About Rspamd
Introduction
Rspamd is a high-performance spam filtering system and email processing framework. It runs as a separate daemon next to your Mail Transfer Agent (MTA): the MTA passes each message to Rspamd, which analyzes it and returns a score and a recommended action.
Core Capabilities
Built on an event-driven architecture with a complete Lua scripting framework, Rspamd offers:
- Advanced spam filtering - Combines Bayesian statistics, neural networks, fuzzy hashing, DNS blocklists and rule-based content checks
- Email authentication - SPF, DKIM, DMARC, and ARC validation with cryptographic signing
- Policy enforcement - Rate limiting, greylisting, reputation tracking, and custom rules
- Machine learning - Neural networks and statistical classifiers that adapt to your mail patterns
- External integrations - Antivirus scanning, URL filtering, AI/ML services, and custom backends
How It Works
Each message is evaluated through multiple stages:
- Pre-filters - Settings, rDNS and ASN lookups, and with Redis the ratelimit and greylist checks (run first, can end processing early)
- Filters - Authentication checks (SPF/DKIM/DMARC), content rules, RBL lookups, fuzzy checks; network lookups run concurrently
- Classifiers and composites - The Bayes classifier, then composites that combine symbols
- Post-filters - Neural networks, the greylisting decision, final action adjustments
- Action decision - Based on the total score: no action, greylist, add header, rewrite subject or reject
Understanding Rspamd describes each stage.
Rspamd communicates results to your MTA via HTTP/JSON API or Milter protocol, recommending an action without directly handling mail delivery.
Performance Profile
- Event-driven I/O - Each worker process scans many messages at once
- Async operations - Non-blocking DNS, Redis, HTTP requests
- Throughput - The project reports roughly ten times SpamAssassin's throughput with the same rules. Actual throughput depends on your hardware, the enabled modules and message size. Scan time also depends on the latency of DNS, Redis and other network lookups
See Architecture documentation for internal details, Performance for the optimizations Rspamd uses and Features for the full list of capabilities.
Choose Your Path
This documentation is organized to help you succeed with Rspamd at any experience level:
🆕 New to Rspamd?
Start here: Getting Started Guide
- Understanding Rspamd - Learn how Rspamd processes messages and makes decisions
- Installation - Choose the best installation method (package, Docker, Kubernetes)
- First Setup - Check Redis and the web interface password, connect Postfix and train Bayes
🎯 Configuring Rspamd?
Go to: Configuration
- Configuration Fundamentals - Understand the layered configuration system
- Tool Selection Guide - Choose between multimap, regexp, Lua, or selectors
Common tasks:
🔧 Technical Reference
For developers and advanced users:
- Module Documentation - Configuration reference for the built-in modules
- Lua API - Programming interface for custom rules and plugins
- Developer Guides - Architecture, protocol, writing rules, testing
- Protocol Documentation - HTTP scanning protocol and reply format; controller endpoints cover the management API
Quick Start Options
Docker Test Environment
Fastest way to explore Rspamd's web interface and test message scanning. The image does not generate a password, and the controller refuses the default password q1 for connections through a published port, so set your own first:
# Generate a password hash (enter the password when asked)
docker run --rm -it rspamd/rspamd:latest rspamadm pw
# Put the hash into a local.d directory for the container
mkdir -p local.d
echo 'password = "$2$your_generated_hash";' > local.d/worker-controller.inc
# Run Rspamd with the ports published on 127.0.0.1 only
docker run -d \
--name rspamd-test \
-v "$PWD/local.d:/etc/rspamd/local.d:ro" \
-p 127.0.0.1:11334:11334 \
-p 127.0.0.1:11333:11333 \
rspamd/rspamd:latest
# Access web interface at http://localhost:11334 and log in with your password
Test message scanning:
# Scan a test message (without From, To, Date and Message-ID headers it scores high on its own)
echo -e "Subject: Test\n\nTest message body" | \
curl --data-binary @- http://localhost:11333/checkv2
Note: This single container has no Redis and no local recursive DNS resolver, so Bayes, greylisting and rate limiting do not work and DNS blocklists may refuse its queries. For production, use the packages below or the Docker Compose setup with Redis and Unbound.
