Here is a thought I have that may be effective on these zero-day SPAM 
campaigns.  It does have a big drawback, but the users may be OK with it if it 
stops the SPAM.

Here is my idea.  I am going to say this is from my standpoint of using 
SmarterMail.

The basic idea is to process each message through declude twice.  Any message 
that declude did not whitelist or delete would be sent to a hold queue folder 
and after a set amount of time declude would rescan the message.
The first time through declude the message would process and drop out of 
declude only if whitelisted, or deleted.  The message would also be counted by 
reputation tests such as barracuda.  Once the message is processed it would be 
put in a hold queue where it would set for a set amount of time (Say 30 min).  
The delay would give a chance for tests to identify SPAM campaigns.  After the 
Queue delay has passed Declude will process the message again and take the 
normal action to the message when complete.  

Thoughts?


#############################################################
This message is sent to you because you are subscribed to
  the mailing list <[email protected]>.
To unsubscribe, E-mail to: <[email protected]>
To switch to the DIGEST mode, E-mail to <[email protected]>
To switch to the INDEX mode, E-mail to <[email protected]>
Send administrative queries to  <[email protected]>

Reply via email to