Discussed in #2777
Originally posted by unixfox February 8, 2026
Hello,
I'm coming from Mailcow where Rspamd provide an LLM classifier too: https://docs.rspamd.com/modules/gpt/ and https://github.com/rspamd/rspamd/blob/master/src/plugins/lua/gpt.lua
I'm sharing some suggestions regarding the current implementation in Stalwart.
Those suggestions are also part of my experience tuning the Rspamd LLM classifier as writing in my article: https://cybercarnet.eu/posts/email-spam-llm/
- Stalwart should send the sender email address to the LLM. Even though the Stalwart phishing protection is already good, LLM are very good at recognizing phishing.
For example, if they see "From Paypal" but the real email address is not paypal.com, they immediately see the red flag.
It's probably not the best example but for lesser known services like local real estate agency, the LLM may know the agency and flag email that try to impersonate the agency.
- Stalwart shouldn't send the email content to the LLM if the content is already classified as HAM (negative score).
Rspamd has such mechanism it's:
allow_ham: When true, messages that already look like ham (negative score) are still evaluated.
It saves on cost and avoid sending everything to the LLM. On my own mail server (still with mailcow), 80% of the email that I receive have a negative score.
- Stalwart should have the ability to give more context to the LLM.
Rspamd GPT plugin has implemented "web search context", it sends to the LLM web searches for all the links found in the email content. It works really great if the LLM doesn't know a specific local business and this business is just sending you a legitimate invoice.
This mirrors how a human would handle uncertain cases by searching online for related information before deciding whether a message is spam.
From my experience and as written in my article, most of the time if the LLM sees a message with something like "Please find attached your payment notice for the coming month.". It will always return: "urges the recipient to open an attachment to view a bill, which is a classic pattern for malware delivery or phishing attempts".
But if you include a web search, their behavior is entirely different, and instead they return that the email is legitimate.
In my opinion, LLMs have strong potential for spam detection, and the Rspamd GPT plugin is a good example of this in practice. Taking inspiration from Rspamd鈥檚 approach could help improve the accuracy and effectiveness of Stalwart鈥檚 LLM classifier.
Thank you in advance for considering this enhancement request.
Discussed in #2777
Originally posted by unixfox February 8, 2026
Hello,
I'm coming from Mailcow where Rspamd provide an LLM classifier too: https://docs.rspamd.com/modules/gpt/ and https://github.com/rspamd/rspamd/blob/master/src/plugins/lua/gpt.lua
I'm sharing some suggestions regarding the current implementation in Stalwart.
Those suggestions are also part of my experience tuning the Rspamd LLM classifier as writing in my article: https://cybercarnet.eu/posts/email-spam-llm/
For example, if they see "From Paypal" but the real email address is not paypal.com, they immediately see the red flag.
It's probably not the best example but for lesser known services like local real estate agency, the LLM may know the agency and flag email that try to impersonate the agency.
Rspamd has such mechanism it's:
Rspamd GPT plugin has implemented "web search context", it sends to the LLM web searches for all the links found in the email content. It works really great if the LLM doesn't know a specific local business and this business is just sending you a legitimate invoice.
This mirrors how a human would handle uncertain cases by searching online for related information before deciding whether a message is spam.
From my experience and as written in my article, most of the time if the LLM sees a message with something like "Please find attached your payment notice for the coming month.". It will always return: "urges the recipient to open an attachment to view a bill, which is a classic pattern for malware delivery or phishing attempts".
But if you include a web search, their behavior is entirely different, and instead they return that the email is legitimate.
In my opinion, LLMs have strong potential for spam detection, and the Rspamd GPT plugin is a good example of this in practice. Taking inspiration from Rspamd鈥檚 approach could help improve the accuracy and effectiveness of Stalwart鈥檚 LLM classifier.
Thank you in advance for considering this enhancement request.