It may sound like an easy question at first, but what actually counts as spam? Anyone dealing with email security, however, knows that the answer is anything but clear-cut, and the discussion quickly drifts into philosophical territory.
Nowadays, ransomware, phishing, and fraudulent emails can be detected very reliably using the latest algorithms. Things get more complicated, however, when it comes to messages that are perfectly legitimate from a technical and legal perspective, but still perceived to be bothersome by the recipient.
That’s where the blurry line between typical spam and emails known as “graymail” kicks in. The term refers to newsletters, marketing emails, or other mass mailing campaigns that were initially subscribed to willingly in a legally sound manner, but are no longer considered interesting or even legitimate by the recipient.
Real-world experience shows that perception of spam is largely subjective
Over the course of many years, we have been exploring this issue with customers across a wide range of sectors. Our findings are remarkably consistent: For end users, what constitutes spam frequently differs from the technical definition. Rather, spam is anything they perceive as annoying in their inboxes and daily work.
This presents a dilemma for IT departments. On the one hand, they need to ensure that as few unwanted emails as possible end up in their users’ inboxes, while on the other hand, nobody wants to inadvertently block legitimate communication.
Newsletters belong in a category of their own
Building on this experience, for many years Retarus has been taking a different approach. In addition to the typical classification of messages into spam and threats, Retarus Email Security adds a separate category for newsletters. This approach unlocks a number of benefits. End users are able to instantly see which messages have been classified as graymail. These emails are clearly displayed in their own category, both in the browser-based online quarantine and the daily email security digest (see screenshots).


There, users are given the option of unsubscribing from these messages with a single click, provided the company has enabled this self-service feature. Just as easily, users can ensure that they continue to receive a specific newsletter directly in their inbox by adding it to their personal allowlist.
Self-service rather than help desk tickets
This is where the real added value becomes evident. At many companies, a large number of support requests end up at the help desk even though they aren’t really related to technical issues. An employee might be missing a regular newsletter, wish to release an email from quarantine, or simply want to ensure they receive a specific message consistently in the future. Each of these cases eats up valuable working time – both for the user and administrator.
Allowing humans to decide which messages are relevant
While technology is steadily getting better at reliably detecting malicious emails, humans remain the final decision-makers when it comes to assessing personal relevance. That’s why at Retarus, our focus extends beyond providing powerful protection mechanisms, user-friendly UI/UX, and APIs for admins.
We’re always sure to pay just as much attention to the end user. In practice, our approach puts an end to the perpetual debates about which emails actually constitute spam. It returns the power to decide if a message is spam to where it makes most sense in everyday business: the recipients themselves.



