SpamAssassin Score Breakdown: How Points Are Assigned in 2026
Understand how SpamAssassin assigns points to emails. Learn what each rule means and how to improve your deliverability with real-world insights — no.
Why Your Email Score Matters More Than You Think
You send a campaign. It lands in the spam folder. Or worse, it doesn’t land at all. You check the logs. The report says: “SpamAssassin score: 6.2.” You shrug. “It’s just a number.” But that number isn’t just a score — it’s a verdict.
SpamAssassin doesn’t guess. It weighs every signal in your email — headers, content, sending behavior — and assigns points. A score above 5 doesn’t just flag your message. It often leads to outright rejection by mail servers. Even if your content is harmless, your sender reputation, DNS setup, or a single misconfigured header can push you over the line.
Understanding the SpamAssassin score breakdown — how points are assigned, what triggers them, and why a single rule can sink your deliverability — isn’t optional. It’s how you stop losing deliverability in silence. This guide walks through each scoring rule, so you know exactly which levers to adjust before your next campaign fails to land.
Key takeaways
- SpamAssassin scores above 5 typically trigger spam filtering or rejection, even for legitimate messages.
- Points are assigned based on detectable patterns in headers, content, and sending behavior — not subjective judgment.
- Knowing the exact points assigned allows you to proactively fix issues like missing SPF, poor alignment, or misleading subject lines before they impact inbox placement.
What Is SpamAssassin, and Why Does It Still Matter in 2026?
SpamAssassin is a mature, open-source email filtering system used by major mail providers and hosting platforms to score and flag suspicious messages. It assigns points based on patterns in headers, content, and structure—commonly used as a baseline risk indicator, even when not the final decision engine. Its rule set remains relevant because it’s transparent, well-documented, and widely adopted in the email ecosystem.
How SpamAssassin Scores Work
SpamAssassin evaluates each email against hundreds of rules that detect known spam signals. A message gets points for things like suspicious link domains, excessive capitalization, or missing or malformed headers. If the total score crosses a threshold—usually 5 or 10—it’s marked as spam. The scoring system is designed to be modular: rules can be enabled, disabled, or weighted based on local policy.
You’ll see SpAMAssassin scores show up in logs from senders using older or self-hosted mail servers, but even modern platforms like cPanel and Zimbra use its rules as part of their filtering stack. The system is not perfect—false positives happen—but because its rule database is public and regularly updated, it remains a trusted reference point across the industry.
Why It Still Matters in 2026
Even with machine learning models now handling much of the real-time spam detection, SpamAssassin’s scoring system persists as a benchmark. Many ISPs and email providers still use it internally or reference its scores in their own systems. For instance, a report from the Messaging, Malware, and Mobile Anti-Abuse Working Group (M3AAWG) highlights how traditional rule sets like SpamAssassin’s still complement algorithmic filtering in real-world deployments.
Let’s be clear: SpamAssassin isn’t the final gatekeeper anymore. But its score still provides meaningful insight into how likely a message is to be flagged by a broader spam detection infrastructure. That makes understanding its point breakdown essential for anyone managing outbound email at scale. Tools like MailTester’s bulk verification check for issues like misconfigured headers and known spam triggers that would spike a SpamAssassin score—even before a message ever leaves your server.
It’s not about replacing modern systems. It’s about knowing what drives them. By checking your email’s structure and content against SpamAssassin’s standards, you reduce the risk of being labeled suspicious—no matter what the final filter says.
How SpamAssassin Points Are Assigned: The Core Mechanism
SpamAssassin assigns points to emails based on how closely they match known spam patterns. Each rule evaluates specific red flags—like odd headers, hidden links, or known spam domains—and adds points accordingly. A score above 5 typically means the email is flagged as spam. The system uses a weighted mix of header, body, network, and DNS checks to build this total.
Rules Evaluated Across Multiple Dimensions
SpamAssassin doesn’t rely on a single signal. Instead, it checks dozens of factors across different layers of an email. Header rules look for anomalies like mismatched From/Reply-To addresses or suspicious Date formats. Body rules scan for phrases like “act now” or “free money,” which are common in spam. These checks are backed by real-world data—SpamAssassin’s rule set is regularly updated based on feedback from the global email community and tools like the SpamAssassin project itself (Apache SpamAssassin).
