I'm trying to get SA to do better manual training to make it better.
We have autolearn turned on but some Spam gets through with low BAYES values and having clearly been incorrectly learnt in the past. Server-wide, we can only look at the maillog so not sure how, if we find a pattern of emails that are definitely Spam, we can put the offending email into a Spam folder. I have one of our own widely known email addresses that gets a fair bit. I have put Spam into the Spam email. Can I run the following command: sa-learn /var/qmail/mailnames/hosted-domain.com/user-1/Maildir/.Spam/cur and if so will that determine all those emails as Spam server-wide for the learning. The pattern for almost every one is the same with a remote image and a fake US address at the bottom. In local.cf we have put: score URIBL_BLACK (1.5) which I understand will add a score of 1.5 to the SA default for that rule. Is that right? Because some Spam is still coming where that rule applies so I am tempted to make it +5, and then monitor carefully to see if any genuine emails get deleted as Spam which would not be great. I can only ever think that it would be an email from us to people like you that would ever have a blacklisted URL mentioned! Kind Regards, Christoph