Please don't hijack existing threads.
On Wed, 4 Nov 2020 21:47:34 +0700 Victor Sudakov wrote: > Dear Colleagues, > > Why does SpamAssassin (Debian 10, SpamAssassin 3.4.2) not count an SPF > check fail as a symptom of spam? That's what I see in the spam > report: > > 0.0 SPF_FAIL SPF: sender does not match SPF record > (fail) > > No spam points for an SPF fail? And it's even a hard fail (a "-all") > in this case. > > I can probably bump up the score for SPF_FAIL but would like to know > first why it is a 0.0 by default. This was probably someone's > well-grounded decision? It was probably set a long time ago when the situation was worse, but even now it doesn't do well in QA: https://ruleqa.spamassassin.org/20201031-r1883012-n/SPF_FAIL/detail With an S/O of 0.651 it's barely a spam indicator on its own. If you look at the score map it's hitting a lot of ham that's not far below the threshold (at least in score set 0).