Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

SpamAssassin proves to be an effective engine for battling spam

SpamAssassin 2.63, MailPoint 3000, and CanIt-Pro demonstrate the spam-fighting power of open source

By Logan G. Harbaugh
July 09, 2004
 

SpamAssassin has proven itself to be a cost-effective and valuable open source weapon in the war on spam. But it’s also a complex solution. Capitalizing on SpamAssassin’s strengths, a number of companies have incorporated it into commercial products, adding extra features and much easier installation and manageability.

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

I recently looked at SpamAssassin 2.63, as well as two commercial products built around it, CanIt-Pro 2.0b from Roaring Penguin Software and the MailPoint 3000 appliance from Digitalinfo Networks. The three products illustrate the full spectrum of convenience vs. cost that applies to all anti-spam products, not just those based on SpamAssassin.

Downloading and installing SpamAssassin 2.63 required a substantial investment in time and reading through the documentation, but the software worked well once I jumped through all its hoops. CanIt-Pro required installing Red Hat Linux and then the software. It also involved a good bit more configuration than the MailPoint appliance, but it proved more flexible. The MailPoint 3000 box took five minutes to install and required little configuration but lacked some features that large companies might need.

In my tests, MailPoint 3000 and CanIt-Pro performed better at filtering out spam than SpamAssassin. However, further tuning of SpamAssassin would undoubtedly have yielded better results.

SpamAssassin 2.63

If you’re a full-time Linux administrator adding SpamAssassin to an existing Linux-based e-mail setup, you’ll find that it can provide more control than most costlier commercial packages. However, if you aren’t familiar with Linux system administration and you don’t relish the idea of wading through hundreds of pages of documentation, SpamAssassin may not be for you. This is not a slap at SpamAssassin; it is capable of good performance and it’s extremely flexible. But it’s not for everyone.

I installed SpamAssassin 2.63, along with the ancillary packages recommended by SpamAssassin.org. It took me a couple of hours to get Linux and the packages installed, but configuration was the real issue. Without looking at every document available, I downloaded more than 700 pages of documentation and found that some of them referred to older versions of SpamAssassin or Linux, and some documents contradicted others. On the upside, there are a couple of newsgroups available for SpamAssassin users and I was able to get quick answers to my questions there.

Configuration is done via a command-line interface, editing text files and Perl scripts. Although SpamAssassin itself doesn’t require a lot of configuration once it’s installed, getting the OS updated with all the correct supporting packages, adding required packages, and getting your e-mail application configured properly to work with SpamAssassin can take some time.

SpamAssassin uses a number of the usual effective techniques to spot spam: header analysis, text analysis, blacklists, real-time blackhole lists, and the newly added Vipul’s Razor, a collaborative spam-tracking database. Additional enterprise-oriented tools can be installed to allow administrators to apply different filtering settings for individual users and groups, or to allow users to access quarantined e-mail and to whitelist senders. These tools can be downloaded and installed freely, but finding them and getting them to work is not a trivial exercise.

Once I got the SpamAssassin software configured and running, its default settings provided acceptable performance, blocking 88 percent of spam, but with a very high 14.77 percent false-positive rate. With a few months of use and tuning, however, I expect its performance would improve substantially. Adding available plug-ins, such as the Bayesian filter or the content-checking filter, would likely help too.

While not a fit for administrators inexperienced with Linux, SpamAssassin is a powerful, extensible package that can perform as well as commercial solutions, provided you are willing to spend the time tuning it and updating it as necessary.

Roaring Penguin Software CanIt-Pro 2.0b

Administrators looking for an inexpensive spam-fighting solution that brings out and adds to the best of SpamAssassin might consider CanIt-Pro.

Although far simpler to install than SpamAssassin, it proved more complex to install than the MailPoint box, requiring the Apache Web Server, PHP Web interface, Perl, and C programming environments. Still, installing the CanIt-Pro package is not onerous and configuration is complex only because of its wide range of features, its scope, and its flexibility. According to Roaring Penguin, a high-end server can handle 100,000 messages a day.