Network and DNS-based rules examine the sender’s IP reputation, domain age, and whether the sending server is listed on public blocklists. If an IP is recently added to a blocklist like Spamhaus, it can spike the score fast. Similarly, domain-level checks look for newly registered domains (often used in spam campaigns) or poor DNS records like missing SPF or DKIM—key indicators of spoofing.
Scoring Is Cumulative and Weighted
Every rule has a point value tied to the strength of the signal. For example, “HTML-only message” might earn 2.5 points, while a hit on a known spammer’s IP could add 6.0. The higher the value, the more confident SpamAssassin is in the match. These points stack—not every rule applies to every email, which means some messages get flagged quickly; others only reach the threshold after accumulating multiple mild flags.
Understanding this breakdown helps you spot weak spots in your email campaign. If your sent messages consistently score above 5, you’re likely triggering multiple low-weight rules—like odd formatting or excessive links—with few high-value warnings. That’s where tools like inbox placement testing or real-time verification help you identify invalid or risky addresses before they hurt your sender reputation.
While SpamAssassin is widely used, it’s not infallible. False positives happen, especially if a domain is new or has a complex layout. The best defense? Clean data, consistent authentication (SPF/DKIM/DMARC), and pre-sending validation. With MailTester, you can verify your list at scale before sending, cutting out junk addresses and reducing risk even before the email hits the first server.
SpamAssassin Score Breakdown: How Points Are Assigned
SpamAssassin assigns points to incoming emails by applying a dynamic set of rules that evaluate headers, content, and network signals. Each rule has a predefined weight—ranging from 0.1 to over 5.0—based on how strongly it correlates with spam. The total score determines whether an email gets flagged, rerouted, or delivered. You can test how your messages might score by simulating inbound filtering with real-world standards.
Rules Are Weighted by Impact and Reliability
SpamAssassin doesn’t treat all red flags equally. A rule that detects a known spammer’s IP might add 5.0 points, while one flagging a single capital letter in the subject line may only add 0.1. These weights reflect how reliably a signal predicts spam in practice. Higher-weight rules usually stem from persistent patterns seen in malicious campaigns, while low-weight ones act as subtle indicators.
Categories of Rules Shape the Final Score
Rules are organized into groups that reflect the part of the email they analyze. Header anomalies—like missing or malformed Date: fields, unusual From: formats, or repeated sender domains—trigger points when they deviate from common sender practices. Content triggers include excessive use of all-caps text, suspicious punctuation (like multiple exclamation points), or repeated spammy keywords. Network-based signals come from real-time checks: if the sending IP is listed on a known blocklist (like Spamhaus), or if the domain has a poor reputation, the system adds points rapidly.
These rule categories don’t work in isolation. A message with a strange From: header, a link to a blacklisted IP, and all-caps promotional text can accumulate a score above the typical spam threshold—commonly set at 5.0. Once that threshold is crossed, the email is rejected, quarantined, or labeled as spam, depending on the recipient’s filtering policy.
Understanding how these weights accumulate helps you avoid unintentional spam flagging. For example, using a clean sender domain, validating your SPF/DKIM/DMARC records, and avoiding excessive promotional language reduces your likelihood of hitting high-scoring triggers. You can test how well your messages would perform in modern spam filters using real inbox placement tools—like the one at MailTester’s Inbox Placement Tester, which simulates delivery through major email providers.
SpamAssassin’s rule system is open-source and maintained by a global community of contributors. You can explore the official rule definitions at the Apache SpamAssassin GitHub repository, where each rule’s logic and point value are documented transparently.
Common SpamAssassin Rules and What They Mean
SpamAssassin assigns points to emails based on specific triggers in content, headers, and sender reputation. A score above 5.0 typically means spam; below 5.0 means likely legitimate. Understanding these rules helps you interpret why an email was flagged and how to fix deliverability issues. Let’s break down the most common ones and what they actually mean.
