Spam Filter Scoring Methodology

Back

10208

Issue:

How does the spam filter score messages based on their content?

Why are some legtimate messages marked as spam?

Solution:

Overview

Our mail servers include a spam filter that attempts to determine whether an incoming message is a spam message or a legitimate email.  The filter assigns a score to each message representing the probability that it is spam.  

If the score is high enough, the server deletes the message automatically and it never reaches your inbox. These thresholds are set by the system administrators and we constantly monitor them to ensure that we are effectively stopping a majority of the spam email while not deleting any legitimate email.

Criteria

Many factors are used in determining the score assigned to a particular message.  Also, the filter is constantly evolving since our system administrators feed the filter known spam messages that did not meet the set thresholds.  This allows the filter to 'learn' and refine the scoring process for future messages.

If you would like to see the specific critia that caused a particular message to be marked, this information is found in the message header.  To see the header in Outlook, right-click on the message then select Options.  In the "Internet Headers" section, scroll down until you see the line beginning "X-Spam-Status".  There you will see the score of the message as well as an itemized list of how this score was determined.

Here are few of main criteria that cause the filter to raise the message's score:

- URLs (web addresses) in the message body that match known spam URLs.
- HTML content and how that content is formatted (text style, ratio of images, etc.).
- A "remove link" or remove instructions.
- HTML comments which obfuscate text (i.e., an attempt by spammers to hide typical spam keywords).
- Forged return address or other forged header information.
- Using certain spam-related words in the body or subject.
- Known spam generating software fingerprints in the message header.

In addition, there are literally hundreds of other different rules and criteria that the system uses to intelligently decide whether a message is spam or not.

More Information:

How to set up a rule in Outlook to take advantage of spam filtering
How does SAGE Prevent Incoming SPAM on SAGE Email Accounts
Unsolicited Email (a.k.a. SPAM)
Best Practices for Preventing SPAM

Type: Info Publish Date: 9/26/2003 12:48:39 PM
Applies To: Last Updated: 11/8/2014 10:25:32 AM
Platform: All Expiration Date: