QUOTE(mootimus @ Jul 24 2009, 05:53 PM)

[...]
The fact that the X-spam-Level is often zero stars, or 1 or 2, coupled with the spams being all the same pretty much (acai berry, online pharmacies and implants, watches, and a few phishing schemes thrown in) makes me wonder what's happening algorithmically on the spam assassin side of the flow.
[...]
So, what can I do to tighten the screws without missing legit mails (note that checking the Held Mail folder is not possible, it has too many daily entries)?
Except for "replica" I think SA doesn't use real words much since the Viagra etc. lot just went over to misspelling. To investigate this properly would need a look at what SA tests were effective both now and in the past - I found the URL tests were the usual trigger - and what might be made more effective.
You don't say how many Spams a month you get (index numbers in VER or Held make this quite easy to record).
I have SA=2.0 3622 spams (121/d), 46 leakers (=1.3 %) for June with all Blocklists including pbl in spite of the false positives caused by the SC implementation.
There is a trick to let you just look at the borderline SA values so going from SA=5.0 to SA=2.0 is no risk nor requires more than a few to be eyballed.
Thus using SC Webmail Search on the held folder (and save as a virtual folder)
Search 'Entire messagel' for any of "hits=0.", "hits=1.", "hits=2.", "hits=3.", "hits=4." plus for good measure any that don't contain "hits=" at all This should show you all the low SA and blocklist items which (for me) is only 1-5 a day.
HTH