This guide helps you work out where unwanted spam reaching your mailbox is actually coming from, and how to cut it down on Noiz hosting. It is written for mailbox users whose accounts run on Plesk with its built-in SpamAssassin spam filter. If your goal is specifically to tune the spam score or train the filter to recognise your spam more accurately, start with the companion article, How to train your spam filter when using Plesk, then return here.
Last reviewed: 27 July 2026, against Plesk and its built-in SpamAssassin spam filter on Noiz hosting. This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk and SpamAssassin documentation linked below.
Official Documentation Reference
- Plesk Customer Guide: Protection from Spam (enabling and configuring the spam filter for a mailbox)
- Apache SpamAssassin (the open-source engine behind Plesk spam scoring, including how tests and scores work)
Before you start
Spam filtering only works well once it has been switched on and given time to learn what your spam looks like. Before treating persistent spam as a fault, confirm that all of the following are true:
- You have enabled spam filtering for your mailbox.
- You have set your spam score to a suitable threshold. A lower threshold makes the filter more aggressive and catches more spam, at the cost of occasionally catching legitimate mail.
- You have set up the correct Spam folder in your mail app so filtered messages have somewhere to go.
- You have been manually moving spam messages into that Spam folder, and moving any wrongly filtered messages back to the Inbox, for at least a week. The filter needs this training time to become accurate.
If any of these are still outstanding, complete them first and give the filter a few days. Many spam complaints resolve on their own once the filter has been trained. The spam filter training guide walks through each of these steps in detail.
Find out where the spam is coming from
Before you can reduce spam, it helps to know its real source. The most reliable way to do this is to read the message headers, also called the raw source. The headers record the servers a message passed through and the results of the sender authentication checks, and they are far harder to fake than the visible From name.
View the raw source of a message
In Plesk webmail, open the offending message, open the message actions menu (the More or ellipsis option), and choose Show source or View source. Most desktop and mobile mail apps offer the same thing under a label such as Show original, View source, or View message details. This opens the full message, including every header line, which you can then read or copy.
What to look for in the headers
- Return-Path and the topmost
Received:lines show the server that actually delivered the message to you. This is the true origin, regardless of what the From line claims. - Authentication-Results shows the outcome of the SPF, DKIM and DMARC checks. A message that fails all three is almost certainly forged or spam.
- X-Spam-Status or X-Spam-Score (added by the spam filter) shows the score the message received and which rules fired. If the score sits just below your threshold, tightening the threshold slightly may be all that is needed.
Which situation are you in?
Reading the headers usually reveals one of three situations, and each is handled differently:
- Genuine inbound spam. The message really was sent to you from an outside server. Reducing it is a matter of filter training and threshold tuning (below).
- Your address is being spoofed. You receive bounce messages or replies for mail you never sent, because a spammer put your address in the From line. Publishing SPF, DKIM and DMARC records for your own domain makes this forgery far easier for other mail servers to reject.
- Your account is sending the spam. If the headers show the spam originating from your own mailbox or the mail server sending on your behalf, your account credentials have likely been compromised. Change the mailbox password immediately, then contact Noiz support.
Reduce the spam you receive
For genuine inbound spam that keeps reaching your Inbox, the two most effective levers are:
- Keep training the filter. Every message you move into the Spam folder, and every false positive you move back out, improves accuracy over time. Consistency matters more than volume.
- Lower the spam score threshold in small steps. Nudge it down, watch for a few days, and check that legitimate mail is not being caught. The training guide covers safe threshold values.
Still getting spam that is not being filtered?
If, after completing all the steps above and giving the filter time to learn, large amounts of spam still arrive in your Inbox without being marked or moved, Noiz support can help. Some diagnostic data is needed first so the problem can be reproduced and investigated.
Please include the following in your support ticket:
- The raw source of one spam message that was not moved to the Spam folder or marked as spam, captured using the steps above. This is the single most useful item, because it contains the headers and the spam score.
- The email address at which you are receiving the spam.
- The spam score threshold you have set in Plesk.
- Roughly how many messages you have trained as spam, and for how long you have been training the filter.
With the raw source in hand, the support team can examine the headers, the spam score and the server-side mail logs for your mailbox, and investigate without ever needing to sign in to your account.
A note on your password
Never share your mailbox password with anyone, including support staff. Noiz support will never ask for it, and it is never required to diagnose a spam problem. The raw source of a message and, where relevant, the server-side mail logs provide everything needed. If anyone asks you to hand over your password to investigate spam, treat it as a phishing attempt. If you suspect your mailbox itself has been compromised, change the password straight away and mention this in your ticket.
Once you have gathered the diagnostic data above, open a support ticket here so the Noiz team can investigate.
