SpamExperts automatically detects and filters unwanted emails. Nevertheless, in individual cases, it can happen that a spam message is not recognized or a legitimate message is falsely classified as spam.
For such cases, SpamExperts offers options to Filter training. In doing so, messages are specifically used as Spam or Ham Reported.
CURIAWEB recommendation: You do not need to manually train SpamExperts continuously. The default configuration is already very well tuned. Use training selectively for actual misclassifications and do not change the general filter settings because of individual messages.
What do spam and ham mean? #
The term Spam is generally known. In the context of spam filters, you will also encounter the term Ham.
Spam
→ unwanted message or message to be classified as spam
Ham
→ legitimate, desired message
During training, you therefore inform SpamExperts that a specific message was misclassified from your perspective.
When is filter training useful? #
Training is particularly useful when the automatic classification of a message does not match the actual character of the email.
Typical cases are:
- A clear spam message was delivered right to your inbox.
- A legitimate message was incorrectly classified as spam.
In the first case, training comes as Spam in question, in the second as Ham.
When should you not train a message as spam? #
Not every unwanted email is automatically a useful training case.
A newsletter you subscribed to at some point, a legitimate business message that you are not currently interested in, or a regular notification from a service you use should not be trained as spam simply because you no longer wish to receive it.
For a legitimate newsletter, for example, the intended unsubscribe function is generally the more appropriate solution.
Important: Filter training is used to correct incorrect spam classification. It is not a substitute for unsubscribing from legitimate newsletters or managing personal email preferences.
Before you train a message #
When investigating a specific message, you should first understand how SpamExperts processed it.
Particularly helpful for this is the Log Search. There you can search for a message and examine its processing or classification.
You can find the complete instructions at SpamExperts Log Search: Trace E-Mail History.
Open SpamExperts Control Panel #
Open your SpamExperts service via the CURIAWEB customer center and check that you are managing the correct domain or the correct user.
We declare the registration under Login to the SpamExperts Dashboard via the CURIAWEB Customer Center.
Train an unrecognized spam message #
If a clear spam message is not recognized by the filter and is delivered to your mailbox, the message in question can be used for spam training.
Use the feature provided in your SpamExperts Control Panel for training or reporting spam.
The crucial part is that you original message use. The technical information of an email is important for the analysis.
Attention: Do not just copy the visible message text into a new email. This causes essential parts of the original message to be missing. Use the designated SpamExperts function or the original message for training.
Train a legitimate message as ham #
If a legitimate message was incorrectly classified as spam, it can be Ham to be trained.
This signals to the filter system that the message in question or its characteristics should not have been classified as spam.
If the message is in the spam quarantine, you should first identify it there and check the classification.
We explain the use of quarantine under Using Spam Quarantine in SpamExperts.
Releasing and training are different actions #
In the case of a misclassified message, you should distinguish between Approval and Training distinguish.
| Action | Purpose |
|---|---|
| Release | The specific withheld message should be delivered. |
| Train like a ham | The message is used as a legitimate message for filter training. |
Thus, an approval initially solves the problem of the specific message. Training, on the other hand, concerns the classification.
Training and sender allow list are also not the same thing #
Filter training should not be carried out with either Sender Allow List to be confused.
| Function | Purpose |
|---|---|
| Filter Training | Classify a message as spam or ham, or report it to improve the filter decision. |
| Sender Allow List | Set up a targeted exception for a sender. |
Therefore, in the event of a single misclassification, it is not automatically necessary to permanently add the sender to the allow list.
How to handle specific exceptions is explained under Sender Allow List: Allow senders in SpamExperts.
Train spam or block sender? #
When spam lands in the inbox, it initially seems obvious to add the sender address to the block list.
However, in typical spam campaigns, this is often not very effective. Sender addresses can change or be forged.
For a clearly misclassified spam message, targeted spam training is therefore often more sensible than continuously collecting individual spam addresses in a block list.
We will cover the blocking function separately under Sender Block List: Block senders in SpamExperts.
What happens after the workout? #
The training provides the filter system with additional information about a misclassified message.
However, you should not infer from this that a single training action guarantees that every future similar message will be treated in the exact same way.
Spam filters evaluate messages based on numerous characteristics. Senders, content, technical headers, routing paths, and other properties can differ between messages.
Briefly explained: Filter training is feedback to the filter system – not a rigid rule based on the principle „this type of email will always be blocked or allowed from now on.“.
