Back to documentation

Checks & threat data

Check modules

Spamexx scores every mail with several modules. Platform admins enable/disable them under Settings → Check modules (live, no restart):

Check modules with on/off toggles per module and the failure-behavior setting.
  • Virus check – scans every message incl. attachments for malware
  • Spam content check – rule- and learning-based content scoring
  • Header heuristics – anomalies in the headers
  • IP reputation – sender IP checked against reputation blocklists
  • In-house threat data – cross-domain spam detection
  • VirusTotal – optional second opinion (add-on)

Behavior on failure

Via checker_fail_mode (Settings → External) you define what happens when an active module is unreachable:

  • closed (default) – hold the mail with 451; the sender retries, never unchecked.
  • virus – hold only if the virus module fails.
  • open – skip and deliver anyway.