Skip to main content
.com domains from $2.99 — free WHOIS privacy on every name

Stack Notes

The best place to stop a message is before you accept it

A spam folder is a filing cabinet for things you already agreed to receive, and everything in it has already cost you storage, scanning and a moment of attention.

The short answer

Put MX-level filtering in front of the mailboxes. A service that evaluates a message during the SMTP conversation can refuse delivery outright — something a mailbox rule can never do, because by then the server has already accepted the message and taken on the cost of storing it.

Below: what changes when the decision moves to SMTP time, how to judge the two error rates a filter trades between, why a quarantine you actually read is the whole mechanism, and the reason outbound scanning protects you more than inbound scanning does.

By the HostingFast team · Reviewed 12 August 2026

99.9%

Uptime target we monitor

24/7

Humans on support, any hour

Free

SSL, issued and renewed

NVMe

Drives, entry tier included

Filter placement determines filter power. A service sitting at MX level evaluates each message during the SMTP conversation and can refuse delivery outright, whereas a mailbox filter can only sort what the server has already agreed to accept. Same intelligence, entirely different set of options.

The practical consequence is a refusal that the sending server has to deal with. A legitimate sender caught by mistake receives a bounce and knows immediately; a message dropped quietly into a spam folder is invisible to everyone involved until somebody asks why you never replied.

What changes when the decision moves earlier

At SMTP time the filter can answer with a rejection, and the sending server carries the consequence. Nothing is stored, nothing is scanned, nothing occupies a mailbox quota, and no user has to look at it. Obvious junk stops being your problem in the most literal sense available.

It also produces a better failure mode. A wrongly rejected sender gets a bounce message and can pick up the phone; a wrongly filed message sits in a folder nobody opens. When you are choosing how strict to be, that difference is worth more than a percentage point of catch rate.

Relying solely on mailbox-level filters when an MX-level service could reject the bulk before your server ever accepts delivery is the trap — the mail still arrives, it just arrives somewhere you have agreed to look after it.

Two error rates, judged together

Every filtering decision trades catch rate against false positives, and a vendor quoting only the first number is quoting the easy half. Perfect catch is trivial if you are allowed to reject everything; the skill is in the second figure.

Measure your own rather than accept anyone's. For a fortnight, count what reaches the mailbox that should not have, and count what you release from quarantine that should never have been held. Two small numbers, collected honestly, tell you more than any comparison table.

Then set strictness deliberately. A shared sales address can afford to be aggressive; the address on your invoices cannot. Filtering is not one setting for a whole company.

The add-on, and how it sits

Put MX-level filtering in front of the mailboxes — our Mail Filtering add-on scrubs the stream before it arrives, with a quarantine you can genuinely review rather than merely trust.

Concretely, that is our Mail Filtering option: filtering placed in front of any mailbox, including mailboxes hosted somewhere else entirely, on one flat rate with renewal charged at the order rate.

Mailboxes on your own domain come as part of every hosting plan with spam and virus screening already switched on — the add-on is the layer in front of that, not a replacement for it.

Outbound scanning is the half that protects you

Inbound filtering saves your attention. Outbound scanning saves your domain. One compromised mailbox sending a few thousand messages is how a business ends up on a blocklist, and the first symptom is usually a customer mentioning that your replies have stopped arriving.

Catching that at the boundary means the burst is stopped before the reputation damage is done, which is a far cheaper outcome than the delisting requests and the fortnight of uncertainty that follow. Pair it with the authentication records on your domain and you have both halves: proof of who may send, and a check on what is actually being sent.

Working through an inbox that carries its own domain name

Placement beats cleverness

The interesting question about a mail filter is not how clever it is but where it stands. In front of the MX it can say no; behind the mailbox it can only sort. Everything else follows from that.

Mailboxes on your own domain come as part of the plan — email is included rather than sold back to you at checkout.

  • Rejection at SMTP time, not a folder
  • A bounce tells a real sender something
  • Quarantine digests you can actually read
  • Works in front of mailboxes hosted elsewhere

Why HostingFast

Standard on every plan

It sits in front of any mailbox

It sits at MX level, so it protects mail hosted with us and mail hosted somewhere else equally well.

Rejection rather than storage

Obvious junk is refused during the SMTP conversation, so it never occupies a quota or a moment of anyone's attention.

A quarantine you will actually open

Borderline messages are held rather than deleted, and every release you make teaches the filter something.

Outbound scanning included

A compromised mailbox is caught at the boundary, before a few thousand messages turn into a blocklist entry.

A company on the record

Vitalcare at Home Ltd, registered in England and Wales — a supplier you can check before routing your MX at it.

One rate, order and renewal

The add-on renews at the price it was ordered at, which is a small thing that stops mattering only when it is not true.

Quick Start

From order to online

  1. 1

    Count both error types for a fortnight

    What got through, and what you released from quarantine. Two honest numbers beat any vendor's headline catch rate.

  2. 2

    Set strictness per address

    A shared sales inbox tolerates aggression; the address on your invoices does not. One setting for everyone is the wrong answer.

  3. 3

    Check outbound as well as inbound

    Confirm a compromised mailbox would be caught leaving. That is the direction that costs you a domain reputation.

Built In

Loaded onto every plan

  • In-place plan upgrades — no migration when you grow
  • Per-site PHP version switching from the control panel
  • No setup fee — there is no joining charge, ever
  • Free SSL that reissues itself well before expiry
  • First year of your domain included on annual orders
  • Spam and virus screening applied to every mailbox by default
  • NVMe SSD on every tier, including the entry plan
  • Softaculous on board for one-click application installs
  • LiteSpeed cache built into the server, not bolted on by plugin
  • WordPress Toolkit handling core and plugin updates

Frequently Asked

What people ask us most often

What does rejecting at SMTP time actually change?

Three things. Nothing is stored, so no quota or scanning cost is incurred. Nobody has to look at it, because it never reaches a folder. And a legitimate sender caught by mistake receives a bounce and finds out immediately, rather than assuming you read the message and chose not to reply.

How do I judge a filter's false positive rate?

Measure your own for a fortnight. Count the junk that still reaches a mailbox, and count the genuine messages you release from quarantine. Those two figures describe the trade-off as it applies to your mail rather than to an averaged benchmark, and they take about a minute a day to collect.

Can filtering sit in front of mailboxes hosted elsewhere?

Yes — that is the point of an MX-level service. You repoint the MX records at the filter and it forwards clean mail to wherever the mailboxes actually live, which can be us or anybody else. It also makes the arrangement portable: change mail providers later and the filtering layer stays exactly where it is.

Why does outbound scanning matter as much as inbound?

Because inbound filtering protects your attention while outbound scanning protects your domain. One compromised account sending a burst of messages is the usual route onto a blocklist, and the first sign is normally a customer mentioning that your replies stopped arriving. Catching it at the boundary is far cheaper than the delisting process afterwards.

Keep reading

Changing hosts? Run through our checklist first.

A straightforward sequence for a switch your visitors never feel: which files move first, how to shift email across without losing a single message, the right moment to repoint DNS, and the two mistakes behind almost all the downtime we get asked to rescue.

You'll get the checklist email, then occasional pointers on keeping a site running fast. Unsubscribe the moment you want out — the privacy policy covers the rest.

Stop it at the boundary.

MX-level filtering in front of any mailbox, a quarantine you can review, and outbound scanning included.

View Mail Filtering plans