Spamfoo on 9686
Problem reported by Brian Bjerring-Jensen - VonBjerring GmbH - 7/11/2026 at 8:34 AM
Submitted
Running extremely low ressorces and works quite good.

As stated it would be nice to be able to add something like campaigns to spam.
Jason Replied
I am under the impression that SpamFoo should train based on moving items form the Junk Mail folder to the Inbox.  We have several customers that are reporting that they are moving items using webmail and the move to inbox button as well as dragging and dropping them using IMAP from the Junk folder to the inbox.  The system does not appear to be learning.  Emails form the same source continuously seem to go into the Junk Mail from multiple senders.  For testing we are trying to avoid whitelisting.

Is anyone else experiencing this?
Heimir Eidskrem Replied
I see several incorrectly categorized emails and we have not ran this 24 hours yet.
Our 2 top offenders are legit business emails.  one being form vw.com going to a VW dealership.

Spamfoos interface is very simple and missing many features I think but its in interesting start.
We installed yesterday and set the score to 1.   
Gabriele Maoret - SERSIS Replied
I set it to a score of 5 to start with... it seems like a good starting point, but I agree with you all, there are too many false positives (and negatives, but those are not a problem... SpamFoo simply won't add spam scores, as if it were disabled...) and the categorization seems to work VERY poorly for Italian users...
Gabriele Maoret - Head of SysAdmins and CISO at SERSIS
Currently manages 7 SmarterMail installations (1 in the cloud for SERSIS which provides services to a few hundred third-party email domains + 6 on-premise for customers who prefer to have their mail server in-house)
Nigel Crump Replied
I have to agree with Gabriele, the default setting on Spamfoo is absurd. I ran it on defaults for 4 hours and watched it chuck 90% of my mail into the spam folder, but deeper inspection showed PayPal, Stripe, and even form submissions from our own website, sent via authenticated SMTP sessions on the box, in the spam folder!

5 seems a little more reasonable, but we are still seeing way too many false positives and blatant junk-mail advertising enlargement products... Where else would a spam filter put it, in the inbox!

Definitely not the most impressive start.
Zach Sylvester Replied
Employee Post
Hey Guys, 

Thank you for your feedback. I reached out to SpamFoo this morning and they let me know that they are currently training a new model that includes data from user corrections. I will let you guys know when this new model is released. 

Kind Regards, 

Zach Sylvester

Software Developer
SmarterTools Inc.
I think its works well


X-SmarterMail-SpamAction: High | MoveToFolder
X-SmarterMail-TotalSpamWeight: 112

X-SmarterMail-Spam: DMARC [passed]: 0, Reverse DNS Lookup [Passed]: 0, Null Sender: 0, ISpamAssassin [raw:5,3]: 5, SpamAssassin [raw:2]: 2, SPF [Pass]: 0, DKIM [None]: 50, _ARC: none, Custom Rules [WORD SPAM: 20], UCEProtect Level 1: 0, SPAMHAUS XBL: 0, SPAMHAUS SBL: 0, SPAMHAUS ZEN: 0, SPAMHAUS PBL: 0, SPAMRATS ALL: 0, BARRACUDA: 0, URIBL Black, URIBL Grey, URIBL Red: 0, SURBL: 0, Spamhaus DBL: 0, SEM-URI: 0, DNSBL: 0, SpamFoo [Spam,prob:0.62]: 30

And when I change the scoring it changes as well in the emails. We are constantly monitoring how it performs and for one client we have brought down their spam with 40% over night after introducing spamfoo.
Zach Sylvester Replied
Employee Post
Hey Everyone, 

I wanted to let you know that SpamFoo has released some new models. 
Please let us know if you notice an improvement. 

Kind Regards, 

Zach Sylvester

Software Developer
SmarterTools Inc.
BMark Replied
Hello,

We're testing SpamFoo, and so far it seems like an excellent product. The full integration with SM and the dashboard is also excellent. Kudos to the team for their work.

