Hit ENTER after each Tag to add it to your post; Numbers in parentheses represent the Tag's usage.
Please see this scenario and help me find a fix.SmarterMail 11.7 is in use as both primary mail and incoming gateway servers.
Relevant Spam Weights:
CommTouch/Cyren: 30 Bulk
Reverse DNS: 10
UCE Protect Level 1: 10
UCE Protect Level 2: 20
UCE Protect Level 3: 30
Delivery Logs show a message come from our inbound gateway:
15:13:15  Delivery started for email@example.com at 3:13:15 PM
15:13:19  Spam check results: [_SPF: Pass], [SPAMCOP: passed], [UCEPROTECT LEVEL 1: passed], [UCEPROTECT LEVEL 2: failed], [UCEPROTECT LEVEL 3: passed], [_REVERSEDNSLOOKUP: passed]
15:13:22  Sending remote mail for firstname.lastname@example.org
15:13:22  Initiating connection to ....primary mailbox server.
15:13:22  Delivery for email@example.com to firstname.lastname@example.org has completed (Delivered)
15:13:25  Delivery finished for email@example.com at 3:13:25 PM [id:2043283268621]
Delivery logs for mailbox SmarterMail Enterprise 11.7 server
15:13:19  Delivery started for firstname.lastname@example.org at 3:13:19 PM
15:13:25  Spam check results: [_REVERSEDNSLOOKUP: passed], [_COMMTOUCH: 30,Bulk], [SPAMCOP: passed], [UCEPROTECT LEVEL 1: passed], [UCEPROTECT LEVEL 2: failed], [UCEPROTECT LEVEL 3: passed]
15:13:36  Starting local delivery to email@example.com
15:13:36  Delivery for firstname.lastname@example.org to email@example.com has completed (Delivered) Filter: Spam (Weight: 18)
15:13:36  End delivery to firstname.lastname@example.org
15:13:36  Delivery finished for email@example.com at 3:13:36 PM [id:1798397904573]
Header with totalled spam score:
Date: Mon, 20 Apr 2015 15:13:12 -0400
From: "Solar Panel Offers" <SolarPanelOffers@keshuff.eu>
Subject: Seasonal savings - on Home Solar panels
X-SmarterMail-SmartHostSpam: SPF_Pass, UCEProtect Level 2
X-SmarterMail-Spam: Commtouch 30 [value: Bulk], UCEProtect Level 2
Can anyone help me figure out why the TotalSpamWeight would be 18?
The total should be 30+20+20-2=68 right? Since UCE Protect Level 2 was used on both servers?
If that was the case, then the message should have scored way higher and been deleted according to our spam handling rules (30+ are deleted and <20 go to Junk-Mail folder).