Continued
1 | 2 | Next Page » 



Roaring Penguin Software CanIt-Pro 2.0b

Roaring Penguin Software, roaringpenguin.com/

Excellent  8.6
criteria score weight
Accuracy 9 25%
Manageability 9 25%
Ease-of-use 8 20%
Setup 8 20%
Value 9 10%

Cost:
Starts at $6 per mailbox for the first year. Subsequent support fees are 50 percent of the initial price. Outright purchase price begins at $18 per mailbox.

Platforms:
Any e-mail application that supports SMTP

Bottom Line:
CanIt-Pro offers an enterprise-oriented feature set that includes user access to quarantined e-mail. With a minimum purchase of 125 mailboxes, it’s not intended for small organizations, but larger organizations will find the comprehensive feature set a good fit.

About our Reviews and Scoring Methodology



Digitalinfo Networks MailPoint 3000

Digitalinfo Networks, digitalinfo.net

Very Good  8.5
criteria score weight
Accuracy 9 25%
Manageability 7 25%
Ease-of-use 9 20%
Setup 9 20%
Value 9 10%

Cost:
$1,599

Platforms:
Any e-mail application that supports SMTP

Bottom Line:
The MailPoint 3000 performed very well in filtering spam and had almost no false positives. Its price is less than many software-only packages. It is very easy to set up and configure, but it lacks some of the enterprise-oriented features and granularity some companies might want.

About our Reviews and Scoring Methodology



SpamAssassin 2.63

SpamAssassin.org, spamassassin.org/

Very Good  7.1
criteria score weight
Accuracy 6 25%
Manageability 8 25%
Ease-of-use 6 20%
Setup 7 20%
Value 10 10%

Cost:
Free

Platforms:
Any e-mail application with SMTP

Bottom Line:
SpamAssassin is powerful, extensible, and free, but it's not for beginners. It requires a substantial investment in time to understand its features and to properly configure and update its modules. Adding features and modules and adjusting rules requires knowledge of Perl programming.

About our Reviews and Scoring Methodology



 


 
IT consultant Logan Harbaugh is the author of two books on networking. Contact him at logan@lharba.com.
 

TOP NEWS:


»  Parts of San Francisco network still locked out
Administrators are still locked out of the city's VoIP system and LANs within the Sheriff's Department and the Recreation & Park Department

»  Intel says Moblin update coming soon
Open-source effort set for mobile Linux should have an alpha-level release in a few weeks

»  Are virtual firewalls a solution for VM security?
Virtual firewalls can be a useful security tool, but their efficacy depends heavily on how you have set up your networks

»  Ubuntu to unveil new version of Launchpad next week
Ubuntu's beta community still has a long way to go to achieve the popularity of competitors such as SourceForge.net

»  Oracle unveils access management suite
Oracle's suite includes a new server that provides controls to fine-tune user privileges

»  5 ways the iPhone 3G still lags in enterprise
Despite Apple's improvements, its iPhone 2.0 software remain less competent and less tested than its BlackBerry and Windows Mobile counterparts




Are you ready for event-driven business?
"Faster than a speeding bullet" doesn't just refer to superheroes anymore, it's the velocity your business needs to compete. In this webcast you will learn strategies you can implement today that will keep your systems ahead of the increased business velocity. Sponsor: Progress Sonic

»  Click here to view this Webcast
  Zombie PCs Are Attacking Your LAN
A recent study showed that malware-infected zombie PCs are now a bigger threat to ISPs and Web infrastructure than DoS attacks. As this brand new IT Strategy Guide explains, an increased use of peer-to-peer techniques by the attackers has made it harder to fight back. Download now, compliments of Verio:

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
SEE ALSO
• SpamBayes knows spam
• Commercial solutions win, spam loses
• MailMarshal puts spam in a headlock


FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist