I agree with you Douglas,
I believe the approach we are following is the right one, with SpamFoo using local AI along with all the other methods already used so far to assign scores.
The real issue lies in controlling what is considered SPAM..
Most end users complain about spam, but they often do not even understand the importance of blocking a spam sender or moving messages to the Junk folder to help train the system.
Therefore, for small and medium-sized environments, the most demanding task still remains the review and supervision work performed by the administrator.
In my opinion, this could be simplified in SM through a dedicated "message review workflow" for emails flagged as SPAM (low, medium, high severity), including:
1) The ability to place messages in quarantine (pending review), typically those with a high score, although this should be configurable by the administrator.
2) A comprehensive SPAM section for viewing messages flagged as spam by the various filtering systems (including SpamFoo), featuring:
- An indication of whether the spam classification is low, medium, or high.
- The ability to open messages and inspect their body, headers, recipients, etc.
- Display of the spam score and detailed information about the checks performed (passed checks, individual scores, and the summary currently available in the message headers).
(With a style similar to what is already available in the SPOOL > QUARANTINE section.)
Most importantly, each message should have dedicated action buttons to:
- Release the message (if it is in quarantine) and mark the sender email address or domain as trusted (meaning it should never be blocked again by any filtering system, including SPF, DKIM, etc.).
- Confirm Spam for the sender email address or domain (confirming that it is spam so that all future messages can be rejected without running the full set of checks, resulting in significant resource savings — optional for the administrator).
In reality, this would essentially be an enhanced version of the current SPOOL > QUARANTINE view in SM, enriched with the data and actions that administrators actually need to manage spam effectively.
All trusted-sender and confirmed-spam information should then be shared with current and future anti-spam systems (such as SpamFoo).
In the future, as I suggested in another post, these features could be integrated directly into the SpamFoo or SM dashboard, along with statistics, probability scores, trends, and other relevant information.
Ultimately, I believe that most of the foundation already exists within SM. It simply needs to be organized and refined to fully support this excellent new development represented by SpamFoo and the additional security capabilities it introduces.
Mark