диагностика · ответ с источниками
SpamAssassin Scores: What They Mean and How to Fix Them
TL;DR: A SpamAssassin score is the sum of points from every rule a message triggers; at 5.0 (the default required_score) it is tagged as spam. Aim for 0 or below, and under 2.0 at most. The rules that hurt legitimate senders are infrastructure, not words: RCVD_IN_PBL (+3.335), URIBL_DBL_SPAM (+2.5), MISSING_DATE (+1.36), RDNS_NONE (+0.793), while valid DKIM only earns -0.1.
What does SpamAssassin measure in an email?
A SpamAssassin score is the sum of points from every rule a message triggers in Apache SpamAssassin, the open-source spam filter maintained by the Apache Software Foundation. Each rule tests one thing, such as a missing Date header, a sending IP with no reverse DNS, a link to a domain on a blocklist, or a valid DKIM signature, and carries a score that can be positive (spam-like) or negative (ham-like). If the total reaches required_score, the message is tagged as spam. The default required_score is 5.0, which Apache's own documentation calls 'quite aggressive' and suitable for a single user; it suggests ISPs use 8.0 or 10.0 and says messages should only be deleted outright at 15.0 or higher. The current release is SpamAssassin 4.0.2, published on August 30, 2025, and the 3.4 branch no longer receives fixes. SpamAssassin runs inside many hosting providers, cPanel servers, Proxmox Mail Gateway, and appliance filters; Gmail, Outlook.com, and Yahoo use their own filters and do not publish scores.
How does SpamAssassin calculate the score?
SpamAssassin calculates the score by running header, body, URI, DNS blocklist, authentication, and Bayesian rules against the message and adding the points of each rule that fires. The points for a rule are not fixed: each rule can have four scores, and which one applies depends on the configuration. Score set 0 is used when Bayes and network tests are both off; set 1 when network tests are on but Bayes is off; set 2 when Bayes is on but network tests are off; set 3 when both are on, which is the normal production setup. That is why RDNS_NONE, 'delivered to internal network by a host with no rDNS', is worth 2.399 points on a server with no network checks but 0.793 on a full setup. Most scores are generated by a mass-check process that trains on real spam and ham corpora, and sa-update downloads new rules and scores between releases. The result is written into the message as an X-Spam-Status header listing the score, the threshold, and every rule that fired.
X-Spam-Status: No, score=-0.1 required=5.0 tests=DKIM_SIGNED,DKIM_VALID,
DKIM_VALID_AU,DMARC_PASS,HTML_MESSAGE,SPF_HELO_NONE,SPF_PASS
autolearn=ham autolearn_force=no version=4.0.2
X-Spam-Flag: NOWhich SpamAssassin rules matter most for legitimate senders?
For a legitimate sender, a small set of rules accounts for most of the score, and the numbers below are taken from Apache's current rule set (score set 3 unless noted). The heavy positive rules are about infrastructure and content structure, not words. Authentication rules give tiny credits: DKIM_VALID and DKIM_VALID_AU are -0.1 each and SPF_PASS is -0.001, so passing authentication barely lowers your score, while DMARC_REJECT (a failing message from a domain with p=reject) adds 1.797. Infrastructure rules hurt most: RCVD_IN_PBL (sending IP on Spamhaus's Policy Block List, typical of residential IPs) adds 3.335, RDNS_NONE adds 0.793, and URIBL_DBL_SPAM (a linked domain on the Spamhaus Domain Block List) adds 2.5. Structural rules catch broken templates: MPART_ALT_DIFF (HTML and text parts differ a lot) adds 0.790, MISSING_DATE 1.360, HTML_IMAGE_ONLY_04 (almost only images) 1.172. Bayes dominates when trained: BAYES_99 adds 3.5, while BAYES_00 subtracts 1.9.