Key SpamAssassin Rules and Their Impact
Each rule represents a test. Some add points for suspicious patterns; others subtract when things look legitimate. You’ll see these in mail logs or diagnostic reports when email delivery fails.
| Rule | Points | Meaning | What It Means for You |
|---|---|---|---|
| BAYES_00 | 0.0 to 0.5 | Bayesian filter indicates content is very unlikely to be spam | The message has text patterns typical of clean email. No action needed, but high scores on similar rules (like BAYES_99) suggest spam content. |
| HTML_MESSAGE | 2.0 | Message contains HTML, which spam commonly uses | Not inherently dangerous—many legitimate newsletters use HTML. But if you're using plain text only, consider it a red flag if this rule triggers. |
| SPF_FAIL | 3.0 | Sender's domain does not authorize the sending IP via SPF record | One of the strongest indicators of spoofing. Check your SPF record at RFC 7208 to fix issues. |
| RDNS_NONE | 1.0 | No reverse DNS entry for the sending IP | Most reputable senders assign reverse DNS. Missing this increases spam risk—common with low-tier providers. |
| DKIM_SIGNED | 0.1 | Message is signed with DKIM—a sign of legitimacy | Not a point gain, but a small reduction. Legitimate senders consistently use DKIM. Use our API to verify DKIM alignment. |
| RCVD_IN_SPAMHAUS | 5.0 | IP is listed in Spamhaus's blocklist | High danger. Your IP is flagged for spam activity. Check your IP’s status at Spamhaus and request delisting if appropriate. |
What to Do When Rules Trigger
If you see multiple high-point rules (like SPF_FAIL + RDNS_NONE + RCVD_IN_SPAMHAUS), your domain or IP may be compromised. Start by validating your sending infrastructure. Use inbox placement testing to see how your email lands across major providers—this reveals how rules like RCVD_IN_SPAMHAUS actually affect real delivery. You can also test entire lists using bulk verification to catch invalid or risky addresses before sending. Remember: SpamAssassin is not perfect, but it reflects real-world filtering logic. You can't control every rule, but you can fix the ones you control.
How to Simulate and Test Your SpamAssassin Score
You can simulate and test your SpamAssassin score by sending a test email through a real inbox-placement tool like MailTester’s Inbox Tester. It runs your message through actual spam filters, including SpamAssassin, and gives you a full breakdown of scoring, rules triggered, and where your message fails. This mimics how your email will be evaluated in live inboxes.
Run Your Email Through a Real-World Evaluation
- Send your test email via MailTester's inbox placement tool at https://mailtester.com/inbox-tester. It uses real mail servers and spam filtering systems, including SpamAssassin, to score your message as it would in production.
- Review the full SpamAssassin score report immediately after the test completes. You’ll see the total score, the threshold that triggered spam classification (typically 5.0+), and the individual rule IDs that added points.
- Check which rules triggered—for example, if "HTML_SHORT_LENGTH" added points, it means your email body is too short and looks suspicious. If "FROM_EXCESS_DIGITS" triggered, you may have too many numbers in your sender name.
- Match rules to your content—look at your From address, subject line, HTML, and headers. The report links rule IDs to documentation, like the Apache SpamAssassin Wiki, so you can verify what each rule means.
- Fix and retest—adjust your email content (avoid all-caps, strip hidden text, verify sender domains) and re-simulate. Repeat until you understand why points were assigned and can reduce them.
Understand How Rules Map to Real-World Filtering
SpamAssassin scores are based on heuristics—patterns commonly seen in spam. Each rule applies a point value based on content, structure, or metadata. For example, a poorly formatted header or a URL with a suspicious top-level domain can add 1–2 points. While SpamAssassin itself is open-source, its rules evolve daily, so test regularly.
MailTester’s inbox test is not a simulation—it’s a live evaluation. It reflects what ISPs see. Use this to catch issues before sending to real users. For teams with bulk sends, automate verification using the API or bulk verification tool. Start with 100 free verifications at https://mailtester.com/pricing.
