Every message that arrives at an EDZNET mailbox passes through a filtering system before it reaches you. Most of the time you never notice it — the junk quietly disappears and the real mail arrives. But occasionally you'll see something unusual: a subject line with a tag in front of it, a red warning sitting next to a link, or a message that never turned up at all.
This guide explains what those things mean, why they appear, and what you can change yourself. It's written for people who use our mail servers, not administrators — no technical background needed.
What Actually Happens to an Incoming Message
When someone sends you an email, it doesn't go straight into your inbox. It's checked in several independent stages, each looking for a different kind of problem:
| Stage | What it checks |
|---|---|
| Sender reputation | Whether the sending server has a history of sending junk, and whether the sender is genuinely allowed to use the domain they claim |
| Virus & malware scanning | The message and every attachment, including inside ZIP and RAR archives |
| Attachment policy | File types that are dangerous to open regardless of whether a virus is detected |
| Content scoring | Hundreds of individual tests on wording, formatting, links and message structure, which combine into a single score |
| Fraud & phishing detection | Links that don't go where they claim to go, and messages impersonating a brand or a colleague |
| Content disarming | Active elements inside the message — scripts, forms, hidden trackers — that are neutralised before delivery |
A message only needs to fail badly at one stage to be treated as junk. More often, it accumulates small amounts of suspicion across several stages until the total crosses a threshold.
This matters for understanding one thing in particular: spam filtering is a scoring system, not a yes/no decision. That's why some junk arrives merely flagged rather than filed away, and why the occasional legitimate newsletter gets caught.
Tags You Might See in a Subject Line
When a message is delivered but something was found, a short tag is added to the front of the subject line so it's visible at a glance in your message list:
| Tag | What it means | What to do |
|---|---|---|
[SPAM] | Scored as junk. If it scored high enough it has also been filed to your Spam folder rather than left in the inbox | Treat with suspicion. Delete unless you recognise the sender |
[SUSPECTED FRAUD] | A link appears to lead somewhere other than where it claims | Do not click any link in the message |
{Virus?} | Malware was detected | Delete immediately. The dangerous part has already been removed |
{Filename?} | An attachment of a type we don't allow through | Ask the sender to resend it in a safe format, or via a file-sharing link |
{Dangerous Content?} | Active or hostile content was found in the message body | Read with care. Don't interact with anything embedded in it |
{Size} | The message exceeded the size limit | Ask the sender to use a file transfer service instead |
The exact wording of these tags is occasionally updated as our filtering evolves. The reliable rule is simpler than memorising the list: if your subject line has picked up a prefix in brackets that the sender didn't type, our system put it there as a warning.
A word about the question marks
Some of the tags above end in a question mark, and older messages still sitting in your mailbox may carry earlier wording — {Spam?} and {Definitely Spam?} in place of [SPAM], or {Fraud?} in place of [SUSPECTED FRAUD]. We changed those because the question mark caused genuine confusion: it was never an invitation to make your own judgement, only an acknowledgement that automated scoring is a probability rather than a certainty.
Whichever form you're looking at, the practical reading is the same. A tagged message is far more likely to be malicious than not. If you weren't expecting it and you don't recognise the sender, the safe response is to delete it.
Warnings That Appear Inside the Message
Subject tags are easy to miss, so the more serious findings also get flagged in the message body itself, right next to the thing that caused them.
Fraudulent link warnings
This is the most important one, and it's worth understanding exactly what triggers it.
In an HTML email, the text you see for a link and the address it actually opens are two separate things. Nothing stops a sender writing the visible text as www.yourbank.co.za while the link underneath points to a completely different server. This is the core mechanic of almost every phishing attack — you believe you're clicking through to a company you trust, and you land on a copy of their login page controlled by someone else.
Our filters compare the two. When the visible text claims one destination and the link leads somewhere materially different, a red warning is inserted directly beside the link, along the lines of:
Our mail scanner has detected a possible fraud attempt from [the real destination] claiming to be [what the link says]
You'll see both addresses spelled out, so you can judge for yourself. A related warning appears when a link points at a raw numeric address instead of a domain name — legitimate organisations essentially never do this, whereas compromised machines used to host phishing pages frequently do.
If you see one of these warnings, don't click the link. Not to check, not to see what it is. If the message appears to be from a company you deal with, open a new browser tab and type their address in yourself, or phone them on a number you already have.
