Many myths have emerged about Mail's junk mail filter. No, it's not an extremely complex set of rules, no it doesn't look for keywords, and no, it doesn't use white magic. To truly understand what makes it so much better than the competition, we'll have to take a closer look at the recognition engine and the technologies it relies on to do its work. It may sound a bit complex at first, but things will begin to make sense as we work through the mechanics.
Source: Mac Dev Center
I have long wanted to know how Mail's spam filter worked. I personally have seen much better results using SpamSieve and POPFile. I have used both heavily, either for myself or for my clients.
