SpamStopsHere has optional "Additional Filters" that can be individually enabled and disabled. These include foreign language and country, sexually explicit language, SPF checking, same-domain checking, URL shorteners, and more. For convenience, we break these up into three groups: Recommended, Optional and Aggressive.

You can also configure what to do with messages that match enabled filters (e.g., delete, forward, modify the subject line, etc.)

Recommended Filters

Likely Image Spam
Likely image (penny stock) spam. This will catch most such spam.
Free Image Hosting
Block likely spam with an image from a free image hosting service
ADV: Prefix in Subject
Block email messages where subject starts with "ADV:" as mentioned in IETF working paper. Likely to be included in CAN-SPAM legislation.
SEXUALLY-EXPLICIT: in Subject
This is required by the CAN-SPAM law for sexually explicit email.
Blank E-mails
Filter blank emails (body is empty or only contains new lines) without any attachments unless one of the following words appears in the subject line: "Remove", "Unsubscribe" or "Test". Blank emails are usually test/dud spam or virus emails

Optional Filters

Weight watchers spam
Many people have complained about getting emails from Weight Watchers and that they cannot unsubscribe
Russian/Cyrillic Character Sets
Identifies emails using a Russian/Cyrillic character set and at least 10 8-bit chars.
Russian Senders
Not to be confused with the character set filter, this looks at the sender email address and hostname of the connecting mail server for the .ru country code.
Chinese Character Sets
Identifies emails using a Chinese character set and at least 10 8-bit chars or 10 escapes
Chinese Sender
Not to be confused with the character set filter, this looks at the sender email address and hostname of the connecting mail server for the .cn country code.
Korean Character Sets
Identifies emails using a Korean character set and with at least 10 8-bit chars or 10 escapes
Korean Sender
Not to be confused with the character set filter, this looks at the sender email address and hostname of the connecting mail server for the .kr country code.
Hebrew Character Sets
Identifies emails using a Hebrew character set and at least 10 8-bit chars
Hebrew (Israel) Sender
Not to be confused with the character set filter, this looks at the sender email address and hostname of the connecting mail server for the .il country code.
Japanese Character Sets
Identifies emails using a Japanese character set and at least 10 8-bit chars or 10 escapes
Arabic Character Sets
Looks for the windows-1256 character set in the headers (from, to, etc) and subject.
Japanese Sender
Not to be confused with the character set filter, this looks at the sender email address and hostname of the connecting mail server for the .jp country code.
Chilean Sender
This filter looks at the sender email address and hostname of the connecting mail server for the .cl country code.
Argentinian Sender
This filter looks at the sender email address and hostname of the connecting mail server for the .ar country code.
Turkish Sender
This filter looks at the sender email address and hostname of the connecting mail server for the .tr country code.
Brazilian Senders
Not to be confused with the Country filter, this looks at the sender email address and hostname of the connecting mail server for the .br country code.
Philippine senders
Not to be confused with a character set filter, this looks at the sender email address and hostname of the connecting mail server for the .ph country code.
Indian Sender
This filter looks at the sender email address and hostname of the connecting mail server for the .in country code.
French Sender
This filter looks at the sender email address and hostname of the connecting mail server for the .fr country code.
Vietnamese Sender
This filter looks at the sender email address and hostname of the connecting mail server for the .vn country code.
spaces.live.com Links
Block emails with a link to a site at spaces.live.com, which is a free hosting service that is often abused by spammers to link to porn, meds and other types of spammer sites.
Extended ASCII in Subject
i.e. "íÏÓË×Á áÎÇÌÉÊÓËÉÊ ÒÁÚÇÏ×ÏÒÎÙÊ", checks if the subject is mostly extended ASCII characters.
SPF failure for your own domain
Spammers often spoof the recipient's domain in an attempt to circumvent antispam services. If you have a SPF record for your domain and a spammer spoofs your users, this filter will block them. PLEASE NOTE: you must have an SPF record in your DNS zone, and it must be configured correctly for this filter to work.
SPF failure for your own domain - From Header
Similar to the "SPF failure for your own domain" filter, except this filter performs the SPF verification against the address in the "From" header of the message instead of the SMTP "MAIL FROM" address.
SPF failure for your own domain - Header from IRL/Friendly name
Similar to the "SPF failure for your own domain" filter, except this filter performs the SPF verification against an email address in the "In Real Life Name/Friendly name" section of the From header of the message instead of the SMTP "MAIL FROM" address. (ie: From: "John.Doe@yourdomain.com" <john617.something-made-up@gmail.com>). Normally you would see: (From: "John Doe" <john617.something-made-up@gmail.com> )
Porn trigger words
Likely porn based on weighted trigger words in short emails.
Block Delivery Status Notifications
If you're being flooded with Delivery Status Notifications, you can temporarily use this filter that will block them. We recommend disabling after a few days so that you can get DSNs again.
Common Bulk Mailers
Block email from well known bulk mailers. Not necessarily spam, but some customers don't want them.
Profanity
This filter blocks email with a percentage of profanity in the body.
Emails with future dates
This optional filter blocks messages with the header date over three days in the future. May block incorrectly configured mail servers or mailers.
Mexican Sender
