Where Does Rspamd Store Config and Data?
Where the Rspamd spam filter keeps local config overrides, learned data, and logs on a Linux mail server.
Last updated
Rspamd splits its files three ways on Linux. Configuration you own lives in /etc/rspamd/local.d, learned Bayes data sits in /var/lib/rspamd, and logs go to /var/log/rspamd. The shipped defaults in modules.d are package property and should never be edited.
The local versus override distinction does the real work. Files in local.d merge with defaults, which suits threshold tweaks and score changes. Files in override.d replace whole sections for advanced setups. Web interface adjustments layer on top of both at runtime.
Where Rspamd stores this, by platform
/etc/rspamd/local.d
Your customizations go here as small files like actions.conf or worker-controller.inc, merged over shipped defaults. Never edit modules.d directly; upgrades overwrite it. Data such as Bayes statistics lives in /var/lib/rspamd with logs in /var/log/rspamd.
Frequently asked questions
how do I change Rspamd spam thresholds
Create a file in /etc/rspamd/local.d/ named after the module, such as actions.conf for spam thresholds. Local files merge with shipped defaults, so only your changed values go there. Restart the service after editing and check the logs for syntax complaints.
how do I back up Rspamd
Back up /etc/rspamd/local.d/ and override.d/ for configuration plus /var/lib/rspamd/ for Bayes statistics and learned data. The modules.d folder ships defaults and restores with the package. Redis holds transient state worth snapshotting separately when used.
why is my Rspamd change ignored
Look in /var/log/rspamd/ first, then verify the file landed in local.d rather than modules.d. A file in the wrong folder gets replaced on upgrade or ignored entirely. The rspamadm configtest tool prints parsing errors before a restart.
Notice an outdated path? Let us know.