Re: Am I an Emule Server?



"Gregg Hill" <bogus@xxxxxxxxxxx> wrote in message
news:u5LPP$qBIHA.4160@xxxxxxxxxxxxxxxxxxxxxxx
Brian

So I guess NDR behavior can be done differently for different forms of
filtering. I have Recipient Filtering turned on (and SMTP tarpitting set
to 35 per a friend's call to MS support to prevent harvesting). I just
sent a test message from my Yahoo account to a non-existent user at my
domain, and the NDR I got back was from Yahoo's mail server as expected.
Cool.

I also use connection filtering with zen.spamhaus.org and this custom
error message "Your mail server IP address %0 is listed as a spam site by
the RBL provider %2. Please call your intended recipient and give them
this exact error message." and the return status codes from spamhaus.org
(I don't understand what those do).

This is a great idea. We used a custom block list for a while based on an
analysis of where our spam came from. What we did find was that some of the
sending servers were gateway servers that were also being used by some of
our genuine customers. So do look into whether you can unblock some IPs if
you find you need to.

I have Sender Filtering turned on with six entries so far (recommended
during my friend's MS support call). The support tech said that would cut
out a lot of spam.

Since I anticipate you asking, here is the list. I added the .ru block.

*@*.ru
@hinet.net
@hinet.net.tw
@mail2000.com.tw
@yahoo.com.jp
@yahoo.com.sg

I do not deal with anyone who sends from one of those domains, so it works
for me.

Good idea. Not something I use ... but now that you've given me the idea I
will investigate the possibilities for us.

I have an SPF record for my domain, and I have SenderID turned on and set
to reject. That way, if the claimed sending domain has an SPF and it
fails, it is likely a spoof, and if it is not, then the sender still gets
an NDR generated by his/her own server. Correct?

I'm aware of SPF records but (to my shame) am quite ignorant. Its something
I need to come up to speed on.

I have the IMF set at 8 and 8 so that anything flagged gets archived. I
use 8 and 8 so that anything that gets through goes to Trend Micro CSMS
for SMB's "End User Quarantine" and not the Junk E-mail folder. I do not
like the IMF set any lower, as I get false positives too often.

I have downloaded but not installed the trial for Vamsoft ORF.

That's what I do to combat the rat bastiges!

There was a phrase in a comic I used to read as a child ... nuke em till
they glow.

Looks like you've doing a better job on spam than I am. Well done, keep it
up.
--
Brian Cryer
www.cryer.co.uk/brian


.



Relevant Pages

  • RE: Getting swamped with NDRs. How do I stop them?
    ... is using non-delivery report (NDR), ... Start the Exchange System Manager program. ... Expand Servers, expand your Exchange server, and click Queues. ... Click the Recipient Filtering tab, click to select the Filter recipients ...
    (microsoft.public.windows.server.sbs)
  • Re: OE 7 Message Rules
    ... Note that spammers constantly change there already munged address, so filtering on that is useless. ... If you filter in your mail, you will get no spam. ... You can choose Delete it from server, but be careful as you will never have any messages downloaded to any folder if you choose this option. ... only addresses you entered will be downloaded to your Inbox. ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)
  • Re: Why?
    ... This periodic flood is making this group nearly worthless to me. ... Like I have said before - I don't normally see an unusual amount of spam at ... This would see to indicate that the filtering was being done on the ... server and I was unlucky enough to download the messages between them ...
    (comp.arch.embedded)
  • Re: Unexplain-able Undeliverable messages being generated
    ... real piece of email or does the message body look like an NDR? ... it as spam and sends it to your Spam account. ... Run Microsoft Exchange Server Best Practices Analyzer Today ... > would get modified by the 3rd party that scans the mail for spam. ...
    (microsoft.public.exchange2000.general)
  • Re: a ton of transaction logs being generated
    ... I applied Recipient filtering and rebooted the server. ... restart any services. ... What you may find is that the spam comes from zombie networks. ...
    (microsoft.public.exchange.admin)

Loading