When a sender is classified as SPAM.R in the analysis status with a red globe in the score column, the origin of the control comes from the geographic filtering policy set up for your domain.
This control is easily identifiable in the message tracking.
You'll see a red globe in the "score" column.