Critical Signs Your Email Is Getting Flagged by SpamAssassin
If your emails are consistently scoring 5+ on SpamAssassin despite clean content and proper formatting, you’re likely dealing with header-level issues, a poor IP reputation, or a shift in DNS-based blocklist status. Even low-scoring messages can fail deliverability if multiple rules trigger simultaneously, especially when headers, routing, or sender identity are inconsistent. Let’s break down the warning signs you can’t ignore.
Multirule Triggers Can Sink Even Low-Score Messages
SpamAssassin evaluates each email against dozens of rules. It’s not just about the final score—it’s how many rules apply. If five rules each add 1 point, you hit the threshold for filtering, even if the total is under 5. This is common with generic content that includes standard footers, auto-generated links, or embedded images without proper alt text.
For example, a simple “unsubscribe” link might trigger both the HTML_MESSAGE and SPF_HELO_NONE rules if your SPF setup is weak. When multiple signals stack, even minor issues compound. Check your headers using tools like MXToolbox to audit alignment, DNS records, and server routing.
Consistently High Scores? It’s Probably Not Your Content
If your messages score high on SpamAssassin but contain no spammy language, the issue is likely external. Sender reputation, IP history, or header inconsistencies are more likely culprits than content.
Even if your content is clean and properly formatted, a previously trusted IP can drop in reputation due to blacklisting by spamtraps or other reputation-sensitive systems. A sudden increase in spam complaints or a high volume of hard bounces from old lists can trigger a reputation downgrade.
Use inbox placement testing to see how your email performs across the major providers. If it’s landing in spam folders across multiple services, it’s a sign of broader signal issues—likely tied to IP or domain reputation.
Deliverability Dips on Trusted Domains? Check for Hidden Shifts
Previously trusted domains or IPs sometimes lose deliverability overnight. This often follows changes in blocklist status, shared IP pool exposure, or a misconfigured authentication setup.
SpamAssassin leverages real-time data from reputation feeds, including DNSBLs and reputation databases. A single misbehaving user on a shared IP can taint the entire block. If you’re using a shared or cloud-hosted sending solution, check your IP’s status on Spamhaus and DMARCian.
Use bulk email verification to clean your list and remove invalid or risky addresses. Then, test deliverability with real inbox placement reports to detect early signals of filtering.
SpamAssassin Points Explained: Real-World Impact on Deliverability
You’re not just fighting spam scores — you’re managing a system where every point counts. A SpamAssassin score of 5.0 is widely treated as the threshold for marking email as spam or triggering aggressive filtering. But even scores below 5 can cause delays or rejections, especially on systems with tight thresholds. The real danger isn’t one big red flag — it’s the slow accumulation of small, seemingly harmless violations that add up fast.
How Points Build Up — And Why It Matters
SpamAssassin assigns points based on patterns it detects: header anomalies, suspicious links, missing authentication, or common spam triggers. Each rule contributes a fraction of a point — a few tenths here, a few more there. Single rules rarely tip the scale. But when multiple low-scoring rules stack up, the total can cross the line. Let's say you send an email with a vague subject line (−0.5), a URL with no SSL (−1.0), and an unfamiliar sender IP (−1.5). Individually, each might seem harmless. Together? They add up quickly — and can easily push your score toward or beyond 5.0.
Even scores below 5 can cause problems. Some mail servers apply thresholds as low as 3.0 for flagging content, especially in high-volume or sensitive industries like finance or healthcare. Others may delay delivery for review, especially if the sender has a weak reputation or inconsistent engagement. The system isn’t just binary — it’s a continuous risk assessment.
What This Means for Your Deliverability
SpamAssassin is a widely used open-source filter, but it’s not the only gatekeeper. Your mail may still get through if the receiving mail server uses a different filter or trusts your domain. But if you’re relying on a single reputation or sender identity, the lack of point transparency can hurt. You can't fix what you can’t measure. And that’s where verification tools come in.
You can test real inbox placement and catch potential issues early with a service like MailTester’s Inbox Placement tool, which simulates delivery across major providers. It checks not just whether your email gets through — but how it scores under real-world conditions. Test your next campaign against live mail servers to see how it performs before sending.
