Spam and phishing protection in MailGuard
Multi-stage spam filter and phishing protection with scoring, Bayes, RBL checks, SPF, DKIM, DMARC as well as link protection and URL rewriting at the gateway.
Spam and phishing protection scores every incoming message through several check layers and combines the result into one score. Suspicious mail is flagged or blocked without losing legitimate mail.
Multi-stage detection
Several methods complement each other so that individual weaknesses do not get through. Only what is needed has to be switched on.
- Bayes filter for statistical content scoring.
- Heuristics for conspicuous patterns in structure and headers.
- RBL checks against known sending sources.
- Link reputation against known malicious sites.
- Sender authentication with SPF, DKIM, DMARC and ARC.

Thresholds and actions of the spam filter per policy.
Thresholds and scoring
Two thresholds govern the reaction. From the mark score an email counts as suspicious and is flagged, for instance through a subject prefix, a header or a redirect. From the block score it is blocked. Instead of flagging, a marked message can be set to go straight into quarantine. Details on the quarantine page.
The scale runs from 0 to 100. The mark score is always set, the block score may stay empty, in which case nothing is blocked on the score alone. There are two switches for flagging: the header X-Conbool-Flag: YES and the subject prefix. The default is [SPAM], the text is freely selectable. If a rule explicitly triggers the mark action, both are set regardless of the switches.
A new policy starts with mark score 5 and no block score. Three templates are available when creating one, and their values stay freely adjustable afterwards.
- Basic marks from 8 and does not block based on the score. Deliberately quiet, with a lenient reading of sender authentication.
- Balanced marks from 5, blocks from 15, switches quarantine on and adds 3 points for newsletters and bulk mail.
- Strict marks from 3, blocks from 10 and puts marked messages straight into quarantine instead of flagging them. Conspicuous headers, suspicious links and encrypted attachments that cannot be checked also go into quarantine.
The numbers are a starting point, not a law of nature. The path to fitting values leads through audit mode: observe first, then adjust on the basis of real messages.

Policies govern scoring and action per mail flow.
Custom rules and dictionaries
Besides the standard checks, custom word lists and regex rules can be stored. Dictionaries bundle terms for content rules and are then available in every policy. The scope of a rule covers subject, body and attachments as chosen.

Additional checks with custom word lists and regex rules.
Phishing and link protection
Against phishing, link protection checks every URL in a message. Three modes are available: monitor only flags, rewrite rewrites every URL through a safe link address, block rejects the email on malicious links. With checking at click time enabled, target, redirects and reputation are evaluated again, even when a link is only redirected to a malicious site after delivery. Suspicious links can be defused and tracking parameters removed.
Header protection detects reply-to deviations, mismatched From and Reply-To domains, display name spoofing and homograph domains. For authentication the presets spec compliant, balanced and lenient are available.
Further reading
Sender-side forgery is additionally contained through DMARC, SPF and DKIM. The IP and sender filter complements it, as does the overview under MailGuard and the solution pages spam filter for businesses and phishing protection.