Is this how DSPAM works?

Hi, I’m getting some messages that contain this:

Spam detection software, running on the system “mail5.m****here.biz”, has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn’t spam) or label
similar future email. If you have any questions, see
the administrator of that system for details.

Is this the way dspam is supposed to work? Why I’m getting the original message as an attachment? Also, is there a way to make mail5.m****here.biz appear as my reseller domain?

Thank you very much.

bump!

That’s the way the spam assassin / HSphere spam-checker tags messages. Look at the full headers of the email message for a DSPAM field to see if DSPAM has checked the message.

Tim

Thanks for the answer.

I had understood that dspam tagged the messages only, not that it sent them in an attachment instead of the actual mail going through directly.

I have a false postive, what should I do?

Also, does anybody know a way to tell the SpamBayes plugin for Outlook to read this headers or something to make it work toghether with the tagging from dspam?

Thank you very much!

For false positives, please create a ticket with complete email as attachment.
Not sure about spambayes, but you can always differentiate messages based on headers.
If you have antispam enabled, look for:
Header → “X-Spam-Status” and Value → “DSPAM_SPAM”

If you dont have antispam enabled in control panel, look for:

Header → “X-DSPAM-Result” and value → “Spam”

Also, there is no way to change mail5.m****here.biz to your service domain unless you run your own mailserver.