With the Log Search With SpamExperts, you can trace how an incoming email was processed by the filtering system. It is one of the most important diagnostic tools when a message is missing, has been recognized as spam, or has unexpectedly arrived in the mailbox.
Instead of changing filter settings on a hunch, when you have problems you should first search for the specific message and examine its status.
CURIAWEB recommendation: If something is wrong with an email, start troubleshooting with the log search. The SpamExperts default configuration should generally remain unchanged. A specific message provides significantly more information for diagnosis than a blanket change of the filter settings.
What is the SpamExperts Log Search? #
SpamExperts logs messages processed through its filtering infrastructure. You can search these log data using Log Search.
This can be used to determine, for example:
- whether SpamExperts has received a specific message
- when the message was processed
- who the sender and recipient were
- how the message was classified
- whether it was accepted, rejected, or quarantined
- whether an allow or block rule was involved
- whether there has been a problem with the further delivery
Log Search thus answers one of the most important questions in almost every email disruption:
What happened to this specific message?
Differentiate between Incoming and Outgoing Log Search #
SpamExperts distinguishes between incoming and outgoing email traffic.
| Log Search | Use |
|---|---|
| Incoming Log Search | Investigate messages sent by external senders to your protected domain |
| Outgoing Log Search | Investigate messages sent via SpamExperts Outgoing Filtering |
If, for example, a customer claims to have sent you a message, you use the Incoming Log Search.
If, on the other hand, you want to investigate what happened to a message sent via SpamExperts, the Outgoing Log Search relevant.
We explain how to set up the outgoing filter at Set up SpamExperts Outgoing Filtering.
What information should you know before searching? #
The more precisely you can narrow down a message, the easier the search.
Especially helpful are:
- Sender address
- Recipient address
- Date
- approximate time
- Subject
In the case of a missing business message, you should therefore ask the sender as much as possible about the sender address used and the approximate time it was sent.
Practical Tip: „The email was sent yesterday is significantly less helpful for a technical search than sent at around 2:35 PM from
absender@example.comanempfaenger@example.ch“.
1. Open SpamExperts Control Panel #
Open your SpamExperts service via the CURIAWEB customer center.
Then check that you are managing the correct domain or user.
We explain how to open the Control Panel under Login to the SpamExperts Dashboard via the CURIAWEB Customer Center.
2. Open Incoming Log Search #
Open in the SpamExperts Control Panel the section for Incoming and there the Log Search or rather the view of the incoming logs.
Depending on the access level, additional search and filter options may be available.
At the domain level, you examine the email traffic of the domain in question. At other access levels, the visible scope of data may be restricted or expanded accordingly.
3. Define search period #
First, narrow down the time period in which the searched message must have been processed.
If you know the approximate shipping time, you shouldn't unnecessarily search through a very large time frame.
Please note that there may be a slight discrepancy between the shipping time specified by the sender and the time of processing by SpamExperts.
Therefore, if necessary, select a sufficiently large time window around the expected shipping time.
4. Search by sender #
If the sender address is known, you can use it to significantly narrow down the search.
Example:
absender@example.com
Make sure to use the actual email address and not just the display name visible in the email program.
5. Search for recipient #
With multiple mailboxes or many messages, the recipient address is another important search criterion.
Example:
info@example.ch
The combination of sender, recipient, and time period is often enough to uniquely find a specific message.
6. Use subject line as an additional search criterion #
The subject line can also help with the search.
However, it should not always be used as the sole criterion. Automated messages can have identical subject lines, and some systems alter the subject during processing.
Therefore, if possible, use multiple characteristics:
Period
+
Sender
+
Recipient
+
Subject, if applicable
7. Show search results #
Start the search with the selected criteria.
SpamExperts then displays the messages that match your query.
Check first in case of a hit:
- Time
- Sender
- Recipient
- Subject
- Status or classification
This is how you ensure that you are actually investigating the message you are looking for and not just a similar email.
What does the status of a message mean? #
The displayed status or classification provides an important indication of how SpamExperts handled the message.
Depending on the message and configuration, different results may be visible, for example.
| Result | Fundamental importance |
|---|---|
| Accepted | The message was accepted by SpamExperts and processed for further delivery. |
| Quarantined | The message was quarantined according to the filter decision. |
| Rejected | The message was rejected during processing. |
| Temporary delivery problem | Further delivery to the target system was temporarily unsuccessful and may require further delivery attempts. |
Important: „Accepted“ initially means that SpamExperts has accepted the message. You should not conclude from this alone that it subsequently ended up guaranteed in the recipient's visible inbox. After SpamExperts, there is still the destination mail server and, if applicable, further local processing steps.
Accepted – but the message is missing in the inbox #
If SpamExperts has accepted a message but it is missing in the mailbox, the further delivery must be investigated.
The simplified message path is:
Sender
↓
SpamExperts
↓
Destination
↓
Destination mail server
↓
Mailbox
A problem can therefore also occur after the SpamExperts filter decision.
Check in particular whether an error message or a temporary problem is visible during delivery to the configured destination.
We explain the connections between SpamExperts and the target mail server at Set up SpamExperts incoming filtering and configure MX records.
Quarantined – What now? #
If a legitimate message has been classified as spam and placed in quarantine, you should first check whether it is actually the expected message.
If it is legitimate, it can be approved if necessary and trained accordingly in the event of a misclassification.
We explain the use of quarantine under Using Spam Quarantine in SpamExperts.
Rejected – why was the message rejected? #
If SpamExperts has rejected a message, you should examine the detailed information of the log entry.
A rejection can have various causes. Therefore, what matters is not just the status Rejected, but rather the specific reason or SMTP response.
Do not immediately change global filter settings because of a single rejected entry.
Check first:
- which message is affected
- which classification is displayed
- which specific reason is given
- whether a manual allow or block rule is involved
- whether an authentication check such as SPF, DKIM or DMARC is relevant
The message is not in the log search at all #
This is a particularly important diagnostic case.
If a message does not appear in the Incoming Log Search even though it has arrived in the mailbox, it may have bypassed SpamExperts.
A possible message route would then be:
Sender
↓
Directly to the destination mail server
↓
Mailbox
SpamExperts was bypassed
In this case, check the MX records of your domain in particular.
When SpamExperts Incoming Filtering is enabled, the public MX records must point exclusively to the designated SpamExperts systems.
Old MX records to the direct mail server can enable an alternative delivery route.
Attention: If spam lands in the inbox but does not appear in the SpamExperts Log Search at all, tightening the filter settings is useless. The message may not have been processed by the filter at all.
How do I check if a message has passed through SpamExperts? #
Log Search is the most important tool for this.
In addition, the full headers of a received email may contain clues about the delivery path.
SpamExperts can insert additional header information into processed messages, such as details on classification or recommended action.
Depending on the system or branding, corresponding headers may be named differently or have been removed by the downstream mail server.
If such headers are missing, this alone is not yet definitive proof. In combination with the log search and the actual MX path, the message routing can be assessed much more reliably.
What does „ham“ mean? #
Is a message considered ham classified, SpamExperts has evaluated it as a legitimate message, or one not to be classified as spam.
This does not automatically mean that every message classified as ham is actually desired. Spam filters make decisions based on technical and content-related characteristics and can be wrong in individual cases.
If a clear spam message has been let through as ham, targeted spam training can be useful.
We explain how this works at Train SpamExperts Filter: Report spam and ham correctly.
What does „unsure“ mean? #
SpamExperts can also process messages as unsure classify as spam when the filter score is not clear enough for a spam classification.
Such a message should be judged based on its actual content and sender.
If it is clearly spam, it can be trained accordingly. If it is legitimate, there is no automatic need for action.
Important: A single message with an unexpected classification is not a reason to change the global spam threshold. CURIAWEB continues to recommend keeping the default values.
Detect allow-list hits #
If a message was handled differently due to an existing allow list rule, this information is critical for diagnosis.
An allow list can influence the normal filtering decision. Therefore, if unexpected spam was delivered, you should check whether an existing exception was involved.
We explain the management of such exceptions under Sender Allow List: Allow senders in SpamExperts.
Investigate block list hits #
An existing sender block list rule can also explain why a message was not delivered as expected.
Particularly when rules apply to the envelope sender, a message can be rejected during the SMTP connection itself.
You can find more information at Sender Block List: Block senders in SpamExperts.
SPF, DKIM, and DMARC in diagnostics #
SpamExperts also considers email authentication mechanisms during message inspection.