A few observations:
- From the SpamFoo dashboard, it's currently not possible to directly check the message (header, body, etc.) recognized as spam, making it difficult and time-consuming to check it to determine if it's a false positive.
If the spam message display were also integrated, it would be possible to better investigate and correct the training, for example, by implementing the same logic used for quarantined messages (possible to immediately release in the event of a false positive).
The optimal implementation, because it already has everything, would be to integrate the "SpamFoo dashboard > messages" with the "SM Spool > Spam Quarantine" section. Messages with a score (or threshold of low, medium, or high) would be quarantined.

- A further future development would be to integrate SM and SpamFoot's anti-spam rules.
For example, I see that in the SpamFoo Dashboard there are "rules and protection" where you can enter an email, domain, or IP address to consider as trusted or spam, but this section is already present (and used) in SM > anti-spam > trusted senders. So are they complementary? Or are the values entered in SM by SpamFoo not considered (but this wouldn't be a good thing, because if we set trusted, SpamFoo doesn't have to check, for both resources and false positives)?

What do you think?

Mark
Douglas Foster Replied
Based on the logs, spamfoo runs last, so is actions will be unrelated to prior disposition instructions, and may consequently override them.

We need the ability to bypas spamfoo, or guide it's behavior, based on header fields
Heimir Eidskrem Replied
@Bmark 
I agree with you and I assume they will build in what you mention.  Currently I find spamfoo lacking so much its not really practical to use.
Looking at senders that I know are legit domains, like vw.com email going to a vw dealership I see emails tagged as spam, but I have no way to know if they actually are spam or not.  Im almost certain they are not.  Also seeing concord.net being tagged as spam.  That is a remote fax service a client is using.  That is not spam but I can't know for sure.  propertysend.com sent 33 emails in the last 48 hours.  72% is tagged as spam, its a real-estate site sending email to a real-estate company.  

My point is that its no way to learn much about the emails from spamfoo.  Im sure they will  add more features.

I think this is a good start and im looking forward to see how this works 6 months from now.

Jason Replied
We are not seeing much of an improvement with the latest update.  Still seeing emails tagged as spam that should not be.  We are now seeing messages that were not tagged as spam previously, now tagged as spam.
Nick Jansen Replied
I agree with @BMark and @Heimir Eidskrem (and @terry in the SpamFoo thus far thread); it would be very helpful to be able to view additional info about individual messages in the SpamFoo dashboard.
Zach Sylvester Replied
Employee Post
Hey Jason, 

Thank you for the feedback. As your users move those emails out of junk the system will learn that those types of messages shouldn't go to junk on the fly. If you'd like to help SpamFoo improve faster you can open a ticket with support and send over some of the EMLS that you are having issues with after removing PII and SpamFoo can add that to their validation set. 

Kind Regards, 

Zach Sylvester

Software Developer
SmarterTools Inc.
Zach Sylvester Replied
Employee Post
@Heimir Eidskrem Aside from submitting moving it to inbox one option that you have is if you go to the system admin spamfoo dashboard or the domain admin spamfoo dashboard you can add a rule for that domain that makes it always ham and never spam. Hope this helps.

Zach Sylvester

Software Developer
SmarterTools Inc.
Heimir Eidskrem Replied
@Zach Sylvester 
I understand that but to know if we should take action we need to know if its spam or not, we need to know if its really spam or not.  Thats not really possible in Spamfoo dashboard.    The dashboard is very lacking when it comes to tools to determine if spamfoo classified the email correctly so for us its not really useful but im sure thats coming.  

Basically, the knowledge gap from Spamfoo classifying to us confirming is a real issue with the dashboard.  
Rod Strumbel Replied
I think the spamfoo analysis of %Spam is way way off.

Since activated, it's reporting 17/18 messages as spam in the Mail Health page (94.4%)
But... if I look at the Messages page, I have hundreds more messages of which at least all on the first page have Decision = "Not Spam".    So... something is amiss.

