No BAYES probability headers in the spam report

georgy.goshin

Member
Sep 27, 2021
23
0
6
48
Hi

Running 7th Mail Gateway, just installed. Do not see the BAYES headers in the message, only rules

X-SPAM-LEVEL: Spam detection results: 4
KAM_DMARC_NONE 0.25 DKIM has Failed or SPF has failed on the message and the domain has no DMARC policy
KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment
KAM_SHORT 0.001 Use of a URL Shortener for very short URL
RCVD_IN_HOSTKARMA_BL 1.5 Sender listed in HOSTKARMA-BLACK
RCVD_IN_MSPIKE_H4 0.001 Very Good reputation (+4)
RCVD_IN_MSPIKE_WL 0.001 Mailspike good senders
SHORT_SHORTNER 1.999 Short body with little more than a link to a shortener
SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record
SPF_SOFTFAIL 0.972 SPF: sender does not match SPF record (softfail)


Use bayesian filter is set to Yes.

Where to look for?

Thanks,
G.
 
Which logs should I take?

t 18 11:16:17 spam03 pmg-smtp-filter[211799]: 141E8B616D2D50D64DD: SA score=0/5 time=0.858 bayes=undefined autolearn=ham autolearn_force=no hits=HTML_IMAGE_RATIO_08(0.001),HTML_MESSAGE(0.001),KAM_DMARC_STATUS(0.01),SPF_HELO_NONE(0.001),SPF_PASS(-0.001)
Oct 18 11:16:43 spam03 pmg-smtp-filter[211656]: 141E8B616D2D6A93F33: SA score=0/5 time=0.867 bayes=undefined autolearn=no autolearn_force=no hits=HTML_MESSAGE(0.001),KAM_DMARC_STATUS(0.01),PROLO_LEO3(0.1),RCVD_IN_DNSWL_NONE(-0.0001),SPF_HELO_NONE(0.001),SPF_PASS(-0.001)
Oct 18 11:16:55 spam03 pmg-smtp-filter[211805]: 141E8B616D2D767307B: SA score=0/5 time=0.812 bayes=undefined autolearn=ham autolearn_force=no hits=AWL(0.206),HTML_MESSAGE(0.001),KAM_DMARC_STATUS(0.01),KAM_NUMSUBJECT(0.5),RCVD_IN_DNSWL_MED(-2.3),SPF_HELO_NONE(0.001),SPF_PASS(-0.001)

Here are the lines from mail.log
 
root@spam03:/var/log# sa-learn --dump magic
0.000 0 3 0 non-token data: bayes db version
0.000 0 4 0 non-token data: nspam
0.000 0 783 0 non-token data: nham
0.000 0 76795 0 non-token data: ntokens
0.000 0 1634542105 0 non-token data: oldest atime
0.000 0 1634553021 0 non-token data: newest atime
0.000 0 1634553024 0 non-token data: last journal sync atime
0.000 0 0 0 non-token data: last expiry atime
0.000 0 0 0 non-token data: last expire atime delta
0.000 0 0 0 non-token data: last expire reduction count

seems that my database us underlearned, isn't it?