I think the only answer is to put equal or better AS defense on the secondary MX.
We have 2 data centers with mail relay appliances in each with similar MX setup - the primary or preferred MX location blocks average of 91% of the inbound connections - of the remaining 9%, 66% is considered legitimate (i.e. not spam or bulk). The secondary location gets a bit more than half the number of connections and 99% of them are blocked - of the 1% allowed, 19% are legit - the rest spam or bulk. Spammers seem attracted to secondary MX, perhaps guessing that there may not be as effective an AS defense there. Don ________________________________ From: Steve Hart [mailto:[EMAIL PROTECTED] Sent: Thursday, January 24, 2008 1:18 PM To: MS-Exchange Admin Issues Subject: mx records We have two real world MX records for our domain. The first has a preference of 10 and points to our main email server, a new E2007 box. The second mx record has a preference of 200 and points to the email server of one of our affiliated companies. That server is an old E2000 beast. Both Exchange servers are part of the same Exchange Organization and there's a point to point T1 between the sites that provides an alternate means of delivery should our main internet connection die. I'm experimenting with spam filtering on the 2007 box using SpamHaus and custom words and having quite a bit of success. Spam directly from the internet passing through the 2007 server is virtually nil. The problem is that a good portion of our spam (about 20%) seems to be arriving through the E2000 box across town. Since that server is part of internal system, the new box isn't filtering the mail. Headers show that even when the addresses are wrightbg.com, remote servers are routing the mail to wbgppm.com. Is there a way to fix this, other than deleting the second mx record? Steve ~ Ninja Email Security with Cloudmark Spam Engine Gets Image Spam ~ ~ http://www.sunbeltsoftware.com/Ninja ~