Not to be confused with the character set filter, this looks at the sender email address and hostname of the connecting mail server for the .mx country code.
Block all messages with a .me domain
Blocks messages that contain a .me sender or links to .me TLD domains.
Block all messages with a .pw domain
Blocks messages that contain a .pw sender or links to .pw TLD domains.
Block all messages with a .rocks domain
Blocks messages that contain a .rocks sender or links to .rocks TLD domains.
Block all messages with a .click domain
Blocks messages that contain a .click sender or links to .click TLD domains.
Block all messages with a .ninja domain
Blocks messages that contain a .ninja sender, or link to a .ninja TLD domain
Block all messages with a .stream domain
Blocks messages that contain a .stream sender, or link to a .stream TLD domain
Block all messages with a .cricket domain
Blocks messages that contain a .cricket sender or link to a .cricket TLD domain.
Block all messages with a .work domain
Blocks messages that contain a .work sender, or link to a .work TLD domain.
Block all messages with a .it sending domain
Blocks the .it TLD sending to your domain.
Block all messages with a .review domain
Blocks messages that contain a .review sender or link to a .review TLD domain.
Block all messages with a .science domain
Blocks messages that contain a .science sender or link to a .science TLD domain.
Block all messages with a .space domain
Blocks messages that contain a .space sender or link to a .space TLD domain.
Block all messages with a .xyz domain
Blocks messages that contain a .xyz sender or links to .xyz TLD domains.
Block all messages with a .link domain
Blocks messages that contain a .link sender or links to .link TLD domains.
Block all messages with a .us sending domain
Blocks messages that contain a ".us" sender.
Block all messages with a .party domain
Blocks messages that contain a .party sender or links to .party TLD domains.
Block all messages with a .webcam domain
Blocks messages that contain a .webcam sender or links to .webcam TLD domains.
Block all messages with a .faith domain
Blocks messages that contain a .faith sender or links to .faith TLD domains.
Block all messages with a .asia domain
Blocks messages that contain a .asia sender or links to .asia TLD domains.
Block all messages with a .name domain
Blocks messages that contain a .name sender or links to .name TLD domains.
Block all messages with a .loan domain
Blocks messages that contain a .loan sender, or link to a .loan TLD domain
Block all messages with a .eu domain
Blocks messages that contain a .eu sender or links to .eu TLD domains.
Block all messages with a .download domain
Blocks messages that contain a .download sender, or link to a .download TLD domain
Block all messages with a .trade sending domain
Blocks all .trade TLD from sending to your domain.
Block all messages with a .gq sending domain
Blocks all .gq TLD from sending to your domain.
Block all messages with a .ga sending domain
Blocks the .ga TLD sending to your domain.
Block all messages with a .top sending domain
Blocks all .top TLD from sending to your domain.
Block all messages with a .stream sending domain
Blocks all .stream TLD from sending to your domain.
Block all messages with a .date domain
Blocks messages that contain a .date sender or links to .click TLD domains.
Block all messages with a .accountant sending domain
Blocks all .accountant TLD from sending to your domain.
Block all messages with a .gdn sending domain
Blocks all .gdn TLD from sending to your domain.
Block all messages with a .biz sending domain
Blocks all .biz TLD from sending to your domain.
Exe link filter
Block emails that contain a link to a ".exe" file. These files can be potentially dangerous. Note, this may block links to some legitimate website scripts.
Zip archive link filter
Block emails that contain a link to a ".zip" file. These are primarily used for phishing or sending viruses.
Compressed Archive Filter
Block any message containing an attachment of the following types: zip, rar, ace, gz, tgz, tbz, bz, 7z, 7zip, cab, xz, lzma
Block Encrypted Archives
This filter will block any encrypted (passworded) archives (zips, rars, etc).
Peru Senders
This looks at the sender email address and hostname of the connecting mail server for the .pe country code.
Singapore senders
This looks at the sender email address and hostname of the connecting mail server for the .sg country code.
Poland Sender
This looks at the sender email address and hostname of the connecting mail server for the .pl country code.
VBA Macro Filter
Blocks messages with attached MS Office files containing VBA macros.
Attachment URL Shortener
This filter blocks messages with attachments that contain a known URL shortener (e.g. http://goo.gl, http://bit.ly, etc). Please note that due to the wide variety, complexity, and encodings of different file formats, some URLs may not be detected.
Block all messages with a .li domain
Blocks messages that contain a .li sender or links to .li TLD domains.
Blocks all messages from .co TLD
Blocks all messages coming from .co domains or contain .co URLs.
Refilter (5 min) Office files with VBA Macros
Rather than blocking based on VBA Macros, the Refilter allows us to stall the message for 0-minute threats until filters should have been put in place (5 minutes)
Refilter (10 min) Office files with VBA Macros
Rather than blocking based on VBA Macros, the Refilter allows us to stall the message for 0-minute threats until filters should have been put in place (10 minutes)
Refilter Archive (10 Minute Delay)
Rather than blocking archives outright, this will delay any message containing an archive for 10 minutes, allowing our analysts time to review and block/allow the message. Delay is 10 minutes.
Refilter messages with URL shorteners
If a message contains a URL shortener link, this will stall the message for ten minutes and then re-filter, at which point filters should have been put in place (10 minutes). If the message does not match after this, then it will be delivered.