Do I need to train many messages? #
No. SpamExperts should not be understood as a system that only becomes usable through constant manual training.
CURIAWEB recommends using training specifically for actual misclassifications.
If the spam filter works reliably during normal operation, there is no reason to submit messages regularly solely for the purpose of training.
A single spam email is no reason for global changes #
If a spam message does get past the filter, you shouldn't immediately tighten the general filter settings.
Likewise, a single legitimate message in quarantine should not cause the filter to be set globally less strictly.
The better approach is:
Detect misclassification
↓
Examine message
↓
Check Log Search
↓
specifically train as spam or ham
↓
monitor further development
Only when systematic problems occur repeatedly should it be investigated in more detail whether an additional measure is necessary.
Why does CURIAWEB recommend the default settings? #
SpamExperts is already pre-configured for professional use. The filtering mechanisms work together and evaluate numerous technical characteristics of a message.
Unnecessary changes to global filter values can therefore cause unwanted side effects – for example, more false positives or less effective spam detection.
CURIAWEB therefore generally recommends leaving default settings unchanged.
The available tools such as log search, quarantine, filter training, and targeted allow and block lists make it possible to handle specific cases without having to rebuild the entire filter configuration.
What to do when spam keeps getting through? #
If spam messages regularly get through the filter, you should document and examine some concrete examples.
Note or check in particular:
- Sender
- Recipient
- Date and time
- Subject
- Result in the Log Search
- whether the messages were actually delivered via SpamExperts
The last point is particularly important. If a message reaches the actual mail server directly and has bypassed SpamExperts, filter training cannot solve the underlying problem.
In such cases, the incoming configuration should be checked.
We explain what the correct communication channel looks like at Set up SpamExperts incoming filtering and configure MX records.
What to do with many legitimate messages in quarantine? #
Even here, you shouldn't change the filter settings immediately.
Check several specific messages about quarantine and log search. This makes it possible to determine whether there is actually a common pattern or whether they are different individual cases.
Document concrete examples for a recurring issue. That is much more helpful than a blanket statement like „SpamExperts blocks too much.“.
A known sender address is not automatically trustworthy #
Do not train a message as ham solely because the visible sender address looks familiar to you.
Email senders can be spoofed. Therefore, especially with unusual or security-relevant messages, check whether the content and context are actually plausible.
Attention: A phishing email can look like it comes from a well-known company, a business partner, or even your own domain. Never train suspicious messages as ham based solely on the displayed sender name.
Filter training does not replace SPF, DKIM, and DMARC #
Spam training and email authentication fulfill different tasks.
SPF, DKIM, and DMARC help with the technical authentication and evaluation of email senders and domains. Filter training, on the other hand, provides feedback to the spam filter on message classification.
Therefore, a spam or spoofing issue should not be addressed solely through training if the root cause lies in faulty email authentication.
When is an allow list more sensible? #
If a specific legitimate sender is repeatedly mistreated and the cause has been investigated, a targeted allow-list rule can make sense.
Even then, the following applies: Only allow as much as is actually necessary.
A single email should not result in an entire domain or a large sender range being unnecessarily exempted from the normal filtering decision.
When is a block list more useful? #
A block list can be useful if you want to specifically block a certain, clearly identifiable sender.
For large spam waves with constantly changing or forged sender addresses, however, manually blocking individual addresses is often unsuitable.
Recommended handling of misclassifications #
| Situation | Recommended initial measure |
|---|---|
| Spam was delivered | Check message and train as spam if necessary |
| Legitimate message detected as spam | Check log search/quarantine and train as ham if necessary |
| Specific legitimate sender repeatedly affected | Check cause and use targeted allow list if necessary |
| A specific sender is to be intentionally blocked | Check sender block list |
| Many different misclassifications | Collect examples and systematically investigate the cause |
| Single misclassification | Do not change global filter settings |
Summary #
SpamExperts basically works automatically and does not require permanent manual training.
Filter training is intended for specific misclassifications: An unrecognized spam message can be Spam and a legitimate message incorrectly treated as spam as Ham to be trained.
In case of problems, first examine the specific message and use log search and quarantine in particular for this purpose.
Training, approval, sender allow list, and sender block list are different tools and should be used specifically for their respective purposes.
CURIAWEB recommends leaving the general SpamExperts filter settings at their default values. A single misclassified message is no reason to change the global filter configuration.