For ongoing list hygiene, you can run a bulk email list check with MailTester’s list verification, which identifies invalid, risky, or catch-all addresses before they hurt your sender reputation. With 98.9% accuracy, it helps you avoid sending to addresses that trigger SpamAssassin scoring due to lack of engagement or fake domains.
Understanding how points accumulate isn’t about chasing perfection. It’s about avoiding small mistakes that compound. Every point lost is one more chance a recipient’s inbox sees your email as suspicious. Verify your list today — and keep your scores in the safe zone.
Using MailTester to Prevent SpamAssassin Failures
SpamAssassin scores are assigned based on content, headers, sender reputation, and server behavior—each rule adds or subtracts points. You can reduce failures by cleaning your list, validating before sending, and testing how your email performs across real inbox environments. A high score means your message risks filtering.
Pre-Send Checks Reduce Spam Risk
- Run bulk list verification to remove invalid, role-based, or catch-all addresses that cause bounces and hurt sender reputation. MailTester flags these with high accuracy: bulk verification.
- Use the real-time API to validate each address before sending. It checks for syntax, MX records, domain existence, and known spam traps—helping you flag risky addresses before delivery. See how it works: real-time verification API.
- Test your campaigns with inbox-placement checks. MailTester simulates delivery across major providers (Gmail, Outlook, Apple Mail) and shows how your message scores under real-world conditions. This reveals whether headers, content, or sending patterns trigger SpamAssassin rules.
How SpamAssassin Rules Translate to Deliverability
- SpamAssassin uses a scoring system where each rule adds or removes points. A total score above 5 typically results in filtering, but thresholds vary by provider. You can’t control the rules, but you can control your sending behavior.
- High scores often stem from inconsistent sender practices: mismatched SPF/DKIM, poor sender reputation, or content resembling spam (e.g., excessive links, all-caps subject lines). MailTester doesn’t predict all 700+ rules, but it surfaces the most common failure points early.
- Use inbox-placement testing to see if your message hits spam folders or lands in inbox. This helps you tune content and headers before sending to real users. Check results across multiple providers: inbox placement tester.
- Integrate MailTester with tools like Mailchimp, HubSpot, or SendGrid to automate validation and keep your sending clean. No matter the platform, pre-verification reduces bounce noise and improves reputation. See supported apps: integrations.
Let’s be clear: no tool can promise 100% inbox delivery. But by using real-time validation and inbox testing, you reduce the risk of SpamAssassin failures. A cleaner list, consistent sender practices, and pre-send checks mean fewer surprises.
SpamAssassin isn’t just about content—it evaluates your entire sending behavior. Clean data and consistent practices matter more than ever.
Start with 100 free verifications at MailTester pricing, and see how your list holds up before you send.
Common Misconceptions About SpamAssassin Scores
SpamAssassin scores aren't a verdict — they’re a tally of signals that suggest spamlikeness. A high score doesn’t mean your message is spam; it means it triggered several heuristic checks, from suspicious headers to unusual formatting. The real test is how the receiving system interprets that score, not the number itself.
Score ≠ Spam — It’s a Signal, Not a Sentence
You might see a score of 10 and panic, but SpamAssassin doesn’t block emails based on that number alone. A high score simply means your message has triggered multiple red flags — like missing headers, URLs in the subject, or repetitive content. Many systems use these scores as input for filtering, not as a binary judgment. What matters is the threshold set by the recipient’s MTA, which varies widely.
For example, a score of 5 might be ignored by one server while triggering a quarantine in another. This is why deliverability isn’t just about your score — it’s about how your email’s sender reputation, volume patterns, and authentication (SPF, DKIM, DMARC) interact with that score. A single rule, even a strong one, won’t define your outcome.
Context and Volume Are the Hidden Variables
Imagine sending 10,000 identical emails with a score of 7. Even if each one is technically “clean” by SpamAssassin’s logic, the volume alone can trigger behavioral filters. ISPs look not just at individual scores, but at patterns — sudden spikes, low engagement, or high bounce rates. These can override any single message’s score.
