On Sat, 12 Dec 2015, Sebastian Arcus wrote:

One of my servers received a spam message which SA missed, with the following report:

-0.4 AWL AWL: Adjusted score from AWL reputation of From: address

After learning the messages as spam into bayes with sa-learn, I get the following report:

-6.1 AWL AWL: Adjusted score from AWL reputation of From: address


Luckily the message is now flagged as spam because I have manually turned up the score on my BAYES_99 and BAYES_999 awhile ago. But what intrigues me is that now the AWL module gives it a -6.1 score. Why would AWL now tilt things heavily towards ham, after the message has just been learned as spam? It seems to be making things worse instead of better. Unless I am misunderstanding what AWL is supposed to be doing?

You are. The name is misleading. AWL is more a score averager than a whitelist. It's intended to allow for the occasionally spammy-looking email from a historically hammy sender (and vice versa).

It has nothing to do with training, which only affect Bayes.

Messages from that sender will get negative AWL scores for a while until their traffic history becomes more on the "spam" side.

A lot of people just turn AWL off, or use a newer replacement called txrep.

I think there's a way to wipe the AWL history for a given sender; I don't recall what it is off the top of my head, though.

--
 John Hardin KA7OHZ                    http://www.impsec.org/~jhardin/
 jhar...@impsec.org    FALaholic #11174     pgpk -a jhar...@impsec.org
 key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C  AF76 D822 E6E6 B873 2E79
-----------------------------------------------------------------------
  When fascism comes to America, it will be wrapped in
  "Diversity" and demanding "Safe Spaces."             -- Mona Charen
-----------------------------------------------------------------------
 3 days until Bill of Rights day

Reply via email to