Skip to main content

SpamAssassin in cPanel: Setting Up the Spam Filter

Hosting & cPanel · 29.09.2026

What Apache SpamAssassin Does in cPanel

Apache SpamAssassin is a filter that analyzes every incoming message against dozens of signals: sender IP reputation, the presence of SPF/DKIM, characteristic phrases, and links to known spam domains. Based on that analysis, each message gets a numeric score: the higher the number, the more it looks like spam.

The filter works at the mail server level, before a message reaches the inbox, and complements SPF, DKIM, and DMARC checks — those confirm the sender's authenticity, while SpamAssassin evaluates the content.

How to Enable SpamAssassin and Set a Threshold

Under "Email", open "Apache SpamAssassin" and click "Enable". By default, the trigger threshold is 5.0 points: messages with that score or higher are treated as spam. You can change the threshold in "Configure Apache SpamAssassin" → "required_score" — lowering it to 3.0-4.0 makes the filter stricter but raises the risk of false positives on legitimate mailings.

Changes apply to new messages right after saving; already received messages are not rescanned.

What to Do With Spam: Tagging or Moving

By default, SpamAssassin adds a ***SPAM*** tag to the message header and delivers it to the normal inbox — further filtering is then handled by a rule in the mailbox or the mail client. Turning on "Spam Box" in the same section moves tagged messages to a separate Spam folder on the server — that keeps the main inbox clean while letting you review suspicious messages before deleting them.

Automatic deletion of messages with a very high score is configured in "Auto-Delete Spam" with a separate threshold — usually 5-10 points above the base one, so only unambiguous spam gets deleted.

How to Read the SpamAssassin Score: Examples

ScoreTypical CauseFilter Action
0.0-2.9Message looks legitimateDelivered without a tag
3.0-4.9Some suspicious signals, but not criticalDelivered, worth watching
5.0-9.9No SPF/DKIM, spam phrases in the bodyTagged as ***SPAM***
10.0 and aboveObvious spam or phishingFalls under Auto-Delete if enabled

The full breakdown of a specific message's score is visible in the X-Spam-Status header — it lists every rule that fired along with its points.

False Positives: Whitelist and Blacklist

If a legitimate mailing keeps landing in spam, add the sender's address to "Configure Apache SpamAssassin" → "Whitelist" — this lowers its final score regardless of the message content. The opposite list, "Blacklist", forcibly tags messages from the listed addresses as spam regardless of their actual score.

Both lists are configured at the account level, not per mailbox: changes take effect immediately for every mailbox on the domain.

Summary: a Spam Filter Setup Checklist

  • Enable SpamAssassin and keep the 5.0 threshold unless you have a clear problem with spam getting through.
  • Enable Spam Box to separate regular mail from suspicious messages.
  • Configure Auto-Delete only for obvious spam — with a threshold noticeably above the base one.
  • Add trusted senders to the Whitelist instead of lowering the overall threshold.
  • Check the X-Spam-Status header in disputed cases, not just the fact of the tag.
← Back to Knowledge Base Ask Support