Here is my latest but I still must warn you that this kills a bunch of list servers so we have to add them to the allowed from email white list. Also, I, too, am getting more junk "leaking" through. This is mostly due to "New And Improved" Spam tactics. I am really hoping that the new "fingerprinting" filter that LogSat is working on will improve that situation but I can't think of any way to filter stuff that is actually and external URL (see the posts a few lines up.)
((http|3dhttp)://.{0,26}(((%.+%))|@|:)[(\d|\w)]) ( http://+[\d]{1,3}\.{1}[\d]{1,3}\.{1}[\d]{1,3}\.{1}[\d]{1,3" CLASS="ASPForums" TITLE="WARNING: URL created by poster. - http://+" CLASS="ASPForums" TITLE="WARNING: URL created by poster. - http://+ [\d]{1,3}\.{1}[\d]{1,3}\.{1}[\d]{1,3}\.{1}[\d]{1,3}) ((<[!--]+[\x20]{0,1}[a-zA-Z0-9]{10,}[\x20]{0,1}[!--](.+)){2,}) (<[!--]+[a-zA-Z0-9]{2}(-->)) (( http://http:/" CLASS="ASPForums" TITLE="WARNING: URL created by poster. - http://http:/ \w)|(<(\w){3,10}(\x20/>)|(\* http://w" CLASS="ASPForums" TITLE="WARNING: URL created by poster. - http://w ))) (<(!-- )+[a-zA-Z0-9=]{28,}( -->)) ((content\-type:\x20text/(html|plain)(;{0,1}))((\r\n)|((\r\n)(\t|((\x20){0,15}))charset(.){5,20}\r\n))(content-transfer\-encoding:\x20base64\r\n)) ((limited time (special|offer))) (((arge your p)|(3 - 5 inches\!)|(herbalpillsonline)|(herbaltrials\.com)|(pillsavings)|(gsc\-100))) ((text\-decoration: blink)|(click here to start)) ((your privacy is extremely important to us)|(this is not spam)) ( http://www.(\w){1,20}(4u).(biz|com|net" CLASS="ASPForums" TITLE="WARNING: URL created by poster. - http://www." CLASS="ASPForums" TITLE="WARNING: URL created by poster. - http://www. (\w){1,20}(4u).(biz|com|net))
Dan S