Prompt caching helps latency.
A warm model reused the shared input prefix even when the mail text changed. Retention improves that opportunity; cache hits are not guaranteed.
Open source · Rspamd + Postfix · MIT
AISSA explores selective content analysis inside an existing mail stack, with bounded waiting and measurable results.
Keep the familiar checks. Select messages worth a closer look. Measure whether the model adds useful evidence.
Experimental. Start in observation mode.
AI Sample Spam AnalyzerLocal Ollama backendOptional live scoringIndependent Redis collection
01 / Integration
Existing Rspamd checks run first. AISSA adds a separate selection and analysis step, while Rspamd keeps control of the final action.
Lua applies score, symbol, URL and reputation criteria, followed by sampling and size limits.
An authenticated loopback bridge extracts bounded MIME text and calls a local Ollama model.
Observation returns after submission. Optional live scoring waits within the remaining scan budget.
The controller records results independently. AI suspicion and independently confirmed abuse stay separate.
A late or failed result adds status information, not a ham verdict. The live wait reserves scan completion time. This is not a hard deadline for the entire SMTP/Milter chain.
02 / Measured behavior
Manual observations with CPU-only Qwen 2.5 1.5B. These cases show behavior, not a production accuracy rate or throughput benchmark.
| Message | Verdict | Model time | Observation |
|---|---|---|---|
| Explicit password / 2FA demand | phishing | 15.128 s | Cold request; live points contributed to rejection |
| Same demand, warm repeat | phishing | 2.523 s | Minimal load and prompt processing time |
| Changed meeting arrangement | ham | 4.195 s | 456 of 536 input tokens reused from cache |
| Suspicious donation offer | ham | 5.400 s | Missed suspicious content; confidence 1.0 |
Model time excludes other filters and SMTP overhead. Test-server phishing points were +5; the repository example uses +3. Read the setup and field notes.
A warm model reused the shared input prefix even when the mail text changed. Retention improves that opportunity; cache hits are not guaranteed.
The model gave its missed donation offer a confidence of 1.0. That number is a self-assessment and does not multiply the configured score.
03 / Current boundaries
Attachments, malware, OCR and fetched web pages are outside the analyzer. Queues and results are held in RAM. Model work may continue after a live timeout. Hostile mail can cause invented evidence or prompt-injection failures.
04 / Participate
Useful contributions are independently labeled, privacy-reviewed cases; model comparisons; and integration reports from other Rspamd versions and SMTP paths.
Report false positives and missed abuse alongside latency, hardware and prompt version. Do not post private mail or credentials.