Rule Score (set 3) What triggers it
BAYES_99 +3.5 Bayes classifier: 99-99.9% spam probability
RCVD_IN_PBL +3.335 Sending IP on Spamhaus PBL (end-user ranges)
URIBL_DBL_SPAM +2.5 Linked domain on Spamhaus DBL
EMPTY_MESSAGE +2.320 No text body
DMARC_REJECT +1.797 DMARC fail, policy p=reject
MISSING_DATE +1.360 No Date: header
HTML_IMAGE_ONLY_04 +1.172 HTML with images and under 400 bytes of text
DMARC_QUAR +1.198 DMARC fail, policy p=quarantine
DMARC_NONE +0.898 DMARC fail, policy p=none
RDNS_NONE +0.793 Relay has no reverse DNS
MPART_ALT_DIFF +0.790 HTML and text alternatives differ
SUBJ_ALL_CAPS +0.5 Subject in all capitals
MISSING_MID +0.497 No Message-ID: header
DKIM_SIGNED +0.1 Has a DKIM signature (offset by DKIM_VALID)
DKIM_VALID -0.1 DKIM signature verifies
DKIM_VALID_AU -0.1 Valid signature from the author's domain
SPF_PASS -0.001 SPF passes
BAYES_00 -1.9 Bayes: 0-1% spam probabilityКакой балл SpamAssassin считается хорошим?
A good SpamAssassin score for transactional or marketing email is 0 or below, and anything under 2.0 is comfortable. The threshold is 5.0 by default, but you do not control the receiver's threshold or which rules they enable, so the aim is headroom: a message at 4.5 passes on a default install and fails on a server where an admin lowered required_score to 4.0, or where BAYES_50 (0.8 points) fires because their users have trained Bayes differently. Negative scores are good: they mean ham-like rules such as DKIM_VALID or BAYES_00 outweighed anything spam-like. A legitimate, authenticated message from a reputable sending service with a balanced HTML and text body typically lands between -2 and +1. If a tester shows 3 or more, look at the two or three biggest rules in the report rather than rewriting copy; one infrastructure rule like RCVD_IN_PBL can outweigh every word in the email.
Do SpamAssassin scores affect Gmail and Outlook delivery?
SpamAssassin scores do not directly affect Gmail, Outlook.com, or Yahoo inbox placement, because those providers run their own filters and do not use SpamAssassin thresholds. Gmail weights sender reputation, authentication, and recipient behavior, and Google's sender guidelines set requirements such as a spam rate below 0.30% in Postmaster Tools. SpamAssassin matters for the rest of the recipient base: business mail servers, universities, hosting companies, and security gateways that run it or a derivative such as Rspamd rule ports. For B2B senders that can be a large share of recipients. A SpamAssassin test is still useful for any audience because many of its rules flag real defects that every filter dislikes: missing Message-ID or Date headers, sending from IPs without reverse DNS, broken DKIM, links to blocklisted domains, and image-only HTML. Treat a low score as a hygiene check, and use Gmail Postmaster Tools, Microsoft SNDS, and your bounce and complaint events to judge how the large mailbox providers actually treat you.
How do you test your SpamAssassin score?
You can test your SpamAssassin score locally in under a minute, which is more reliable than a web tester because you see the exact rule list. Install SpamAssassin 4.0 (apt install spamassassin on Debian or Ubuntu, brew install spamassassin on macOS), run sa-update to fetch the current rules, then save a real message, with full headers, as an .eml file by sending it to yourself and using 'Show original' or 'Download message' in your mail client. Run spamassassin -t on the file to get a report of every rule that fired and its points. Testing the raw MIME you generate before sending misses rules that depend on the path: received headers, rDNS, and DKIM signatures added by your sending provider. Online testers such as mail-tester.com and MailerCheck send a message to a seed address and show the SpamAssassin result alongside authentication checks; they are convenient but use their own configuration and network rules. Note that URIBL_BLOCKED in a report means the URI blocklist refused your resolver, usually a public DNS like 8.8.8.8, not that your links are listed.
sudo apt install spamassassin # Debian/Ubuntu, installs 4.0.x
sudo sa-update # fetch current rules and scores
# score a saved message (full headers) and print the rule report
spamassassin -t < welcome-email.eml | sed -n '/Content analysis details/,$p'
# against a running spamd daemon
spamc -R < welcome-email.emlHow do you lower a SpamAssassin score?
