Thursday, September 20, 2012

When it comes to spam, less is more.

One of the biggest complaints we get about spam is that there's too much of it to review.  Today, we're announcing a simple change to our default display settings, that we hope will drastically reduce this problem for those of you whose anti-spam level is set to Standard.

While the Pobox Spam section and emailed reports can be customized for your preferred views, the vast majority of you use the defaults we provide.  To reflect how we use the Spam section, and how we think it can be most useful to you, we've changed the defaults. Effective today, we're switching the default view we provide from Held Messages to our Quick Check view.  If you were previously set to go directly to Held Messages on the web, or if your emailed report sent all held messages, you will now see the Quick Check view instead. 

The Quick Check view removes messages caught by our 3 most effective filters.  How effective are they? For our two most accurate filters, customers review more than 10,000 messages they caught to release just one message.  For the third, you review more than 2,000.  Of the messages released, header reviews indicate the vast majority are actually spam or suspected phishing, which customers choose to release to themselves for their own purposes.

These 3 highly accurate filters catch more than 88% of the spam we handle each day.  In house, Pobox staffers nearly always choose to use Aggressive filtering, because it bounces messages flagged by these filters, and drastically reduces the amount of mail to review.  Reviewing thousands of pieces of spam for the extremely unlikely possibility that one legitimate piece of mail might be there is simply not effective. Not only do you waste all that time reviewing spam, but it ends up burying mail caught by our less accurate filters. Reviewing messages that have a 1 in 400 chance that they are legitimate makes much more sense than wading through messages whose chances are 1 in 10,000 (or much, much less.)  

Please note: this change has not modified what we catch for you (your anti-spam level) in any way.  It only changes the default setting of what we are asking you to review.  If your view was set, on the web or via email, to Bounced or For Review, your settings have not been changed.  If your anti-spam level is Aggressive, this change will not alter your view.  Aggressive bounces these extremely accurate filters, so they are already part of your Bounced view, not your Held view.

For some of you, part of the peace of mind that Pobox provides is knowing that you can easily check all the mail we've blocked for your account.  If you would prefer to continue reviewing all spam we hold for your account, just switch the view we send back to Held Messages.  (If you want to try the new view out for a few days first, the "Emailed Reports Settings" button at the bottom of every report takes you to the settings for the view included in your report.) To switch the default view when reviewing messages on the web, just select "Held Messages" in the top right corner under Spam Views.
Search in the spam section also checks every section and every view, and always has.

We believe this small change will dramatically reduce the amount of spam you have to review, without impacting the accuracy of your results in any way.  We welcome your continued feedback on any way we can make Pobox better and easier for you to use.  Let us know if you think this has helped!

Updated (9/24/12): Text has been modified to clarify that this change modifies the display for people whose anti-spam level is set to Standard.  Users using Aggressive or higher will not see a change.

11 comments:

  1. The idea seems sound but the figures describing te chances of legitimate mail being trapped are confusing. I am not clear what the 1 in 200 on the blog refers to and the Pobox help page says:

    "Aggressive (catches approximately 95% of spam): We bounce mail most likely to be spam (from our accurate Standard filters), and hold messages caught by our more aggressive filters (less than .25% of messages caught are legitimate mail, or 1 in 400.)"

    I read this to mean there is a 1 in 400 chance of 'held' mail being legitimate. Or have I misssed something? In the meantime I am reverting to 'held' messages.

    Steve Davis
    steve.davis@pobox.com

    ReplyDelete
    Replies
    1. Thanks for pointing this out. I've revised the blog post to correct that 200 vs. 400 typo. To address the meat of your comment, though, if you're using Aggressive as your spam level, you will not see a difference between Held Messages and Quick Check. Because you bounce all the messages that Quick Check removes from the Held view, they would have appeared in Bounced Messages for you, not Held Messages.

      Delete
  2. Thank you for this note. Where do I find the place to change my spam levels? You filter out literally hundreds of messages in foreign languages that have come recently Also, while I indicate most of my e-mail is "junk" these still come through

    ReplyDelete
    Replies
    1. Your anti-spam level can be changed at http://www.pobox.com/spam/settings (or by clicking the button marked "Antispam level" after you log in.)

      If you are getting more than a handful of spam messages a day, you may also be forwarding mail to Pobox from another account. Our help page, I'm getting too much spam. Can you catch more?, talks more about how a change needs to be made to your account to catch those messages. Email us at pobox@pobox.com for assistance setting this up.

      Delete
  3. Hello Pobox

    I've been with you since the early days (1994) and still continue to be amazed at the extremely low level of false positives I find in the message you hold for me. As someone who has had the same email address for the past 18 years I get lots of spam, but hardly ever see any of it... and seldom miss legitimate messages. I don't know how you do it, but I wanted to thank you for this... please stay in the market for the next 20 years...

    ReplyDelete
    Replies
    1. I agree with gregwah. I've been a happy POBox customer since 1996 and have a number of techy friends that have used you for almost as long. I would have given up your service a long time ago had it not been for the great spam filtering you provide. Not getting bogged down by spam, extremely low false positives, not having to notify people every time I have a new email address due to changing jobs or ISPs - all things that I have come to rely on POBox to handle seamlessly for me. I've also received great customer service from them on the rare occasions that I've actually had to ask them a question. Thanks for providing such a great service! Keep up the good work!!

      Delete
    2. Came here to say this. I was an op on EFNet #www when Meng started Pobox and I've never looked back or had to worry about my email getting through. Great job everyone over there.

      Delete
  4. I'm one of the ones who releases stuff that turns out to be spam of phish.

    Why? Because I cannot tell it is truly fraudulent until I can inspect the envelope-from address and/or the X-Pobox-Client-Name and X-Pobox-Client-Address headers. Only the Subject and From headers from the message body are shown in the spam reports or searches.

    Weirdly, the envelope-from is usually shown on the "You have released X messages" page... which means 90% of the time I know I released a spam/phish message before I actually receive it in my inbox.

    ReplyDelete
    Replies
    1. If you click "Edit Columns" at the top of the Spam table, you can edit what information we show in the listing, including "Envelope Sender". Give it a shot; it sounds like it would definitely help you reduce false positive releases!

      Delete
  5. When a legitimate email is caught by one of the 3 email filters, what prevents one of the remaining filters to catch this same email again in the future?

    ReplyDelete
    Replies
    1. When you release a message, we recommend always adding the sender as a Trusted Sender. Trusted Senders are automatically exempted from spam processing in the future.

      Delete