In the case of a suspicious or rejected message, information on SPF, DKIM, or DMARC may therefore be relevant for root cause analysis.
A failed authentication check should not simply be „fixed“ by globally disabling the corresponding security check.
Instead, investigate why the message failed the review.
Spam gets through – how to proceed #
When a spam email has arrived in your inbox, you should first check whether it even passed through SpamExperts.
Search for the message in the Incoming Log Search using the sender, recipient, and timestamp.
After that, there are fundamentally two different situations:
| Result | Next step |
|---|---|
| Message is present in log search | Investigate classification and filter decision; use spam training if necessary |
| Message is not present in Log Search | Check MX configuration and possible direct delivery path to the mail server |
Legitimate email missing – here's what to do #
If an expected message has not arrived, first determine the sender, recipient, and time of dispatch as precisely as possible.
Then search in the log search.
Depending on the result:
| Log result | Exam |
|---|---|
| Quarantined | Check quarantine and classification |
| Rejected | Investigate specific grounds for rejection |
| Accepted | Check further delivery to the destination or target mail server |
| No match | Check if the sender actually sent the message and what delivery path the message took |
Uniquely identify a message in Log Search #
Do not rely solely on the subject line when there are multiple similar matches.
Compare if possible:
- Time
- Sender
- Recipient
- Subject
- further news information
Automated systems can send multiple messages with identical subject lines within a short period of time.
Why the SMTP error text matters #
If a message was not successfully processed or forwarded, an SMTP response can contain crucial information.
Generally, SMTP systems distinguish between temporary and permanent errors.
4xx
→ temporary error
5xx
→ permanent error
A temporary error usually means that delivery was not possible at this time and further attempts can be made.
A permanent error, on the other hand, indicates that the message was not accepted in this form.
Practical Tip: If you need assistance regarding a bounced email, the full SMTP error text is much more helpful than just the information that email is not working.
Log Search and Quarantine are not the same #
Quarantine shows you withheld messages. Log search, on the other hand, is used for a much more comprehensive investigation of message traffic.
| Tool | Main purpose |
|---|---|
| Spam Quarantine | View held messages and release them if necessary |
| Log Search | Search for messages and investigate their processing or delivery status |
A missing message does not necessarily have to be in quarantine.
Log Search before filter change #
The log search should generally be used before changing the filter settings.
An example:
Problem:
Spam arrives in the mailbox
Wrong reaction:
Change the quarantine threshold on suspicion
Better reaction:
Search for message in Log Search
↓
check if it passed through SpamExperts
↓
examine classification
↓
fix targeted cause
We explain the filter settings and our recommendations for them under SpamExperts Filter Settings: Why the Default Configuration is Usually the Best Choice.
What information helps with a support request? #
If you cannot classify an email issue yourself, you should have as specific information as possible ready.
Especially helpful are:
- affected domain
- complete sender address
- complete recipient address
- Date and time as precise as possible
- Subject of the message
- Status or classification from the log search
- displayed error message or SMTP response
For a problematic message that has already been received, the original message including complete headers can also be helpful for analysis.
Important: Never send passwords for your email account, SpamExperts, or the CURIAWEB customer center with a support request.
A practical diagnostic workflow #
For a specific email issue, you can use this process as a guide:
Identify email uniquely
↓
Open Incoming Log Search
↓
Search sender + recipient + time frame
↓
Message found?
↙ ↘
Yes No
↓ ↓
Check status Check delivery path /
↓ MX
Narrow down cause
↓
Targeted action
This allows you to avoid guesswork and much more quickly determine at which point in the message processing a problem has occurred.
Summary #
The SpamExperts Log Search is the central tool for investigating specific e-mails. It helps you determine whether a message reached SpamExperts, how it was classified, and what happened during further processing.
In the case of a missing message, you should ideally know the sender, recipient, date, and time, and then specifically search for it.
A message with the status Accepted can still encounter a problem later on the way to the destination mail server. A quarantined or rejected message should be investigated based on its specific classification or error message.
If you cannot find a delivered spam email in the Incoming Log Search at all, you should check in particular whether the message bypassed SpamExperts and whether the MX configuration is correct.
CURIAWEB recommends: First log search, then act. Do not change the general SpamExperts filter settings based on a single message, but first determine the specific cause.