User guide
Using VStream Antispam
530 Check Point Safe@Office User Guide
Header Marking
VStream Antispam adds the following headers to each email that is scanned by the Content
Based Antispam or Block List engine, but not blocked:
• X-VStream-Spam-Level. Contains an integer between 0 and 100, where
100 indicates the highest likelihood that the email is spam.
• X-VStream-Engine. The VStream Antispam engine, (either "Content Based
Antispam" or "Block List")
• X-Spam-Level. Contains one to five asterisks, where five asterisks indicates
the highest likelihood that the email is spam.
• X-Spam-Flag. Contains YES if the email is deemed to be spam, according to
the currently configured thresholds.
For example:
X-VStream-Spam-Level: 81%
X-VStream-Engine: Content Based Antispam
X-Spam-Level: ***
X-Spam-Flag: YES
If your email client allows defining rules based on message headers, you can create rules
specifying that emails with certain headers should be moved to specific folders. For
example, you can configure your email client to move all emails with the X-Spam-
Flag: YES header directly to a "Spam Email" folder.
Default Antispam Policy
The VStream Antispam default policy includes the following rules:
• All incoming SMTP connections are scanned, unless they originate from VPN.
This protects mail servers in your network.
• All outgoing POP3 connections are scanned. This protects mail clients in your
network.
You can easily override the default antispam policy, for example to exclude certain
addresses or networks from spam scanning, by creating user-defined rules. For further
information, see Configuring the VStream Antispam Policy on page 547.