Email Spam Filtering: A Complete Guide to Layered Protection

·

Email Spam Filtering: A Complete Guide to Layered Protection

No single spam filter catches everything. Spammers rotate IP addresses, register fresh domains, hide links behind shorteners, and write convincing text with AI. A filter that relies on one technique will, thus far, always miss some of it.

The answer is layers. This guide walks mail administrators through each layer of email spam filtering, in the order your mail server should apply them, so you stop the most spam for the least effort and keep legitimate mail flowing.

Why spam filtering still matters

Spam is not shrinking. Kaspersky found that spam made up 44.99% of global email traffic in 2025. Much of it is harmless advertising, but the same channel carries phishing, malware, and fraud.

For mail operators, every unwanted message costs something: bandwidth, CPU, storage, support time and, when something gets through, user trust. Good email filtering keeps those costs down.

How spam filters decide

Modern spam filtering looks at several signals, not just the words in a message:

  • Connection: the reputation of the sending IP address, and how the sending server behaves.
  • Authentication: whether SPF, DKIM, and DMARC confirm the sender is allowed to send for the domain.
  • Content: the domains, links, attachments, and text inside the message.
  • Behavior: sending volumes, patterns over time, and complaints from recipients.

Each signal can trigger a decision: accept, reject, quarantine, or send to the spam folder. The earlier you make that decision, the less the message costs you.

The layers of spam filtering, in order

1. Connection rate limits

Your first filter is how many connections you accept. Rate limits protect your server from spam floods and denial-of-service attacks. 

Set limits for total connections, simultaneous connections, and connection rate per client. Base them on your hardware and normal daily load, and start conservatively: most legitimate senders don’t need many parallel connections. Refine the numbers over time. The Postfix tuning guide is a good starting point.

2. Relay settings

A misconfigured mail server can become an open relay, forwarding spam for anyone who connects. Only allow relaying from authenticated users and from your own networks, and test your configuration from outside your network.

3. Real-time DNS blocklists (DNSBLs)

DNSBLs let your server check the reputation of a connecting IP address with a quick DNS query before the message is even transferred. This is where most spam should stop.

  • Use a complete suite from one trusted provider. Blocklist suites are designed so their lists work together. Mixing parts of different suites leaves gaps.
  • Inbound IP lists: reject connections from IP addresses known for spam, from infected hosts, and from addresses that should never send mail directly, such as home broadband ranges. Many providers offer these as a single combined list.
  • Logins and outbound mail: use a separate list designed for authentication, with short listing times, to spot compromised accounts logging in to send. Don’t reuse your inbound list for this.
  • Domain and URL lists: check the domains and links inside messages. This catches spam from shared IP addresses that also send legitimate mail.

Abusix Mail (formerly known as Guardian Mail) provides all of these lists. Here’s how each Abusix blocklist works.

4. Local blocklists and allowlists

Turn on your mail server’s local blocklists, so your team can block a spammer or phishing domain immediately while you investigate. Keep a short local allowlist for critical partners, and review both regularly so they don’t go stale.

5. Email authentication

Check SPF, DKIM and DMARC on every inbound message, and respect the sender’s DMARC policy. This stops most spoofing of known brands and of your own domain. You can read our guide to SPF, DKIM, DMARC and BIMI here.

6. Content filtering

Content filters such as rspamd or SpamAssassin score what gets through the earlier layers. 

They look at:

  • Message structure and headers.
  • Links, including shortened and redirected URLs.
  • Attachments, scanned for malware. Treat password-protected archives with caution.
  • Text patterns, using rules and machine learning.

Content filtering costs the most CPU per message, which is why it comes last. The fewer messages that reach it, the better it performs.

7. User feedback

Give users a “This is spam” button, and use those reports to retrain your filters and alert the networks that sent the mail. You can learn how feedback loops work here.

Example: adding a DNSBL check to Postfix

Here’s what layer 3 looks like on a Postfix server using Abusix Mail. 

In /etc/postfix/main.cf, add the blocklist checks to smtpd_recipient_restrictions, after reject_unauth_destination:

smtpd_recipient_restrictions =
    …
    reject_unauth_destination
    permit_dnswl_client <APIKEY>.white.mail.abusix.zone
    reject_rbl_client <APIKEY>.combined.mail.abusix.zone
    reject_rhsbl_sender <APIKEY>.dblack.mail.abusix.zone

The welcome list check comes first, so trusted senders are never rejected. The combined list then rejects listed IP addresses, and the domain list rejects listed sender domains. 

Replace <APIKEY> with the key from your Abusix account, use a reply map so the key never appears in rejection messages, and reload Postfix.

If you use Postscreen, add the combined list to postscreen_dnsbl_sites instead. See the full Postfix setup guide, and the guides for Exim, Exchange, rspamd and other platforms in our documentation.

Where to run your filtering

You can apply these layers in three places, and many operators combine them:

  • On your own mail servers: full control and the lowest cost per message. Best for ISPs, hosting providers and anyone running Postfix, Exim or Exchange at scale.
  • On an email security gateway: a dedicated appliance or virtual machine in front of your mail servers. Most gateways can query external DNSBLs, so you can add specialist blocklists to their built-in filtering.
  • In a cloud filtering service: mail passes through the provider before reaching you. Simple to run, but you depend on the provider’s data and settings.

Whichever you choose, check that it supports every layer in this guide, especially connection-time blocklists and outbound filtering.

Keep false positives low

A filter that blocks legitimate mail does as much damage as one that lets spam through. To keep false positives low:

  • Reject only on strong signals, such as reliable IP blocklists and DMARC reject policies. Score weaker signals instead of rejecting on them.
  • Use clear rejection messages that tell the sender why their mail was refused and how to fix it.
  • Review your quarantine regularly, and track how many legitimate messages end up there.
  • Allowlist carefully, and only after checking that the sender is genuine.

Filter outbound mail too

Spam leaving your network damages your IP reputation and causes your users’ legitimate mail to be blocked elsewhere. Apply the same layers to outgoing mail, with rules tuned for your own users, and act quickly on compromised accounts. Here’s how to check if your server is sending spam.

Keep your filtering healthy

Spam filtering is not set-and-forget. Build these habits into your routine:

  • Patch and update your mail server, filter software, and rules.
  • Monitor your logs for rising rejection rates, queue growth, and unusual sending.
  • Check performance: CPU, memory and disk on your mail servers. Rising load can mean a spam wave is getting further down your filtering stack than it should.
  • Remove dead blocklists. Lists that have shut down, such as SORBS, introduce delays to every connection and return stale results.
  • Write it down. An email security policy that covers filtering, acceptable use, and incident response keeps your team consistent.

Email spam filtering checklist

  1. Set conservative connection rate limits.
  2. Lock down relaying.
  3. Query a complete DNSBL suite at connection time.
  4. Turn on local blocklists and keep a short allowlist.
  5. Check SPF, DKIM, and DMARC.
  6. Score the rest with a content filter.
  7. Feed user reports back into your filtering.
  8. Filter outbound mail, and review false positives regularly.

Stop most spam at the edge

The earlier you stop spam, the less it costs you. Abusix Mail gives your mail servers real-time IP, domain, and URL blocklists that work with Postfix, Exim, Exchange, rspamd, SpamAssassin, and most email security gateways. See how Abusix Mail works.

Read More

·

Email remains a cornerstone of business communication but also a primary vector for cyber threats like spam, phishing, malware, and...

·

Blocklists remain one of the most effective controls in email security. They stop bad traffic early, reduce system load, and...

·

Email can be the lifeline of a business – a way to communicate with your customers and advertise your products...