Topic: Spam tagging and spam threshold
==== Required information ====
- iRedMail version (check /etc/iredmail-release): 0.9.7
- Linux/BSD distribution name and version: FreeBSD 11.1-RELEASE-p8
- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MySQL
- Web server (Apache or Nginx): Apache
- Manage mail accounts with iRedAdmin-Pro? Yes
- [IMPORTANT] Related original log or error message is required if you're experiencing an issue.
====
This server's spam threshold is set to 6.0 but it classifies many messages with lower X-Spam-Score: values as spam.
Below are headers from an example message. In this case, the X-Spam-Score: is only 2.325 but the server classified it as spam. In this case, the sender address "@.citibank.com" is also whitelisted, but I mention that for information only. The key point is that regardless of whitelist status messages with scores < 6.0 get tagged as spam.
Is this expected behavior? If so, what are some strategies for reducing the false-positive rate?
Thanks.
Return-Path: <1a5970c2blayfivciarwxpcaaaaaabibo5c6itx3bamyaaaaa@info.citibank.com>
Delivered-To: user@example.com
Received: from mail8.networktest.com (localhost [127.0.0.1])
by mail8.networktest.com (Postfix) with ESMTP id 8072B5E60BD
for <user@example.com>; Thu, 8 Mar 2018 20:19:59 -0800 (PST)
X-Virus-Scanned: amavisd-new at mail8.networktest.com
X-Spam-Flag: YES
X-Spam-Score: 2.325
X-Spam-Level: **
X-Spam-Status: Yes, score=2.325 tagged_above=0 required=0
tests=[BAYES_40=-0.001, DCC_CHECK=1.1, DKIM_SIGNED=0.1,
DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001,
RCVD_IN_BL_SPAMCOP_NET=1.347, RCVD_IN_DNSWL_NONE=-0.0001,
RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01,
SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail8.networktest.com (amavisd-new);
dkim=pass (1024-bit key) header.d=info.citibank.com;
domainkeys=pass (1024-bit key) header.from=citicards@info.citibank.com
header.d=info.citibank.com
Received: from mail8.networktest.com ([127.0.0.1])
by mail8.networktest.com (mail8.networktest.com [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id sAv4f9OyNfhm for <user@example.com>;
Thu, 8 Mar 2018 20:19:56 -0800 (PST)
Received: from bigfootinteractive.com (arm186.bigfootinteractive.com [206.132.3.186])
by mail8.networktest.com (Postfix) with ESMTP id 0460F5E60BC
for <user@example.com>; Thu, 8 Mar 2018 20:19:55 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha1; d=info.citibank.com; s=ei; c=simple/simple;
q=dns/txt; i=@info.citibank.com; t=1520569190;
h=From:Subject:Date:To:MIME-Version:Content-Type;
bh=W9PMW+xR7dw3hrijnrIgWyHfcak=;
b=b2HCGRNhxOQpB9lhGDnajYnvXmfkYT5EG7xDeuN+2cbK9YdAjO+d0Zzam4jZCxJP
Pr0lcgBNK3RD2ryW4X7SX+nxtPSzyVC48tMzV/5OCmBMb4qsCTI+mvGggmliE7zy
HttzM36f7rjexR6YXH3kWAvpYAB2Lja5er4/jajHzqQ=;
DomainKey-Signature: q=dns; a=rsa-sha1; c=nofws;
s=ei; d=info.citibank.com;
h=Received:Reply-To:Bounces_to:Message-ID:X-SS:X-BFI:Date:From:Subject:To:MIME-Version:Content-Type;
b=qsHh9DyZDLpN/5JFDPXPyPM33ij/VlL9fDV9FEZDDS0O7rdgStbXvpaJ7QwTtiUt
3zRFbteX1IhPwAi+VynclRUVq/A1t9ZI6T964somm5FfSXreYnA6TbdXC+pjFHVF
QwM57n5OmbI2voaDZtx0wIlA7gCIIsxiepzBFKvDPKc=
Received: from [192.168.3.50] ([192.168.3.50:54291] helo=unjdrmmailerpv25)
by pimta07.epsiloninteractive.com (envelope-from <1a5970c2blayfivciarwxpcaaaaaabibo5c6itx3bamyaaaaa@info.citibank.com>)
(ecelerity 2.2.2.45 r(34222M)) with ESMTP
id 19/60-17715-66B02AA5; Thu, 08 Mar 2018 23:19:50 -0500
Reply-To: =?iso-8859-1?B?ImNpdGljYXJkcyI=?= <1a5970c2blayfivciarwxpcaaaaaabibo5c6itx3bamyaaaaa@info.citibank.com>
Bounces_to: citicards.1a5970c2blayfivciarwxpcaaaaaabibo5c6itx3bamyaaaaa@info.citibank.com
Message-ID: <1a5970c2blayfivciarwxpcaaaaaabibo5c6itx3bamyaaaaa.9376.3955.unjdrmmailerpv25.DumpShot.2@info.citibank.com>
X-SS: 1-1-6540082-939189857
X-BFI: 1a5970c2blayfivciarwxpcaaaaaabibo5c6itx3bamyaaaaa
Date: Thu, 08 Mar 2018 23:18:10 EST
From: =?iso-8859-1?B?Q29zdGNvIEFueXdoZXJlIFZpc2GuIENhcmQ=?= <citicards@info.citibank.com>
Subject: ***Spam*** Reminder: We have emailed your 2018 reward certificate to
you
To: user@example.com
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="ABCD-1a5970c2blayfivciarwxpcaaaaaabibo5c6itx3bamyaaaaa-EFGH"
----
Spider Email Archiver: On-Premises, lightweight email archiving software developed by iRedMail team. Supports Amazon S3 compatible storage and custom branding.