In fact, if I filter the SpamFoo dashboard (System Admin) for the domain in question and specify just "Spam" as the Decision, it finds the 17 messages, but, if I set it to "Not Spam" I get 48 pages of results with 25 per page.
So again... the Mail Health page appears to have some serious calculation issues.
Scott Johnson Replied
The all or nothing approach for SPAMFOO used in the anti spam section would be better served with a layered approach on percent much like is allowed for mailspike.  allow for adding percent brackets and a weight.

[2026.07.15] 12:06:19.031 [SpamFoo Client] [42898860] Done Scanning Message. MessagePath: /var/lib/smartermail/Spool/SubSpool2/590242898860.eml IsSpam: True, Probability: 53.1 %, Classification: spam, TextScore: 0.42, MetaScore: 0.53, ConfidenceMargin: 0.03, Entropy: 0.69, Disagreement: 0.11, ShouldEscalate: TrueTabs Probabilities: []
echoDreamz Replied
We are still seeing way too many false positives, tons of legit emails from Facebook are being flagged as spam, mariott, Ingles Market, Allegiant, non-US banks like ICICI, Fanatics, Office Depot, campaign emails from various people running for various office positions, such as ginafortexas.com and democrats.org. Various notifications being flagged too from sites like Alarm.com.
David Fisher Replied
I believe the best approach would be to have an automatic whitelist, would be nice if SpamFoo developers could create a database of popular sites, like citi.com, disney.com, facebookmail.com, etc..  If the email comes from them, it passes SPF, DKIM, and DMARC, to be sure it is not being impersonated, it is automatically allowed, no matter what!

  Yes it is possible for someone to hack a popular site's email server and send out mass spam, but the likelihood of this is very rare, and why can't we trust these banking, amusement, and social media sites, to not have this happen?

  I think this might be the best answer to combat all the phishing and impersonation style emails, basically the reverse of a RBL.

  Right now, I am using ClamAV Yara Rules to Quarantine impersonation style emails, but I cannot exempt companies like amazon.com, citi.com, and chase.com from all Yara rules. As sometimes you have Amazon send out an email about a Chase Credit Card!

  I think it is best to trust ALL legit emails from these various companies.  Now of course we wouldn't auto whitelist gmail.com and outlook.com etc..

  Just a thought I have, has to be some better way of doing it.  If we were to auto whitelist like this, the email comes in, we do a quick check, it is on the okay list, so we skip all further spam checking and the mail flows though more quickly.

  But maybe I am way off base here with this thought, and don't see the hang up in this idea.
Grady Werner Replied
Employee Post
We’ve been fortunate to run SpamFoo internally for quite a while, including on my own personal domains, and I’ve had great success with it. That said, the success came after users on each of the domains trained SpamFoo to match how to handle email.

I think the biggest discussion point is the initial experience before it has learned from each user.

Some emails are obvious. Banks and government sites should rarely, if ever, be flagged as spam. Fortunately, SpamFoo has made adjustments and it should happen much less often now.  

David Fisher is pretty much right on the money with his most recent post, and from my understanding, that was part of the last update that rolled out, although some “large domains” can’t be automatically trusted (looking at you, Gmail and Yahoo), and the list is still being expanded.

Other emails are more subjective. For example, without revealing my political affiliation, I’d bet that if 100 Americans received an email from democrats.org, about half would move it to Primary and half would move it to Junk.

That raises the real question: where should the initial model start before users train it? Treating nothing as spam doesn't work, and treating everything as spam is just as bad. That's where the content analysis helps, and that improves from corrections.

Even running SpamFoo at a low weight (around 5) is valuable because user corrections are fed back into the training process. By default, only calculated values from emails (hashes and similar metadata) are shared.

Users who opt in to Enhanced Feedback in SmarterMail help even more because SpamFoo can learn from the actual content of new messages, allowing improved models to be developed much faster.

I’ve personally shared some of your feedback in the community to SpamFoo as have other employees. For example, the desire to make corrections directly within the interface. I agree that would be a valuable improvement for everyone.
Grady Werner
SmarterTools Inc.
echoDreamz Replied
While not to get into politics or anything of sorts, I would say the odds of democrats.org sending out actual spam is nearly if not, zero. Democrats.org does not crank out mail to randoms, you've opt'd in somehow to receive emails from the domain.

Said logic can be applied to really anything. IE, if a user decides, emails from SmarterTools are now spam, does that mean emails from SmarterTools are spam? Of course not, SmarterTools does not send out spam.

Domains and services like Yahoo, Gmail etc. are also user-based mail. So, anyone can signup for an account and start sending out mail, so it makes sense to be more "aggressive" on those emails because they are not really trusted sources.

Well known and trusted sources though like Facebook, DNC, Banks and other financial institutions, education entities such as colleges and ISDs, shopping sites like Amazon, eBay, NewEgg etc.

David above had a great idea about the message, is the message passing DMARC etc. is the message from a trusted source.

Which is where I think this gets difficult, what is actually spam vs. what a user says to them is spam. 
Douglas Foster Replied
I started a topic on "What is spam?" awhile back, but it stimulated no discussion.

Political mailings are an interesting example.  You are correct that they use valid lists for their mailings, but they also have no restraint.   Work accounts are for work, and when you use your account for non-work purposes, the usage must not create an excessive workload.   Some political mailings get quarantined as suspicious because they are asking for money, while others they get blocked their abusive volume has caused me to blocklist them.

The point here is that what users want and what administrators want are not the same thing, and SpamFoo needs to be able to move upward in the kill chain so that its behavior can be fully controlled by administrators, with advice from users rather than control by users.

As an aside, I have been using the training folder for awhile, with manual review of submissions.    I have a huge problem with users sending messages to Junk when they should be sent to Deleted.   I have begun sending gentle correction emails to fix the probvlem.  I don't know how to keep that behavior from poisoning SpamFoo unless administrators have the ability to review and filter user submissions.
BMark Replied
I agree with you Douglas,

I believe the approach we are following is the right one, with SpamFoo using local AI along with all the other methods already used so far to assign scores.

The real issue lies in controlling what is considered SPAM.. 
Most end users complain about spam, but they often do not even understand the importance of blocking a spam sender or moving messages to the Junk folder to help train the system. 
Therefore, for small and medium-sized environments, the most demanding task still remains the review and supervision work performed by the administrator.

In my opinion, this could be simplified in SM through a dedicated "message review workflow" for emails flagged as SPAM (low, medium, high severity), including:

1) The ability to place messages in quarantine (pending review), typically those with a high score, although this should be configurable by the administrator.

2) A comprehensive SPAM section for viewing messages flagged as spam by the various filtering systems (including SpamFoo), featuring:
- An indication of whether the spam classification is low, medium, or high.
- The ability to open messages and inspect their body, headers, recipients, etc.
- Display of the spam score and detailed information about the checks performed (passed checks, individual scores, and the summary currently available in the message headers).

(With a style similar to what is already available in the SPOOL > QUARANTINE section.)

Most importantly, each message should have dedicated action buttons to:
- Release the message (if it is in quarantine) and mark the sender email address or domain as trusted (meaning it should never be blocked again by any filtering system, including SPF, DKIM, etc.).
- Confirm Spam for the sender email address or domain (confirming that it is spam so that all future messages can be rejected without running the full set of checks, resulting in significant resource savings — optional for the administrator).

In reality, this would essentially be an enhanced version of the current SPOOL > QUARANTINE view in SM, enriched with the data and actions that administrators actually need to manage spam effectively.

All trusted-sender and confirmed-spam information should then be shared with current and future anti-spam systems (such as SpamFoo).

In the future, as I suggested in another post, these features could be integrated directly into the SpamFoo or SM dashboard, along with statistics, probability scores, trends, and other relevant information.
Ultimately, I believe that most of the foundation already exists within SM. It simply needs to be organized and refined to fully support this excellent new development represented by SpamFoo and the additional security capabilities it introduces.

Mark

Reply to Thread

Enter the verification text