Production Package Installation
Ubuntu/Debian
# Install prerequisites
sudo apt-get update
sudo apt-get install -y lsb-release wget gpg
# Add GPG key
sudo mkdir -p /etc/apt/keyrings
wget -O- https://rspamd.com/apt-stable/gpg.key | gpg --dearmor | sudo tee /etc/apt/keyrings/rspamd.gpg > /dev/null
# Add repository
CODENAME=$(lsb_release -c -s)
echo "deb [signed-by=/etc/apt/keyrings/rspamd.gpg] http://rspamd.com/apt-stable/ $CODENAME main" | sudo tee /etc/apt/sources.list.d/rspamd.list
# Install Rspamd and Redis
sudo apt-get update
sudo apt-get --no-install-recommends install rspamd
sudo apt-get install redis-server
# Start services
sudo systemctl enable --now rspamd redis-server
RHEL, AlmaLinux, Rocky Linux and other EL distributions
# The packages need EPEL (on RHEL itself, see the installation guide)
sudo dnf install epel-release
# Add Rspamd repository for your EL version
source /etc/os-release
EL_VERSION=$(echo -n $PLATFORM_ID | sed "s/.*el//")
sudo curl -o /etc/yum.repos.d/rspamd.repo https://rspamd.com/rpm-stable/centos-${EL_VERSION}/rspamd.repo
# Install Rspamd and Redis (on EL 10, install and enable valkey instead of redis)
sudo dnf install rspamd redis
# Start services
sudo systemctl enable --now rspamd redis
Next Steps After Installation
-
Verify installation:
sudo systemctl status rspamdrspamd --version -
Connect Rspamd to Redis. The shipped configuration has no Redis server set, so Bayes, greylisting and rate limiting stay disabled until you add one:
# /etc/rspamd/local.d/redis.confservers = "127.0.0.1"; -
Set web interface password (connections from localhost do not need it, but clients outside
secure_ipdo):rspamadm pw # Generate password hashecho 'password = "$2$your_hash_here";' | sudo tee /etc/rspamd/local.d/worker-controller.incsudo systemctl restart rspamd -
Continue with: First Setup Guide for complete configuration
For detailed installation instructions including Kubernetes, Docker Compose, and other platforms, see the Installation Guide.
Key Features at a Glance
| Feature | Description |
|---|---|
| Event-driven architecture | Async I/O lets each worker scan many messages concurrently |
| Email authentication | SPF, DKIM (signing+validation), DMARC, ARC with caching |
| Statistical learning | Bayesian classifier + Neural networks + Fuzzy hashing |
| Content analysis | Regex rules (Hyperscan-optimized), MIME checks, language detection |
| Real-time blacklists | Preconfigured IP, domain, URL and email blocklists (Spamhaus, SURBL, URIBL and others) with parallel DNS queries |
| Anti-abuse | Rate limiting, greylisting, spamtrap detection |
| Web UI | Statistics and throughput graphs, history, scanning and training, editing scores, action thresholds and maps, selector testing |
| Protocols | HTTP/JSON, Milter (proxy worker), legacy RSPAMC and spamc protocols |
| Security | HTTPCrypt encryption, localhost-only binding, minimal attack surface |
| Scalability | Horizontal scaling, load balancing, Redis HA support |
See the Features page for technical details.
Architecture Overview
┌─────────────────────────────────────────────────┐
│ Mail Transfer Agent │
│ (Postfix/Exim/Sendmail/etc) │
└────────────────┬────────────────────────────────┘
│ Milter/HTTP
▼
┌───────────────┐
│ Rspamd Proxy │ ◄── Load balancing, protocol translation
│ Worker │
└───────┬───────┘
│
┌───────▼────────┐
│ Rspamd Normal │ ◄── Message analysis, scoring
│ Worker │
└───────┬────────┘
│
┌────────────┼────────────┐
▼ ▼ ▼
┌────────┐ ┌────────┐ ┌─────────────┐
│ Redis │ │ DNS │ │ External │
│ (Bayes,│ │Resolver│ │ Services │
│ limits)│ │ (RBLs) │ │ (AV, URLs) │
└────────┘ └────────┘ └─────────────┘
Key components:
- Proxy worker - Protocol translation (Milter ↔ HTTP), multiplexing, load balancing
- Normal worker - Actual message scanning and rule execution
- Controller worker - Web UI and management API
- Redis - Statistics, learning data, rate limiting, caching
- DNS resolver - Critical for RBL checks; use local recursive resolver
See Architecture documentation for detailed process model and event-driven implementation.
Integration Examples
Postfix (most common)
# /etc/postfix/main.cf
smtpd_milters = inet:localhost:11332
non_smtpd_milters = inet:localhost:11332
milter_default_action = accept
milter_protocol = 6
Exim
Exim talks to the normal worker on port 11333 with the legacy RSPAMC protocol:
# Main section of the Exim configuration
spamd_address = 127.0.0.1 11333 variant=rspamd
# In the ACL used for acl_smtp_data
warn
spam = nobody:true
add_header = X-Spam-Score: $spam_score
add_header = X-Spam-Report: $spam_report
This only adds headers. The Exim section of the integration guide shows a complete ACL that rejects or defers mail based on $spam_action.
