|X_MESSAGE_INFO|4.244 594|Sent with 'X-Msmail-Priority' set to high|X_MSMAIL_PRIORITY_HIGH|0 595|X-Originating-IP doesn't look like IPv4 address|X_ORIG_IP_NOT_IPV4|2.582 596|Sent with 'X-Priority' set to high|X_PRIORITY_HIGH|0 597|Has Yahoo Redirect URI|YAHOO_DRS_REDIR|0.984 598|Has Yahoo Redirect URI|YAHOO_RD_REDIR|1.642 599|You can search for anyone|YOU_CAN_SEARCH|1.63 600|Who really wins?|YOU_WON|0.579 601|Doing something with my income|YOUR_INCOME|1.092