Overview of Spam Control
This page provides a brief overview of the Campus Spam Control service and how it works.
Spam Control is a service that reduces the amount of spam you receive and eliminates known viruses before they reach your mailbox. As soon as you have a NetID you are automatically enrolled in the service.
Is it real email, spam, or a virus?
Spam Control uses a scoring system to determine if an incoming email sent to netid@uis.ed is legitimate email, spam, or virus-infected. Depending on its score, the email is regarded as one of the following:
- Not Spam: The email is legitimate correspondence.
- Possible Spam: The email has questionable characteristics but could be legitimate.
- Likely Spam: The email is probably spam.
- Certain Spam: The email is definitely spam.
- Virus: The email contains a known virus.
You can find detailed information about how email messages are evaluated on the Spam Control Scoring System page.
Choosing how your spam is handled
You can choose one of five different ways for Spam Control to handle possible, likely and certain spam. (Messages containing viruses are immediately deleted, and legitimate email messages [Not Spam] are delivered to your mailbox, regardless of which preference you select.)
The five ways for handling likely and certain spam are referred to as Personal Spam Policies. They are:
[NOTE: Cautious Plus is the default policy for all users. When you login to the Proofpoint Portal you may see something different list next to Default Policy, the portal does not correctly reflect the what has been applied to all users.]
- Cautious: Possible, likely and certain spam is sent to your Quarantine, a server space where spam is held for 10 days.
- Cautious Plus: Possible and likely spam is sent to your Quarantine, certain spam is automatically deleted.
- Aggressive: Possible spam is sent to your Quarantine; likely and certain spam is automatically deleted.
- No Quarantine: Possible spam is delivered to your mailbox; likely and certain spam is automatically deleted.
- Cautious Plus, No Quarantine: Possible and likely spam is delivered to your mailbox; certain and known spam is automatically deleted.
The following chart illustrates the differences in the policies:
| Personal Spam Policies | ||||||
| Cautious | Cautious Plus | Aggressive | No Quarantine | Cautious Plus, No Quarantine | ||
|---|---|---|---|---|---|---|
| Not Spam (spamscore=0-49) | delivered | delivered | delivered | delivered | delivered | |
| Possible Spam (spamscore=50-70) | quarantined | quarantined | quarantined | delivered | delivered | |
| Likely Spam (spamscore=80-98) | quarantined | quarantined | deleted | deleted | delivered | |
| Certain Spam (spamscore=99-100) | quarantined | deleted | deleted | deleted | deleted | |
| Known Virus | deleted | deleted | deleted | deleted | deleted | |
How to Adjust your Personal Spam Policy
- Login to the UIS Proofpoint Portal
- Click on Profile in the lower left corner of the window
- Choose the policy that works best for you
- Click Save
Safeguarding your email
Over the past several years, Spam Control has proven to be very reliable at correctly distinguishing spam from real email. However, an occasional mistake might occur--spam might slip through the filters or, conversely, an email from your friend could get caught. Spam Control has additional safeguards if you are concerned that your legitimate email messages might be mistaken for spam.
The Quarantine and Daily Digests
Some policies use a separate storage space called the Quarantine to hold email marked as spam so that they do not take up space in your email account. If you choose a policy that quarantines spam, please be aware that emails in the Quarantine for more than 10 days will be automatically deleted.
You can view the contents of your Quarantine through daily email digests, which will list all emails added in the past 24 hours. You can choose to release an email if you want to make sure it is not legitimate email. It is recommended that you review the list every day to make sure there are not any legitimate emails in your Quarantine.
How to view your Quarantine
- Login to the UIS Proofpoint Portal
- Review the messages that you do not believe should be quarantined
- Choose to either Release the message, Allow Sender, mark it as Not Spam or leave it in quarantine to be deleted after 10 days.
- When you are done reviewing your Quarantine be sure to Logout of your UIS Proofpoint Portal
Safe and Blocked Senders Lists
You can add your correspondents' email addresses to your Safe Senders list, which will prevent them from being marked as spam. Similarly, you can add unwanted email addresses to your Blocked Senders list.
Information Technology Services also maintains a Global Safe List. This allows official University communication to go through Spam Control to users' mailboxes.