Direct HTTP API
# Scan message via HTTP
curl -X POST http://localhost:11333/checkv2 \
-H "Content-Type: message/rfc822" \
--data-binary @message.eml
See Integration guide for complete MTA setup instructions.
Performance Comparison
The project reports that Rspamd processes about ten times as many messages as SpamAssassin with the same rules, loaded through the SpamAssassin module. In a 2019 measurement, one server handled about 1500 messages per second with about 80% of its CPU idle. Throughput on your system depends on your hardware, the enabled modules and message size. Slow DNS, Redis and other network lookups add to the scan time of each message, but they do not hold up other scans.
Why Rspamd is faster:
- Non-blocking I/O (single process handles many messages)
- Optimized regex engine (Hyperscan or its fork Vectorscan in the official packages)
- Efficient memory pools
- Connection pools for Redis and HTTP keep-alive connections
- Zero-copy message handling where possible
See Performance for the optimizations and the comparison with SpamAssassin for a feature-by-feature table.
Common Use Cases
- ISP/hosting providers - High-volume mail filtering (millions of messages/day)
- Enterprise mail servers - Policy enforcement, outbound scanning, advanced authentication
- Small business - Simple spam filtering with minimal resources
- Mailing list operators - ARC handling, reputation management
- Security teams - Threat intelligence integration, custom detection rules
Migration from SpamAssassin
If you're currently using SpamAssassin:
- Install Rspamd alongside SpamAssassin (don't remove SA yet)
- Configure both to add headers (test mode, no rejection; see Testing alongside SpamAssassin)
- Compare results for several days
- Retrain Bayesian classifier with your mail corpus (SA Bayes data not compatible)
- Switch to Rspamd once confident
Key differences:
- Roughly ten times SpamAssassin's throughput with the same rules
- Different statistical model (must retrain)
- DKIM and ARC signing and DMARC aggregate reports built in (SpamAssassin only checks DMARC and ARC)
- Event-driven vs process-per-message
See SpamAssassin migration guide for step-by-step instructions.
Community and Support
Community Channels
- GitHub Discussions - Questions, ideas, and general discussion
- Discord - Real-time chat for quick questions and community support
- Telegram - Alternative real-time chat
- Mailing Lists - Long-form technical discussions and announcements
Development and Issues
- GitHub Repository - Source code, issue tracking, pull requests
- Issue Tracker - Bug reports and feature requests
- Contributing Guide - How to contribute code; contributing to the documentation covers this site
Commercial Support
For large or custom deployments that may require NDA signing, consulting, or dedicated access to fuzzy storage or DNS lists, commercial support is available. Contact support@rspamd.com; see the Support page.
Security Vulnerabilities
Report security issues privately through GitHub private vulnerability reporting (preferred), or email vsevolod@rspamd.com with [SECURITY] in the subject.
Do not open public GitHub issues for security vulnerabilities. SECURITY.md explains what the project treats as a vulnerability.
Documentation Structure
This documentation is organized into several sections:
- Getting Started - Installation, configuration basics, first setup
- About - Features, comparison, performance
- Configuration - System-wide settings, UCL syntax, configuration layers
- Modules - Reference for the built-in modules
- Workers - Worker types and their configuration
- Tutorials - Step-by-step guides for common tasks
- Developers - Architecture, protocol, writing rules, writing tests
- Lua API - Complete programming interface documentation
- FAQ - Frequently asked questions
License and Legal
Rspamd is open source software licensed under the Apache 2.0 License.
Key points:
- Free to use, modify, and distribute
- Commercial use permitted
- Patent grant included
- No warranty provided
See LICENSE.md file for complete terms.
Project Status
- Active development - Regular releases with new features and improvements
- Production ready - Used by ISPs, hosting providers, and enterprises worldwide
- Upgrade notes - Incompatible changes between versions are listed in Updating Rspamd
- Security updates - Released for the latest stable series only (currently 4.x); older series get no backports
- Project history - Developed since 2008
Current stable version: Check GitHub releases for latest version
Ready to start?
→ New users: Understanding Rspamd → Installation → First Setup
→ Experienced users: Configuration Fundamentals → Module Reference
→ Developers: Architecture → Writing Rules → Lua API