Configure spam filter in cPanel

Reading time approx.: 12 minutes

With the Spam filter In cPanel, you can have incoming emails automatically checked for typical spam characteristics. Suspicious messages receive a spam score, which can be used to identify them as spam and handle them accordingly.

In this guide, we will show you how to check and configure the spam filter in CURIAWEB, what the spam threshold means, and why you should use automatic message deletion settings with particular caution.

Important: No spam filter detects unwanted messages with one hundred percent certainty. Overly aggressive settings can lead to legitimate emails also being classified as spam.

How does the spam filter in cPanel work? #

The spam filter analyzes incoming messages based on numerous characteristics and assigns them a spam score.

Simply put:

The higher the spam score of a message, the more suspicious it is classified.

The configured threshold then determines from which value a message is considered spam.

This also means: the lower you set this threshold, the more aggressively the detection works.

Briefly explained: A lower threshold does not automatically mean a „better“ spam filter. It results in fewer weakly suspicious messages being classified as spam.

1. Open Spam Filters in cPanel #

Log in to your CURIAWEB cPanel.

Scroll to the section on the homepage Email and click on Spam filter.

Here you can check the status of the spam filter and manage the available settings.

2. Enable spam filter #

First, check whether automatic spam processing is enabled.

The corresponding setting ensures that new incoming messages are checked for spam characteristics.

If spam detection is disabled, incoming messages are not evaluated in the same way against the spam filter rules.

Recommendation: If you don't have a specific reason for disabling it, you should keep spam detection enabled.

3. Understanding spam threshold #

One of the most important settings is the spam threshold.

The spam filter calculates a spam score for a message. If this score reaches or exceeds the configured threshold, the message is classified accordingly as spam.

A threshold of, for example:

5

simply means that messages with a correspondingly high spam score are classified as spam.

The specific score of a message results from the results of various checks and should not be understood as a percentage value.

What happens with a lower threshold? #

If you lower the threshold, the detection becomes more aggressive.

A message then requires fewer spam features or a lower spam score to be classified as spam.

While this may capture additional unwanted messages, it simultaneously increases the risk of legitimate emails being incorrectly classified as spam.

What happens at a higher threshold? #

A higher threshold makes the spam classification less aggressive.

A message must stand out more as spam before it is classified as such.

While this reduces the risk of certain false positives, it can at the same time allow more unwanted messages to remain unmarked.

Basic rule: Do not change the spam threshold just because individual spam messages get through. First, observe whether there is actually a systematic problem.

What are false positives? #

As False Positive is referred to as a legitimate message that is incorrectly classified as spam by the spam filter.

This can concern, for example, a real customer inquiry, order, invoice, or message from a business partner.

For business email accounts, false positives are particularly problematic because an important message could be missed as a result.

Important: With a business mailbox, it is often better to manually remove an unwanted message occasionally than to lose important customer emails due to overly aggressive configuration.

4. Check current threshold #

Open the spam threshold configuration in the spam filter settings.

First, check the currently set value before you change anything.

If the spam detection is working satisfactorily overall, there is usually no reason to change the value as a precaution.

5. Adjust threshold only gradually #

If indeed too many clearly unwanted messages are not recognized as spam, you can carefully adjust the threshold.

Do not change it in giant leaps.

After a change, observe over an appropriate period of time which messages are additionally classified as spam.

Practical Tip: Always change only one relevant setting at a time. Otherwise, it will be hard to determine later which change actually influenced the spam filter's behavior.

6. Use Spam Box #

Depending on the configuration, cPanel provides a Spam folder available.

When this feature is enabled, messages recognized as spam can be stored in a separate spam folder instead of appearing in the inbox like normal messages.

This has an important advantage: the message is still there and can be checked.

If a legitimate email was accidentally classified as spam, you can still find it this way.

Why the spam box is useful for business mailboxes #

For business email accounts, a verifiable spam folder is much safer than the immediate automatic deletion of suspicious messages.

You can check the spam folder regularly and thus also recognize if the selected threshold might be set too aggressively.

Recommendation: If you can choose between „store spam in a separate folder“ and „delete spam immediately,“ the spam box is initially the safer option.

Spam folder not visible in email program #

If the spam box is enabled but the corresponding folder does not appear in your email program, this may be due to the folder display or the subscribed IMAP folders of the mail program.

In this case, first check via webmail whether the spam folder is there.

If the folder is visible in webmail but not in the local mail client, the problem is likely related to the folder display or IMAP configuration of the program being used rather than the spam filter itself.

7. Check spam folder regularly #

A spam folder should not be completely ignored.

Check it regularly for legitimate messages, especially after changes to the threshold.

If you repeatedly find desired emails in your spam folder, you should investigate why these messages are being evaluated that way before making the filter even more aggressive.