Lower a SpamAssassin score by fixing the highest-scoring rules in the report first; most transactional messages need three or four changes. Authenticate fully: publish SPF, sign with DKIM on your own domain (DKIM_VALID_AU), and publish DMARC so a forged copy cannot pass. Send from infrastructure with clean IPs and matching forward and reverse DNS, which a hosted email API handles for you and a home or cloud VM usually does not (RCVD_IN_PBL, RDNS_NONE, RDNS_DYNAMIC). Always include a plain-text alternative that matches the HTML so MPART_ALT_DIFF does not fire, and keep real text in the HTML rather than a single image. Make sure every message carries Date, Message-ID, From, and a non-empty Subject; a mailer that omits them triggers MISSING_DATE, MISSING_MID, or MISSING_SUBJECT. Check that every linked domain, including URL shorteners and tracking domains, is not on the Spamhaus DBL or SURBL. Last, and least, avoid ALL-CAPS subjects and spammy formatting; word lists cost fractions of a point compared with the infrastructure rules.
How does SendHQ affect SpamAssassin results?
SendHQ removes several of the infrastructure rules from the report by default, while content rules remain your responsibility. Messages go out through Amazon SES by default from a verified domain, so they carry a DKIM signature for your domain, come from IPs with reverse DNS, and include standard Date and Message-ID headers. When you send HTML without a text part, SendHQ generates a text alternative, which avoids MIME_HTML_ONLY (0.1) and usually MPART_ALT_DIFF; an authored text part is still more reliable than a generated one. After sending, the message record shows whether the recipient server accepted it (delivered) or rejected it (bounced), and a bounce from a SpamAssassin-filtered server often includes the score in the SMTP response text, for example '550 5.7.1 Message rejected as spam (score 7.4)'. Use that text with the local test above to see which rules pushed the message over the receiver's threshold.
Что спрашивают команды
What is the SpamAssassin spam threshold?
The default required_score is 5.0. Apache's documentation calls that aggressive for multi-user systems and suggests ISPs use 8.0 or 10.0. Receivers can change it, so a sender should aim well below 5 rather than just under it.
Is a negative SpamAssassin score good?
Yes. A negative total means ham-like rules such as DKIM_VALID, DKIM_VALID_AU, or BAYES_00 outweighed spam-like rules. Most well-authenticated transactional email from a reputable sending service scores between -2 and +1.
What does URIBL_BLOCKED mean in SpamAssassin?
URIBL_BLOCKED means the URI blocklist refused to answer the DNS query, usually because the filter used a public resolver such as Google DNS. It scores 0.001 and says nothing about your links. The receiving admin fixes it by running a local resolver.
Does Gmail use SpamAssassin?
No. Gmail, Outlook.com, and Yahoo use their own filtering and do not apply SpamAssassin scores. SpamAssassin matters for business, university, and hosting mail servers, and as a hygiene check that catches header and authentication defects.
Why do SpamAssassin rules have four scores?
Each rule can have a score for four configurations: no Bayes and no network tests, network tests only, Bayes only, and Bayes plus network tests. SpamAssassin uses the score set that matches how the receiving server is configured.
How often do SpamAssassin scores change?
Scores and rules update between releases through sa-update, which downloads the latest rule set published by the Apache project. Run it regularly on your test machine so local results match what current receivers use.
Первоисточники
- Mail::SpamAssassin::Conf (4.0.x) — Apache SpamAssassin
- Apache SpamAssassin project news — Apache Software Foundation
- SpamAssassin rules: 50_scores.cf — Apache SpamAssassin
- SpamAssassin rules: 72_scores.cf — Apache SpamAssassin
- SpamAssassin score guide — MailerCheck