Sender reputation is another invisible hand. An email from a known domain with strong authentication (see RFC 7001) can survive a high score. But the same score from a new or unverified domain? Much more likely to be treated as risky.
Let’s be clear: no single rule is conclusive. The SpamAssassin scoring system is designed to help — not decide. If you're sending transactional or marketing emails, don’t react to a score in isolation. Test inbox placement with real inboxes, verify your list, and check for common pitfalls like disposable domains or catch-all addresses.
Use tools like MailTester’s inbox placement test to see how your email lands in real inboxes across providers. You can also verify your entire list with bulk verification, or integrate real-time checks via the API. A strong sender reputation, clean data, and proper authentication matter more than any score.
Final Takeaway: Score Awareness Is Part of Deliverability Discipline
SpamAssassin’s scoring system is grounded in decades of empirical analysis of spam patterns. Every point assigned corresponds to a measurable signal — header structure, content heuristics, or reputation data — not arbitrary rules.
Understanding how points are assigned allows you to spot vulnerabilities in your sending setup before they trigger delivery failures. A high score isn’t a warning from a black box — it’s a diagnostic map of what’s being flagged.
Stay below the spam threshold by combining accurate email verification, strict authentication (SPF, DKIM, DMARC), and regular inbox placement testing. These practices are not optional; they are part of responsible sender discipline.
Sources
- Microsoft (Outlook/Hotmail) is the toughest major provider for senders, with just 75.6% inbox placement and a 14.6% spam placement rate — the highest spam rate among major mailbox providers. — Validity 2025 Email Deliverability Benchmark Report (2025)
- The effective spam-complaint target for 2026 has tightened to below 0.1%, down from the historical 0.2–0.3% tolerance, as mailbox providers raise the bar for senders. — Validity 2026 Email Deliverability Benchmark Report (via The Agile Brand Guide) (2026)
Keep reading
- Inbox placement by mailbox provider: Gmail, Outlook, Yahoo and spam filters (complete guide)
- Inbox Placement vs Deliverability: What’s the Difference?
- Does Gmail Block Image-Only Emails in 2026?
- Yahoo CFL Reports Format and How to Parse Them in 2026
- Why Outlook Sends My Emails to Junk in 2026
Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.
Frequently asked questions
What is a good SpamAssassin score?
A score below 5.0 is generally safe. Scores above 8.0 are almost always marked as spam. Many providers use 5.0 as the filter threshold.
Does SpamAssassin score alone determine if an email is blocked?
No. The score is one signal among many — delivery decisions also depend on sender reputation, authentication, and recipient behavior.
Can I lower my SpamAssassin score after sending?
Not directly. You can fix issues in the next send — remove problematic content, fix headers, verify your DNS records, and avoid known spam triggers.
Are all SpamAssassin rules equally important?
No. Some rules like SPF_FAIL or RDNS_NONE carry higher weight. Others like HTML_MESSAGE are common but not definitive.
How do blacklists affect SpamAssassin score?
Lists like Spamhaus or SORBS directly trigger high-point rules. Being on one raises the score automatically, even if content is clean.
Is SpamAssassin still used in 2026?
Yes. It remains a standard component in many mail filtering stacks, especially in enterprise and open-source environments.
What is the difference between a SpamAssassin score and email reputation?
Score is a real-time signal based on message structure. Reputation is a long-term metric based on sending volume, engagement, and complaint history.
Can MailTester help me reduce my SpamAssassin score?
Yes. By verifying your list, testing inbox placement, and identifying risky senders, MailTester helps reduce triggers before emails are sent.
Do all email providers use SpamAssassin?
No. But most use similar rule-based systems. SpamAssassin is a common reference point for scoring, even if not directly implemented.
Why does my email score high even with clean content?
Header issues, missing SPF/DKIM, or sending from a known bad IP can trigger high scores regardless of content.
Can spam filters change over time?
Yes. Rule weights and thresholds evolve as spamming tactics change. Regular testing helps stay aligned.
Is a zero-score email always safe?
Not necessarily. A zero score means no active triggers, but can still be rejected due to sender reputation or blacklisting.