Aggressive Filters

We generally do not recommend enabling these aggressive filters, as they will block more legitimate email. However, some or all of them might be suitable for small or family domains that want to block porn from minors, and should be reviewed.

All TinyURL Links
Block emails with a link to a site using Tinyurl.com. URL forwarding services are often abused by spammers to create links to porn sites.
Image source is an IP Address
Filter emails where the link to an image is an IP address (instead of a domain). These are usually porn.
IP Address Link
A link in the email points to an IP address (instead of the more typical domain name). Likely spam/porn, but occasionally used in a legit newsletter.
MIME encoded Subject
Blocks messages that include MIME encoded text in the subject, e.g. "=?iso-8859-1?Q?Adi=F3s?=" or "=?iso-8859-1?B?QWRp83M=?=", each of which translates to "Adiós". This filter will block many legitimate emails that are not written in English.
Extended ASCII in Body
i.e. "íÏÓË×Á áÎÇÌÉÊÓËÉÊ ÒÁÚÇÏ×ÏÒÎÙÊ", checks if a sample of the body is mostly extended ASCII characters.
Small body with single attachment
This filter will block any e-mail with an attachment and less than 12 characters in the body.
English language countries only
A majority of our clients are located in the USA, Canada or the United Kingdom, so we have created this filter to look at the country code of the sender IP address. This filter will match messages that do not have a country code pertaining to those countries.
"From" header is in your domain
Block e-mail where the From header claims to be in your domain, but the Envelope-Sender is an outside organization.
Block all messages with .co.uk sending domain
Blocks all messages coming from .co.uk, very aggressive
Fax senders
This filter will look for apparent fax messages. ONLY enable this filter if your organization does not use an electronic faxing service!
User ID of the recipient's address appears in the subject
For example, Subject: "hello <userID>" matches <userID>@domain.com.
SPF Softfail
Blocks messages if the SPF result for the envelope sender is "fail" or "softfail".
Block all messages where the Reply-To domain is not the sending domain
This optional aggressive filter blocks any message which has a Reply-To address from a different domain than the sending domain. Example: Mail From: <Example@somedomain.com> Reply-To: <spammer@gmail.com> This filter _will_ cause false positives for mailing lists and re-mailers.
Aggressive Bulk Mailer
Block messages that represent bulk mail and subscribed lists. Not necessarily spam however some organizations want to restrict this type of email from being delivered. This filter will block known bulk mailers that you may want.

Other Resources