External sender banner
On mailboxes where we've enabled it, messages from outside your own organisation carry a banner at the top of the message body noting that the sender is external. It sounds trivial, but it's one of the most effective defences against a specific and very costly attack: an email that appears to come from your managing director, your accounts department, or a supplier, asking for an urgent payment or a change of bank details.
If a message claims to be internal but carries an external banner, that contradiction is the whole warning. Verify it by phone before acting on it.
Removed attachments
When an attachment is stripped out — because it contained malware or because its file type isn't permitted — the message still arrives, with a plain-text file attached explaining what was removed and why. You get the correspondence and the context; you just don't get the dangerous file. If it turns out to be something you genuinely need, contact us and we can look at retrieving it from quarantine.
Neutralised content
Some elements are made safe rather than removed, and this happens silently to a great deal of ordinary mail:
- Scripts — code that would run when you open the message is defused
- Forms — input boxes embedded in an email are disabled. No legitimate organisation asks you to type a password into a form inside an email, so these are treated as hostile by default
- Embedded frames — panels that pull in content from another website are blocked
- Tracking pixels — invisible single-pixel images used to report back when you opened a message, and often to confirm your address is live and worth targeting again, are replaced with a blank
If a marketing email ever looks slightly plainer in your inbox than it did in the sender's preview, this is usually why. The readable content is untouched.
The Hidden Headers on Every Message
Every message we deliver carries additional technical headers recording what the filters found. You never see them in normal use, but they're there if you need them — and they're the fastest way for our support team to diagnose a filtering problem.
These headers record whether the message was scanned, the outcome, a spam score shown as a row of repeated characters (more characters means more suspicious), and a unique ID for the message as it passed through our servers.
To view them, look for your mail client's option to show the message source or full headers — usually View → Message Source, Show Original, or View Source depending on the application.
When reporting a filtering problem to us, forwarding the message as an attachment — rather than pasting the text — preserves these headers and makes the issue far quicker to resolve. A normal forward strips them.
One caution worth knowing: because these headers are well documented, spammers sometimes forge them to make a message appear pre-approved. Our servers strip and replace any incoming copies with our own, so the ones on delivered mail are genuine. But this is exactly why you shouldn't trust a "scanned and clean" claim inside a message body — real results live in the headers, not the visible content.
Where Filtered Mail Goes
Messages that score highly enough are delivered to a separate Spam folder rather than your inbox. It appears alongside your other folders in webmail and in any properly configured desktop or mobile mail client.
Nothing there is deleted on arrival — it's held so you can check it. Two habits are worth forming:
- Check it weekly. Legitimate mail lands there occasionally, particularly first-time senders, automated notifications from web forms, and mail forwarded from another provider.
- Don't leave it indefinitely. Older messages are cleared automatically. If something important is in there, move it to a real folder.
If your mail client isn't showing the Spam folder, it usually needs subscribing to in the folder list, or the account may be set up as POP3 rather than IMAP — POP3 only ever downloads the inbox. Our support team can help you switch.
Managing Your Own Filters in cPanel
You don't have to accept the defaults. Our servers run the MailScanner front-end tools, which put per-domain filtering controls directly in your cPanel account — no support ticket needed.
Log into cPanel, find the Email section, and open MailScanner. Settings apply per domain, so if you have several domains on one account you can configure each one differently.
What you can change
| Setting | What it does |
|---|---|
| Spam scanning | Turns content scoring on or off for the domain |
| Low scoring spam threshold | How suspicious a message must be before it's tagged. Lower catches more, with more false positives |
| High scoring spam threshold | The point at which a message is treated as definite junk and filed to the Spam folder rather than tagged |
| Virus scanning | Malware scanning for the domain. We strongly recommend leaving this on |
| Deliver cleaned emails | Whether to receive a message after an infected attachment has been removed, or discard it entirely |
| Whitelist | Senders that bypass spam scoring |
| Blacklist | Senders always treated as junk |
| Spam destination | Send filtered mail to the Spam folder, or route it to a specific address such as a shared review mailbox |
Getting the thresholds right
The two threshold settings are the ones worth spending a moment on, because they change the behaviour most.
Think of them as a pair. The low threshold decides when a message gets tagged but still lands in your inbox; the high threshold decides when it's moved out of your inbox altogether. The gap between them is the band where you make the judgement call — and if you find yourself constantly deleting tagged messages from your inbox, that gap is too wide. Bringing the high threshold down means more of that junk is filed to the Spam folder automatically, where you can still review it but don't have to wade through it.
