Virus Bulletin’s latest VBSpam comparative review, authored by Ionuţ Răileanu and Adrian Luca, confirms that email security vendors are winning the volume war against spam but facing a tougher fight against phishing campaigns engineered to hide behind legitimate-looking infrastructure.
The Q3 2026 test, run over 16 days from August 1–17 and validated under AMTSO’s LS1-TP207 standard, evaluated ten full email security platforms and one open-source engine against a corpus of 103,969 emails.
Net at Work NoSpamProxy took the top spot with a final score of 99.995, edging out Bitdefender GravityZone Premium (99.994) and SEPPmail.cloudfilter (99.985).
VBSpam Q3 2026: NoSpamProxy, Bitdefender
Fortinet’s FortiMail, N-able SpamExperts, and N-able Mail Assure rounded out the VBSpam+ tier, each combining spam catch rates above 99.9% with zero false positives.
Notably, six of the eleven tested products achieved this elite VBSpam+ certification, reflecting how mature detection engines have become against bulk spam and attached malware threats; four vendors hit a flawless 100% malware catch rate.

Bluepex Mail Security, Coro Email Security, and Zoho Mail earned standard VBSpam certification but were pulled below the plus threshold by newsletter false positives, a recurring weak point across the industry.
Meanwhile, Rspamd’s open-source build managed only a 57.507 final score, catching just 57.873% of spam, underscoring the detection gap between commercial and community-maintained filtering stacks.
Its commercial sibling, Rspamd Premium 3.14.3, jumped from the previous test’s 92.960% catch rate to 99.069%, though a 0.75% false-positive rate still capped its final score at 95.410. The report’s highlight cases matter more than the scoreboard.
Three campaigns a Dutch fake-antivirus renewal scam, a German invoice-themed lure funneling victims to OpenSea, and a Romanian BCR banking phish using IPv6-mapped URL obfuscation shared a common design philosophy: no attachments, DKIM-aligned or authenticated sending domains, and multi-stage redirect chains that only reveal malicious intent after browser fingerprinting or geofencing.

Static scanners and simplified sandboxes routinely missed these because the “attack” itself never touched the inbox; it lived downstream in cloaked infrastructure that could serve benign content on demand.
These cases illustrate a structural shift: attackers are optimizing for authentication compliance (SPF, DKIM, DMARC) precisely because filters increasingly trust it as a signal of legitimacy.
Splitting tracking, unsubscribe, and CTA URLs, then routing through disposable subdomains, effectively launders reputation checks.
For defenders, this means email security can no longer be a mail-gateway-only discipline; browser-level fingerprint detection, dynamic re-analysis of “cold” URLs, and behavioral sandboxing at click-time are becoming necessary complements to inbox filtering.
- Authentication passing (SPF/DKIM/DMARC) is no longer a reliable trust signal on its own.
- HTML-only, attachment-free phishing is evading static and simplified sandbox analysis.
- IPv6-literal and encoded URLs remain an effective obfuscation technique against extraction tools.
- Even top-tier vendors show measurable gaps in phishing catch rates (as low as 98.730% for Rspamd Premium) compared to malware and spam catch rates.
The full methodology, scoring tables, and product breakdowns are available in Virus Bulletin’s published Q3 2026 VBSpam report.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.