Spam, malware and phishing protection with Rspamd, ClamAV/Avast REST and quarantine policy

Focused product for Pitbull Secure Gateway Security Engine and Quarantine modules: spam, malware, phishing and policy decisions on inbound SMTP; preview, charset decode, score analysis and false positive management for suspicious messages.

Security Engine · Quarantine Rspamd · Policy
Rspamd score 8.4
SPF/DKIM PASS
ClamAV CLEAN
Quarantine 3 mesaj
Rspamd ClamAV Quarantine FP Policy
Rspamd
Policy engine
3 AV
Provider choice
Hot path
SMTP performance
FP
Portal reporting

Filtering and quarantine challenges

Signature-only single-layer filtering and scattered quarantine mailboxes cannot scale operations.

Single-layer filtering

Spam score alone is insufficient; Rspamd symbol breakdown and policy engine are required.

Quarantine blind spot

Suspicious messages cannot be managed without preview; charset and attachment risks stay invisible.

FP management load

False positive requests lock support without centralized quarantine and customer portal.

Antivirus flexibility

Not every environment wants the same AV layer; clamav / avast_rest / off choice is essential.

Security Engine + Quarantine layer

Advanced Threat & Quarantine is the inbound protection core of Pitbull Secure Gateway. Rspamd integration delivers spam, phishing and policy decisions on the SMTP hot path in milliseconds; the selectable antivirus layer (clamav, avast_rest or off) scans malicious attachment risks.

Security Engine capabilities

  • Rspamd symbol and score breakdown — ops teams see why a decision was made
  • SPF, DKIM, DMARC authentication results merge in the policy engine
  • ClamAV / Avast REST malware and macro risk scanning
  • Policy-based accept, reject, quarantine and soft-reject
  • Heavy analysis kept off the hot path — mail acceptance latency minimized

Quarantine & Policy

  • Quarantine mail preview and Turkish charset decode (Windows-1254 / ISO-8859-9)
  • Score, threshold, SPF/DKIM/DMARC and symbol breakdown analysis screen
  • Attachment / risk signal visibility (macro, executable, archive)
  • False positive marking and admin-approved quarantine release
  • False positive reporting via customer portal

Operational principles

Auto reject/quarantine activates only with explicit policy. Release actions are written to the audit log. KVKK/GDPR compliant customer-scoped data separation is maintained.

Note: AI-powered operations layer is planned as a future roadmap phase — read-only analysis and policy suggestions; does not make automatic decisions on mail flow.

How it works

  1. 1 Complete Pitbull Secure Gateway MX routing.
  2. 2 Configure Security Engine antivirus provider (clamav / avast_rest / off).
  3. 3 Set quarantine thresholds and release policy per domain.
  4. 4 Enable FP reporting workflow from the customer portal.
  5. 5 Monitor reject reasons and quarantine queue on the NOC panel.