Adjust in small steps, one setting at a time, and give each change a week of real mail before judging it. Changing both at once makes it impossible to tell which one caused what.
Using the whitelist wisely
Whitelisting is the right fix for a specific recurring problem — a supplier's invoices that always get tagged, a monitoring alert you can't afford to miss. It's the wrong fix for spam in general, and there's a catch worth understanding.
A whitelisted sender skips spam scoring entirely. That's the point of it, but it also means that if that address is ever spoofed or the mailbox is compromised, the resulting attack arrives with no filtering at all. Sender addresses are trivial to forge — there is nothing preventing anyone from putting your own address in the "from" field.
So: whitelist specific addresses rather than entire domains where you can, keep the list short, and review it occasionally. Never whitelist your own domain in an attempt to stop your internal mail being filtered — that hands attackers a guaranteed route into every mailbox on it. If internal mail is being caught, that's a configuration issue worth raising with us instead.
When the Filter Gets It Wrong
Legitimate mail is being caught
- Check the Spam folder first — it may be arriving, just not in the inbox
- Add the specific sender address to your whitelist in cPanel
- If it keeps happening across many senders, the low threshold may be set too aggressively for your mail — raise it slightly
- If a whole category of legitimate mail is affected, send us the message as an attachment so we can see the headers and tune the rules server-side
It's also worth checking the sender's own setup. Mail from domains without proper sender authentication records scores higher everywhere, not just with us — if a supplier's mail is constantly filtered by multiple recipients, the fix usually belongs on their end.
Junk is still getting through
- Blacklist persistent senders in cPanel
- Lower the high threshold so more junk is filed automatically instead of tagged
- Report samples to us — forwarded as attachments. Real examples are what let us improve detection for everyone on the platform, and we'd genuinely rather see them than not
Please don't reply to spam or click unsubscribe links in messages you didn't sign up for. Both confirm your address is live and monitored, which typically increases what you receive.
What the Filter Can't Do For You
No filtering system catches everything, and the messages that get through are by definition the ones that looked most legitimate. A few habits close the remaining gap:
- Never enter your email password on a page you reached from a link in an email. This single rule defeats the overwhelming majority of successful phishing attacks. Go to the site directly instead
- Verify payment and bank detail changes by phone, on a number you already have — not one printed in the email requesting the change
- Treat urgency as a warning sign. "Your account will be closed in 24 hours" and "mailbox full, verify now" are pressure tactics, engineered to make you act before you think
- Use a unique password for your mailbox, and enable two-factor authentication wherever your mail client supports it. A compromised mailbox is used to attack everyone you correspond with, from an address they trust
Frequently Asked Questions
Why did a message I was expecting get marked as spam?
Scoring is based on the message's characteristics, not your relationship with the sender. First-time senders, mail relayed through another provider, messages that are mostly one large image, and mail from domains lacking sender authentication all accumulate suspicion regardless of legitimacy. Whitelist the sender in cPanel and it won't recur.
Can I turn spam filtering off completely?
You can disable content scoring per domain in cPanel, though we'd advise against it — a typical mailbox receives far more junk than real mail. Virus scanning stays on regardless, as it protects the wider platform, not just your mailbox. If filtering is causing you problems, adjusting the thresholds is almost always the better answer than switching it off.
Does the filter read my email?
Messages are analysed automatically to score them, in the same way any spam filter operates. Nothing is read by a person, and content isn't retained beyond the scanning process. Messages held in quarantine are stored only for a limited period before automatic deletion, and are accessed solely when investigating a specific reported problem.
Why do some emails look plainer than intended?
Active content — scripts, forms, embedded frames, tracking pixels — is neutralised during delivery. Formatting, images and text are unaffected. If a message genuinely doesn't render properly, send it to us and we'll look at it.
Someone received a message that appeared to come from my address, but I never sent it.
The "from" address on an email is as forgeable as the return address on an envelope — a spammer writing your address there doesn't mean they have any access to your mailbox. Proper sender authentication records on your domain are what stop others successfully impersonating you, and they're part of how receiving servers decide whether to trust your mail. If you're seeing this, get in touch and we'll check your domain's records.
I've lost something in the Spam folder. Can it be recovered?
If it's still in the folder, just move it back. If it's been cleared, or the message was quarantined before delivery, contact support with the sender address and approximate date — quarantined mail is retained for a limited window and we may be able to retrieve it.