This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

why did the email get marked as spam

Is there anyway we can see the rules/reasoning as to why the UTM marked an email as spam. It would be very useful to understand and collated against false postives etc.


This thread was automatically locked due to age.
Parents
  • Hey, Coder, what'er ya doin' speakin' Cisco here!?! [[[:D]]]  Tell your office they should dump that old Ironport and get a UTM! [[[:D]]][[[:D]]]

    Max, I assume you mean that you have a "Warn" selection in the 'Spam Filter' section of SMTP so that some emails come to you flagged as SPAM instead of being quarantined or rejected.

    For every email that gets past the SMTP-time checks (RBLs, rDNS, Greylisting, BATV & SPF), the Proxy accepts the body and attachments of the email, and then uses ctasd to calculate a "signature" which it sends to a cloud service.  When the service replies with "Unknown" or "Suspect," the email is delivered.  The other possibilities are "Bulk" (SPAM) an "Confirmed."  Here's an example from our SMTP log file of a line showing the signature and the report:

    2015:07:02-06:34:24 secure exim-in[12690]: 2015-07-02 06:34:24 1ZAcl5-0003Ig-1o ctasd reports 'Suspect' RefID:str=0001.0A090202.559521C0.0043,ss=2,re=0.000,recu=0.000,reip=0.000,cl=2,cld=1,fgs=0


    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Hey, Coder, what'er ya doin' speakin' Cisco here!?! [[[:D]]]  Tell your office they should dump that old Ironport and get a UTM! [[[:D]]][[[:D]]]

    Max, I assume you mean that you have a "Warn" selection in the 'Spam Filter' section of SMTP so that some emails come to you flagged as SPAM instead of being quarantined or rejected.

    For every email that gets past the SMTP-time checks (RBLs, rDNS, Greylisting, BATV & SPF), the Proxy accepts the body and attachments of the email, and then uses ctasd to calculate a "signature" which it sends to a cloud service.  When the service replies with "Unknown" or "Suspect," the email is delivered.  The other possibilities are "Bulk" (SPAM) an "Confirmed."  Here's an example from our SMTP log file of a line showing the signature and the report:

    2015:07:02-06:34:24 secure exim-in[12690]: 2015-07-02 06:34:24 1ZAcl5-0003Ig-1o ctasd reports 'Suspect' RefID:str=0001.0A090202.559521C0.0043,ss=2,re=0.000,recu=0.000,reip=0.000,cl=2,cld=1,fgs=0


    Cheers - Bob
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data