NAME
Mail::SpamAssassin::Handler::ICS - A MIME-part handler for text/calendar parts
SYNOPSIS
loadhandler Mail::SpamAssassin::Handler::ICS
icstext RULE_NAME /pattern/modifiers
body ICS_MANY_ATTENDEES eval:check_ics_attendee_count('50')
body ICS_RANDOM_DTSTART eval:check_ics_random_start_time()
DESCRIPTION
This handler parses each iCalendar part and renders the text of every event's SUMMARY and DESCRIPTION into the message body, so ordinary body rules can match it. The same text can additionally be matched with the new icstext rule type, which sees the invite text on its own -- so a word can be scored differently inside an invite than in the surrounding body. Links found in the URL, ATTACH and LOCATION properties are added to the URI detail list (type ics). It also counts ATTENDEE properties and flags events whose DTSTART has a non-zero seconds component (a fingerprint of machine-generated / bulk invites, since human and most-client invites round to :00) -- see "EVAL RULES".
RETURNS
This handler returns one text/html sub-part for each HTML-typed property found, or an empty list if there are none.
ICS TEXT RULES
icstext RULENAME /regex/modifiers
score RULENAME 1.0
describe RULENAME ICS event text matching /regex/
These rules behave like rawbody rules and support the multiple and maxhits=N tflags. By default a rule stops at its first match. icstext matches only the invite text; to run one of the eval rules below, use a body rule.
EVAL RULES
check_ics_attendee_count(MIN, [MAX])
body RULENAME eval:check_ics_attendee_count(<min>,[max])
min: required, invites contain at least x ATTENDEE properties in total
max: optional, if specified, must not contain more than x ATTENDEE properties
check_ics_random_start_time()
body RULENAME eval:check_ics_random_start_time()
Fires if any event's DTSTART has a non-zero seconds component
(e.g. DTSTART:20250610T120005Z) -- a fingerprint of a machine-generated
start time, since human and most-client invites round to whole minutes.
check_ics_event_prop(NAME, REGEX)
body RULENAME eval:check_ics_event_prop('ATTACH', 'ENCODING=BASE64')
Fires if any calendar event has a property named NAME (case-insensitive)
whose content matches REGEX. The leading property NAME is stripped -- REGEX
sees "params:value" (or just "value" when the property has no parameters) --
so a rule for the DESCRIPTION value need not skip past a "DESCRIPTION:"
prefix. REGEX is a regular expression; the surrounding /.../ delimiters are
optional, so 'ENCODING=BASE64' and '/ENCODING=BASE64/' are equivalent -- use
the delimited form when you need flags (e.g. '/foo/i'). Note that even
without delimiters it is still a regex, not a literal substring:
metacharacters such as . | ( ) are active. Because the parameters are
retained, REGEX can still match them as well as the value -- e.g.
ENCODING=BASE64, VALUE=BINARY, FMTTYPE=image/png. Useful for finding
invites that carry inline attachments or images.
URI DETAILS
This handler creates a new "ics" URI type. You can detect URIs found in calendar invites using the URIDetail plugin. For example:
uri-detail RULENAME type =~ /^ics$/ raw =~ /^https?:\/\/bit\.ly\//