Managing Safe and Blocked Senders Lists
- Login to the UIS Proofpoint Portal
- Click on Lists in the lower left corner of the window
- Choose the list you want to view under My Lists on the left side of the screen
- You can either add senders, edit senders, or delete senders from this location
Adapting to emerging spam threats
Information Technology Services receives constant updates from Spam Control's software vendor on global emerging spam threats, allowing us to quickly and accurately identify the worst spam servers. Using a practice known as connection blocking, ITS restricts these servers' communication with our campus mail server, making it less likely that spam can end up in your mailbox.
Spam Scoring System
How email messages are tagged
Information Technology Services Spam Control uses a statistical model based on thousands of attributes such as language in the subject and body, the origination of the message, and information in the message's headers to evaluate each message sent to netID@uis.edu. Depending on its attributes, each message is "tagged" with a score from 0 to 100. The higher the number, the more likely the message is spam. You can see the tagged score by viewing the full headers of your email message.
Spammers constantly change how they send spam in order to deceive anti-spam programs. Spam Control updates its scoring attributes continually to keep pace with emerging spam threats.
Note: Information Technology Services receives constant updates from Spam Control's software vendor on global emerging spam threats, allowing us to quickly and accurately identify the worst spam servers. Using a practice known as connection blocking, we restrict these servers' communication with our campus mail server, making it less likely that spam can end up in your mailbox. Because these spam messages are blocked before they are even sent, they are not scored and processed by Spam Control.
Your Personal Spam Policy is comprised of your chosen spam management options. You can choose a Personal Spam Policy that will automatically set the threshold for a message to be regarded as spam. The Cautious, Cautious Plus, Aggressive, and No Quarantine policies use the following thresholds:
| Score | Regarded as | Definition |
|---|---|---|
| 0 to 49 | Not Spam | The email is legitimate correspondence |
| 50 to 79 | Possible Spam | The email has questionable characteristics but could be legitimate. |
| 80 to 98 | Likely Spam | The email is probably spam. |
| 99 and 100 | Certain Spam | The email is definitely spam. |
So what does this mean?
The spam policy you choose determines how you what suspicious spam messages you see.
- Email with a score >98 will certainly get discarded...unless you safelist the sender
- Email with a score >80 will be 'likely spam'.. and discarded by aggressive policies, or quarantined by others
The Cautious, Cautious Plus, Aggressive, and No Quarantine polices will either quarantine or delete spam automatically for you. See these KB articles for more information about the available policies and how you customize Spam Control to meet your spam tolerance.
URL Defense [URL Re-Writing]
In an effort to reduce the occurrence of malicious URLs for our Campus email customers, Technical Services has implemented Proofpoint's Targeted Attack Protection (TAP) service. This service verifies the URLs in email are not malicious and then it rewrites the URL to reflect it has been verified by our Spam Control service.
How does it work?
This service automatically scans incoming email for hyperlinks and rewrites them with special URLs. These new URLs allow Proofpoint to check the original URL before actually sending the reader to that web page.
If Proofpoint checks the intended web page and discovers that it is being used for malicious purposes such as phishing scams or delivering malware, the email reader will not be taken to the malicious web page. They will instead see a message saying that the web page was malicious and blocked.
The most noticeable piece of this service is the URL labelling. All rewritten links will have the website's domain added in square brackets after the link to show where the link points to. After clicking on a rewritten link, web pages should load with little or no noticeable delay — unless, of course, the link was to a malicious web page in which case it will be blocked.
This will only affect email passing through the Campus Email Relays from outside the University of Illinois. Email sent from @uis.edu to @uis.edu accounts will not have the URLs rewritten.
What do rewritten hyperlinks look like?
The link text in a message will stay the same, with the domain of the URL added in square brackets as a label to alert you where the link points.
When you hover over a link that has been rewritten, you will see that https://urldefense.proofpoint.com/v1/url?u= has been added to the beginning of the link and a string of letters and numbers have been added after the link. To hover place your cursor over a link without clicking it.
If a URL has been determined to malicious, and you click the URL then a campus web page will appear stating the URL was blocked.
What should I do if I click on a link and the page is blocked?
Once a page is blocked, there is nothing more that you need to do. This page will also be blocked for all other customers.
In addition, it is not necessary to report to ITS or the web site's administrator that the page has been blocked. However, if a page has been blocked and is not malicious, a false-positive, then please send an email to infosec@uis.edu with the details and we will review it with the vendor to determine if it's a false-positive and update the URL as needed.
