GroupShield blocking and allowing spam messages with identical content?
Hi - We are using GroupShield for Exchange and Exchange 2010. We are examining the message headers on incoming spam and find that some messages with exactly the same content (although from different senders) have spam scores of 5 or higher embedded in the header (X-NAI-Spam-Score: 5) while other identical messages have no X-NAI entries at all and are therefore not flagged as spam.
For example, one spam message was receieved fine times within an hour. Two of the messages were scored as spam and the other three were not (no NAI score in the header). The message content from one of the non-scored messages was copied/pasted and sent using Yahoo email, and it was scored as spam (5).
Why is the spam detector either skipping some messages or handling them differently?
Re: GroupShield blocking and allowing spam messages with identical content?
Well detail in header could depend how you have configured the antispam settings - if you have set "attach a spam report" to spam mail only and your low detection threshold is 5 then mails under 5 won't get a report in header ... (set for all mail)
e..g difference in good mail and bad mail could be 1 trait which takes the score over 5 - maybe the "similar" mail scores close to 5 but beloow what is determined as spam (this is example only).
But if you fell a mail is scored too low - then submit it as spam (vice versa if you think its score is too high - submit as non-spam)