8. Understanding automatic spam deletion #

Depending on the configuration, cPanel can provide a feature to automatic deletion of offering messages that reach a defined spam score.

That sounds convenient, but carries a much greater risk than the spam box.

If a legitimate message is falsely caught by the filter and automatically deleted, you cannot simply look for it in the spam folder.

Attention: Automatic deletion should only be used with great caution. For business-critical mailboxes, a verifiable spam quarantine is usually the safer solution.

Distinguish spam threshold and delete threshold #

If cPanel offers separate settings for spam classification and automatic deletion, you should not confuse them with each other.

For example, a message can be recognized as spam and moved to a spam folder without having to be automatically deleted.

A separate or stricter threshold can be used for automatic deletion.

As a result, only messages with a particularly unambiguous rating can be considered for automatic deletion.

Why the same aggressive deletion value is risky #

If you already have every message classified as spam automatically deleted, you are missing a security level.

A false positive is then not merely moved to another folder, but can be removed immediately.

Therefore, especially right after changing the spam threshold, you shouldn't configure aggressive automatic deletion at the same time.

9. Only activate automatic deletion intentionally #

If you still want to use the function, first check the current spam detection over a longer period of time.

Check in particular which scores legitimate messages receive and whether false positives occur.

Only when you know the behavior well enough should you consider an automatic deletion rule.

Practical Tip: A spam message in the folder is annoying. An automatically deleted customer inquiry can be relevant to the business. Adjust the configuration accordingly with care.

10. Open advanced spam filter settings #

cPanel can additionally provide an area for advanced configurations provide the spam filter.

Depending on the server configuration, additional functions may be available there, such as lists for specific senders or domains.

Change advanced settings only if you understand their purpose.

Use allow list #

Via a Allow List or corresponding approval rules can treat certain senders in such a way that they are given special consideration during spam classification.

This can be helpful in certain situations, but should not be used carelessly for entire domains.

A very broadly worded approval can reduce the spam filter's protection for the sender domains in question.

Safety: A visible sender address is not a secure proof of identity. Email senders can be spoofed. Therefore, use allowlists as selectively as possible and not as a blanket rule of trust for large sender domains.

Use block list #

With a Block List or corresponding blocking rules, certain senders can be treated more strongly as unwanted.

This can be helpful in the case of recurring unwanted messages from a clearly identified source.

Here too, you should formulate rules as precisely as possible.

Blocking an entire domain can also affect legitimate senders from that domain, for example.

Why Sender Blocklists Do Not Completely Solve Spam #

Professional or automated spam does not always originate from the same visible sender address.

Senders can constantly change or be forged.

Therefore, an ever-growing list of individual spam addresses is not a complete alternative to actual spam detection.

Blocklists are more suitable for clearly defined, recurring cases.

Differentiate between spam filters and regular email filters #

The spam filter evaluates messages based on spam characteristics.

Normal email filters, on the other hand, execute rules defined by you.

With a normal filter, for example, you could move messages with a specific subject into a folder.

We show you how to create such rules at Create and manage email filters in cPanel.

Differentiate between spam filter and global email filters #

Global email filters are also rule-based and can operate at the cPanel account level.

They are therefore not the same thing as the actual spam detection.

We explain how global rules work at Using Global Email Filters in cPanel.

Why a simple subject filter is not a good spam filter #

A rule like:

Subject contains "Gewinn" → delete

can capture certain unwanted messages, but can also hit legitimate emails.

Spam detection takes significantly more signals into account than a single word.

Therefore, use normal email filters for specific organizational rules and the spam filter for actual spam classification.

A legitimate email ends up in the spam folder #

If an expected message has been classified as spam, you should first check whether it is an isolated incident or a recurring pattern.

If possible, check the spam rating or the technical headers of the message.

If numerous legitimate messages are classified as spam, the threshold may be set too aggressively.

Do not change it based on a single message without further review.

Many spam emails continue to land in the inbox #

If numerous obvious spam messages are not detected, first check whether spam detection is even enabled.

Then check the current threshold.

If an adjustment is necessary, carefully reduce the value and then observe the effects.

Avoid extreme changes, as these can significantly increase the risk of false positives.

Spam filter only works on incoming messages #

The spam filter described here serves to detect unwanted incoming emails.

If your own outgoing messages end up in recipients' spam folders, that is a different problem.

In this case, you should check your domain's authentication and deliverability, among other things.

We show how this works at Check email deliverability in cPanel.

Important: Setting the spam filter more aggressively does not improve the deliverability of your outbound emails.

Spam filter and SPF, DKIM or DMARC #

SPF, DKIM, and DMARC are also not the same as the spam filter.

These methods serve for email authentication or for evaluating whether domains and sending paths technically match.

A message can pass SPF and DKIM successfully and still be spam.

Conversely, a legitimate message can cause delivery issues due to faulty authentication.

Catch-all can increase the volume of spam #

If a catch-all address is set up for your domain, messages sent to non-existent recipient names can also be accepted or processed further.

This can result in significantly more unwanted email traffic.

Before setting the spam filter increasingly aggressively during high spam volume, you should therefore check whether a catch-all is active and is actually needed.

We explain the configuration at Default Address in cPanel: Catch-All and Unknown Recipients.

Spam messages to random addresses of your domain #

If you send spam to addresses like:

abc123@deine-domain.ch

or:

zufallsname@deine-domain.ch

receive, even though these addresses were never set up, you should also check the default address or catch-all configuration.

A spam filter can evaluate unwanted messages, but an unnecessarily active catch-all configuration increases the email traffic to be processed beforehand.

Test spam filter after a change #

A change to the spam filter cannot be meaningfully tested by sending yourself a message with the subject Spam you send.

The spam score is based on several technical and content-related characteristics.

Instead, observe the actual incoming messages after making an adjustment and check the spam folder in particular for false positives.

Do not change multiple settings at once #

If you simultaneously reduce the spam threshold, enable automatic deletion, and add multiple list rules, it will be hard to trace later which setting caused an issue.

Therefore, change as few relevant parameters as possible and observe their effect.

Practical Tip: Document major changes to the spam filter. If legitimate messages are missing a few days later, this will make it easier for you to trace what was changed.

An expected email did not arrive at all #

If a message appears neither in the inbox nor in the spam folder, you should not automatically assume that the spam filter has removed it.

Check first whether automatic deletion is enabled and whether other email filters are present.

You can then use cPanel delivery tracing to examine how the mail server processed the message in question.

We show the procedure at Track email delivery in cPanel.

Mailbox is full – that is not a spam filter problem #

Delivery issues can occur when an email account has reached its storage limit.

Changing the spam threshold does not fix a full mailbox.

If error messages indicate a quota or missing storage space, you should check the account's storage consumption instead.

We show how this works at Check and clean up email storage in cPanel.

Recommended procedure for too much spam #

If you suddenly receive significantly more spam, proceed systematically.

  1. Check if the spam filter is enabled.
  2. Check the current spam threshold.
  3. Check whether a catch-all address unnecessarily accepts additional mail traffic.
  4. Check which messages are actually not recognized.
  5. Adjust the threshold only as needed and gradually.
  6. Use the spam box first instead of an aggressive automatic deletion.
  7. Then regularly check for false positives.

Recommended procedure for false positives #

If legitimate messages end up in the spam folder, you shouldn't immediately change several settings either.

First, check whether specific senders or message types are repeatedly affected.

Check the spam threshold and existing advanced rules.

If the threshold was set very aggressively previously, a cautious correction can be useful.

Depending on the cause, a targeted rule may be more sensible for an individual sender than a global relaxation of spam detection.

When should you contact support? #

If you cannot understand the behavior of the spam filter, you should not just use increasingly aggressive settings on a hunch.

Concrete examples are particularly helpful for an analysis.

If possible, have the following information ready:

  • affected email account
  • approximate date and time
  • Sender address
  • whether the message appears in the inbox, the spam folder, or not at all
  • whether the spam threshold has been changed
  • whether automatic deletion is enabled

For a specific message, the complete mail headers can also be helpful for the analysis.

The secure basic configuration #

For normal business mailboxes, a conservative approach makes sense.

Keep spam detection enabled, only change the threshold if a specific issue arises, and use a spam box first if possible so that misclassified messages remain reviewable.

You should only use automatic deletion once you know how the spam detection behaves and consciously accept the risk.

Basic rule: A good spam filter should detect as much unwanted mail as possible without letting important messages disappear. The most aggressive setting is therefore not automatically the best setting.

Summary #

You can find the spam filter in your CURIAWEB cPanel under Email -> Spam filter.

First, check if spam detection is enabled. The spam threshold determines the spam score at which a message is classified as spam. A lower value works more aggressively, but at the same time increases the risk of false positives.

For business mailboxes, it makes sense to first keep suspicious messages separately in a spam box instead of automatically deleting them immediately.

Use allowlists and blocklists purposefully and do not change multiple spam filter settings at the same time. If too much spam gets through, adjust the threshold only gradually and then check regularly whether legitimate messages are affected.

If an expected message is completely missing, also use delivery tracking. If, on the other hand, your own outgoing messages end up in spam at other providers, you should not change the incoming spam filter, but instead investigate the email deliverability of your domain.

Last updated August 28, 2026
Was this article helpful?
Cookie Consent with Real Cookie Banner