# Spam checks

> How Emailit scores every outgoing email with Rspamd, why messages scoring 7 or more are held, how to read Spam Checks and how to fix and resend.

Emailit scores every email it sends with Rspamd, the same kind of spam filter many receiving servers use. Messages that look too much like spam are held instead of sent, which protects your domain's reputation. This page explains how scoring works, how to read the results and what to do when a message is held.

## How scoring works

1. **Emailit prepares the message.** It adds its headers, such as `Message-ID` and the return path, and signs the message with your DKIM key.
2. **Rspamd scores the exact bytes that would be sent.** Each rule that matches adds to or subtracts from the score.
3. **Emailit compares the total with the threshold of 7.**
   - **Under 7:** the message is sent.
   - **7 or more:** the message gets the status `held` and isn't sent. Its delivery history says: "Held because Rspamd scored this message 8.4, which is at or above the threshold of 7."

This applies to every outgoing message: API, SMTP, campaigns and automations. Inbound email isn't scored.

If Rspamd is unavailable, Emailit sends the message without a score rather than delaying it. Those messages show **Not inspected**.

## Read the results

### On the email page

Open a message in **Email API → Emails**. The header shows its score as a colored badge, such as **Score +3.20**:

| Color | Score | Meaning |
| --- | --- | --- |
| Green | Under 5 | Low spam likelihood. |
| Orange | 5 to under 7 | Close to the threshold. Worth improving. |
| Red | 7 or more | Held. |
| Grey | **Not inspected** | The message wasn't scored. |

The **Spam Checks** panel lists every rule that matched, with three columns:

| Column | Description |
| --- | --- |
| **Check** | What the rule looks for. Hover to see Rspamd's rule name. |
| **Result** | **Negative** for rules that add to the score (bad), **Positive** for rules that subtract from it (good), **Neutral** for rules with no effect. |
| **Score** | How much the rule added or removed, for example `+2.50` or `-0.10`. |

Use the **All**, **Negative**, **Positive** and **Neutral** filter to focus on the rules that pushed the score up.

### In the email list

The **Spam score** column in the Emails list shows each message's badge. Add a **Spam score** filter, for example *greater than or equal to* 5, to find messages that are close to being held. With the API, [List emails](/docs/api-reference/emails/list/) accepts the same filter:

```bash
curl -G https://api.emailit.com/v2/emails \
  -H "Authorization: Bearer $EMAILIT_API_KEY" \
  --data-urlencode "spam_score.gte=5"
```

## Common rules and fixes

Rule names come from Rspamd. Their exact scores can change as the rules are updated.

| Rule | What it means | Fix |
| --- | --- | --- |
| `MIME_HTML_ONLY` | The message has HTML but no plain-text part. | Send a `text` version along with `html`. |
| `R_PARTS_DIFFER` | The plain-text and HTML parts say very different things. | Generate the text part from the same content as the HTML. |
| `HTML_SHORT_LINK_IMG_1` | A short HTML body that's mostly a linked image. | Add real text. Don't send image-only emails. |
| `SUBJ_ALL_CAPS` | The subject is in capital letters. | Use normal capitalization. |
| `PHISHING` | A link's visible text shows a different domain from where it actually goes. | Make the visible URL match the link, or use descriptive link text instead of a URL. |
| `ZERO_FONT`, `MANY_INVISIBLE_PARTS` | The message contains text hidden from the reader. | Remove hidden text, such as words set to a font size of 0. |
| `DBL_SPAM`, `URIBL_BLACK`, `SEM_URIBL` | A link points to a domain on a blocklist. | Remove the link or replace it with one on your own domain. Avoid public URL shorteners. |
| `R_SUSPICIOUS_URL` | A link uses an unusual or obfuscated address, such as a raw IP address. | Link to normal domain names. |
| `FREEMAIL_REPLYTO` | The `Reply-To` uses a free mailbox provider such as Gmail. | Use an address on your own domain. |
| `MIME_BAD_EXTENSION`, `MIME_DOUBLE_BAD_EXTENSION` | An attachment has a risky file type, such as an executable or a name like `invoice.pdf.exe`. | Don't attach executables. Link to the file instead. |
| `BAYES_SPAM` | The wording resembles messages known to be spam. | Rewrite promotional phrasing and reduce sales language. |
| `FUZZY_DENIED` | The message closely matches known spam. | Write your own content rather than reusing text from bulk templates. |

## Resend a held message

Fix the cause first. A retry sends **exactly the same content** again, so it only helps when the problem was outside the message itself, for example a linked domain that has since been removed from a blocklist.

- **If the content triggered the rules,** fix your template or code and send a new message.
- **If the cause is resolved,** retry the held message:

**Dashboard**

  Open the email in **Email API → Emails** and select **Retry**. Emailit creates a new email with the same content and leaves the original unchanged.

**API**

  Call [Retry an email](/docs/api-reference/emails/retry/) with the held email's ID.

```bash
curl https://api.emailit.com/v2/emails/em_5Vb2Nq8Xc1Jm/retry \
  -X POST \
  -H "Authorization: Bearer $EMAILIT_API_KEY"
```

  The response contains the new email's `id` and the `original_id`.

The retry is scored again before it's sent and costs credits like any other email. You can retry held emails for up to 30 days, as long as their content hasn't been removed by your [data retention](/docs/data-retention/) settings. See [Retry and forward](/docs/email-api/retry-and-forward/).

> **Note:** Spam scores aren't the only reason for `held`. A message is also held when the workspace runs out of credits, its domain is paused, the workspace is suspended or Emailit has put the API key on hold. The email's delivery history shows the reason.

## Related

  - [Best practices](/docs/deliverability/best-practices/): Content habits that keep scores low.
  - [Email statuses](/docs/logs/email-statuses/): What held and every other status means.

---
Source: https://emailit.com/docs/deliverability/spam-checks/
