you find domains in the body (every one I've seen has had only the one) and then check against the list.
Good point.
But I'm using a filter that someone else programmed. They did include a tremendous amount of flexibility via XML config files. However, I don't have direct access to the list of extracted domains and I'm can't do everything as I don't have the source code. Also, I think that much of the filtering rules proceed even if a rule had already caught something... (But I'll have to look into this to be sure). Thanks for the suggestion anyway.
Rob McEwen PowerView Systems rob@PowerViewSystems.com (478) 475-9032